IP Library Granted Patent US 11,153,342
Granted Patent B2
US 11,153,342 · App. 16/565,149 · Granted Oct 19, 2021

Method and system for providing ddos protection by detecting changes in a preferred set of hierarchically structured items in stream data

Inventors: Andrew Lee Adams (Burlington, MA); Cameron Hanover (Burlington, MA); Dagan Harrington (Burlington, MA); Jiasi Li (Burlington, MA); Joachim Wright (Burlington, MA)
Assignee: Arbor Networks, Inc.
H04L63/1458H04L63/1416H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,342
App. No.
16/565,149
Granted
Oct 19, 2021
Kind
B2
Abstract

A computer implemented method and system for protecting against denial of service attacks by detecting changes in a preferred set of hierarchically-structured items in a network data stream in which a set of network destination prefixes is identified that account for a user specified target of the attack traffic. Changes in the attack traffic profile are detected and new sets of network destination prefixes are generated when the attack has shifted by a predetermined threshold. sets of identified destination prefixes are then translated into route announcements to divert attack traffic to mitigation devices.

Claims (17)

1. A method for protecting against denial of service (DoS) attacks by detecting changes in a preferred set of hierarchically-structured items in a network data stream, comprising:

capturing network traffic from a network data stream from a plurality of network routers coupled to the network data stream;

collecting the captured network traffic in a plurality of network traffic collectors wherein each of the network traffic collectors is respectively coupled to a respective network router in the plurality of network routers and wherein each of the network traffic collectors includes a network traffic counter, reads destination host addresses and bytes counts present in the captured network traffic, maintains a limited set of network traffic counters for tracking network traffic to host addresses, tracks network traffic to a configured set of network prefixes containing the host addresses, wherein each of the network traffic counters in the limited set of the network traffic counters is maintained using a Hierarchically Heavy Hitters (H3PREF) algorithm and whereby each of the network traffic collectors is further coupled to a common leader nodal device;

querying, upon detection of a DoS attack, by the common leader nodal device, each of the coupled network traffic collectors to obtain network counter values and Internet Protocol (IP) prefixes tracked by each of the coupled network traffic collectors;

identifying, by the common leader nodal device, a set of network destination prefixes that account for a user specified target of the DoS attack utilizing the obtained network counter values and IP prefixes;

tracking, by the common leader nodal device, changes in the attack traffic profile present in the DoS attack;

generating, by the common leader nodal device, new sets of network destination prefixes when the DoS attack has shifted by a predetermined threshold; and

translating, by the common leader nodal device, sets of identified destination prefixes into route announcements via the generated new sets of network destination prefixes to divert attack traffic of the DoS attack to mitigation devices.

2. A system for protecting against denial of service (DoS) attacks by detecting changes in a preferred set of hierarchically-structured items in a network data stream, comprising:

a plurality of network routers coupled to the network data stream configured to capture network traffic from a network data stream;

a plurality of network traffic collectors, respectively coupled to a respective network router such that each of the network traffic collectors collects the captured network traffic from a respective coupled network router wherein each of the network traffic collectors includes a network traffic counter, reads destination host addresses and bytes counts present in the captured network traffic, maintains a limited set of network traffic counters for tracking network traffic to host addresses, tracks network traffic to a configured set of network prefixes containing the host addresses, wherein each of the network traffic counters in the limited set of the network traffic counters is maintained using a Hierarchically Heavy Hitters (H3PREF) algorithm;

a common leader nodal device coupled to each of the plurality of the network traffic collectors, the common leader nodal device configured to:

query, upon detection of a DoS attack, the network traffic counter of each of the coupled network traffic collectors to obtain network counter values and Internet Protocol (IP) prefixes tracked by each of the coupled network traffic collectors;

identify a set of network destination prefixes that accounts for a user specified target of the DoS attack utilizing the obtained network counter values and IP prefixes;

track changes in attack traffic profile present in the DoS attack;

generate new sets of network destination prefixes when the DoS attack has shifted by a predetermined threshold; and

translate sets of identified destination prefixes into route announcements via the generated new sets of network destination prefixes to divert attack traffic of the DoS attack to mitigation devices.

Assignments (3)
SECURITY INTEREST Recorded Oct 22, 2024
From: NETSCOUT SYSTEMS, INC.; ARBOR NETWORKS LLC; NETSCOUT SYSTEMS TEXAS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069216/0007 →
SECURITY INTEREST Recorded Jul 27, 2021
From: NETSCOUT SYSTEMS, INC.; ARBOR NETWORKS, INC.; AIRMAGNET, INC.; NETSCOUT SYSTEMS TEXAS, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056997/0847 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2020
From: ADAMS, ANDREW LEE, MR.; HANOVER, CAMERON T., MR.; HARRINGTON, DAGAN, MR.; LI, JIASI; WRIGHT, JOACHIM, MR.
To: ARBOR NETWORKS, INC.
Reel/Frame 051408/0752 →