IP Library Granted Patent US 11,122,080
Granted Patent B2
US 11,122,080 · App. 16/564,740 · Granted Sep 14, 2021

Method and system for identifying a preferred set of hierarchically structured items in streaming data

Inventors: Andrew Lee Adams (Burlington, MA); Cameron Hanover (Burlington, MA); Dagan Harrington (Burlington, MA); Jiasi Li (Burlington, MA); Joachim Wright (Burlington, MA)
Assignee: Arbor Networks, Inc.
H04L63/1491G06K9/6231H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,122,080
App. No.
16/564,740
Granted
Sep 14, 2021
Kind
B2
Abstract

A computer implemented method and system for identifying a preferred set of hierarchically structured items in streaming data for analyzing Netflow data to identify those network destinations that are currently the target of a DDoS attack and to automatically select a set of network prefixes such that diversion routes for the prefixes are sent to the routers to divert attack traffic to TMS devices, The method includes searching sets of Hierarchical Heavy Hitters wherein each set corresponds to a different fraction of a total volume of network traffic and scoring each set according to an arbitrary scoring function. A certain set is selected and scored with a ‘good’ score and a member of the ‘good’ scored set is ranked in accordance with an arbitrary ranking function. A subset of the ‘good’ scored set is selected such that the volume associated with the subset is in close proximity to a user-specified total whereby the selected subset becomes a set of recommended prefixes.

Claims (16)

1. A method for identifying a preferred set of hierarchically structured items in streaming data for analyzing network data traffic (Netflow data) to identify those network destinations that are currently the target of a Distributed Denial of Service (DDoS) attack and to automatically select a set of network prefixes such that diversion routes for the prefixes are sent to routers to divert attack traffic to Threat Mitigation Systems (TMS) devices, comprising:

searching sets of Hierarchical Heavy Hitters (H3PREF) wherein each set corresponds to a different fraction of a total volume of network traffic and includes at least: 1) a lattice structure modeling hierarchy in an ID space; 2) a counter update procedure; and 3) a stream merging procedure;

scoring each set according to an arbitrary scoring function that includes a mix of network mask lengths present in the set and a number of members in the set;

selecting a good scored set with a value indicative that a network device is not associated with a DDoS attack;

ranking member of the good scored set in accordance with an arbitrary ranking function; and

selecting a subset of the good scored set such that a volume associated with the subset is in close proximity to a user-specified total whereby the selected subset becomes a set of recommended prefixes.

2. A computer system for identifying a preferred set of hierarchically structured items in streaming data for analyzing network data traffic (Netflow data) to identify those network destinations that are currently the target of a Distributed Denial of Service (DDoS) attack and to automatically select a set of network prefixes such that diversion routes for the prefixes are sent to routers to divert attack traffic to Threat Mitigation Systems (TMS) devices, comprising:

a memory configured to store instructions;

a processor disposed in communication with said memory, wherein said processor upon execution of the instructions is configured to:

search sets of Hierarchical Heavy Hitters (H3PREF) wherein each set corresponds to a different fraction of a total volume of network traffic and includes at least: 1) a lattice structure modeling hierarchy in an ID space; 2) a counter update procedure; and 3) a stream merging procedure;

score each set according to an arbitrary scoring function that includes a mix of network mask lengths present in the set and a number of members in the set;

select a good scored set scored with a value indicative that a network device is not associated with a DDoS attack;

rank member of the good scored set in accordance with an arbitrary ranking function; and

select a subset of the good scored set such that a volume associated with the subset is in close proximity to a user-specified total whereby the selected subset becomes a set of recommended prefixes.

3. The computer method as recited in claim 1 , wherein each H3PREF further includes a selection process for identifying a set of IDs representative of a user-specific fraction of a total volume of the streaming data.

4. The computer system as recited in claim 2 , wherein each H3PREF further includes a selection process for identifying a set of IDs representative of a user-specific fraction of a total volume of the streaming data.

Assignments (3)
SECURITY INTEREST Recorded Oct 22, 2024
From: NETSCOUT SYSTEMS, INC.; ARBOR NETWORKS LLC; NETSCOUT SYSTEMS TEXAS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069216/0007 →
SECURITY INTEREST Recorded Jul 27, 2021
From: NETSCOUT SYSTEMS, INC.; ARBOR NETWORKS, INC.; AIRMAGNET, INC.; NETSCOUT SYSTEMS TEXAS, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056997/0847 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2020
From: ADAMS, ANDREW LEE, MR.; HANOVER, CAMERON T., MR.; HARRINGTON, DAGAN, MR.; LI, JIASI; WRIGHT, JOACHIM, MR.
To: ARBOR NETWORKS, INC.
Reel/Frame 051408/0696 →