IP Library Granted Patent US 11,489,865
Granted Patent B2
US 11,489,865 · App. 16/638,793 · Granted Nov 1, 2022

Control device, communication system, control method, and computer program

Inventor: Kaname Nishizuka (Tokyo, JP)
Assignee: NTT Communications Corporation
H04L63/1458H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,489,865
App. No.
16/638,793
Granted
Nov 1, 2022
Kind
B2
Abstract

A control device includes a controller configured to instruct a mitigation device executing a defending process against an attack on a network to execute the defending process in response to reception of a defending request indicating a request for executing the defending process. When predetermined specific data included in the received defending request is valid, the controller instructs the mitigation device to execute the defending process at an earlier timing after the reception of the defending request than when the specific data is not valid or the specific data is not included in the defending request.

Claims (22)

1. A control device comprising:

a controller configured to instruct a mitigation device executing a defending process against an attack on a network to execute the defending process in response to reception of a defending request indicating a request for executing the defending process,

wherein, when predetermined specific data included in the received defending request is valid, the controller instructs the mitigation device to execute the defending process at an earlier timing after the reception of the defending request than when the specific data is not valid or the specific data is not included in the defending request by instructing the mitigation device to execute the defending process without executing some or all of processes executed when the specific data is not valid or the specific data is not included,

wherein the specific data is defined in advance between a first subject providing the defending process by the mitigation device and a second subject receiving a provided defending process, and

wherein the specific data indicates that the type of the attack the second subject is receiving matches one type of attack or a plurality of types of attacks decided in advance.

2. The control device according to claim 1 , wherein, when the specific data is valid, the controller instructs the mitigation device to execute the defending process without executing a determination process which is a process of determining whether there is an actual attack on a network which is an execution target of the defending process.

3. A communication system comprising:

a detector configured to detect an attack on a network and transmit a defending request indicating a request for executing a defending process for the network;

a mitigator configured to execute the defending process against the attack on the network; and

a control device configured to control the mitigator,

wherein the control device includes a controller configured to instruct the mitigator to execute the defending process in response to reception of the defending request,

wherein, when predetermined specific data included in the received defending request is valid, the controller instructs the mitigator to execute the defending process at an earlier timing after the reception of the defending request than when the specific data is not valid or the specific data is not included in the defending request by instructing the mitigator to execute the defending process without executing some or all of processes executed when the specific data is not valid or the specific data is not included,

wherein the specific data is defined in advance between a first subject providing the defending process by the mitigator and a second subject receiving a provided defending process, and

wherein the specific data indicates that the type of the attack the second subject is receiving matches one type of attack or a plurality of types of attacks decided in advance.

4. The communication system according to claim 3 , wherein the detector validates the specific data of the defending request in accordance with a predetermined condition related to the detected attack.

5. A control method in a control device that instructs a mitigation device executing a defending process against an attack on a network to execute the defending process in response to reception of a defending request indicating a request for executing the defending process, the control method including, determining whether or not predetermined specific data included in the received defending request is valid, and when the predetermined specific data included in the received defending request is valid, causing the control device to instruct the mitigation device to execute the defending process at an earlier timing after reception of the defending request than when the specific data is not valid or the specific data is not included in the defending request by instructing the mitigation device to execute the defending process without executing some or all of processes executed when the specific data is not valid or the specific data is not included,

wherein the specific data is defined in advance between a first subject providing the defending process by the mitigation device and a second subject receiving a provided defending process, and

wherein the specific data indicates that the type of the attack the second subject is receiving matches one type of attack or a plurality of types of attacks decided in advance.

6. A non-transitory computer-readable storage medium storing a computer program causing a computer to function as a control device including a controller that instructs a mitigation device executing a defending process against an attack on a network to execute the defending process in response to reception of a defending request indicating a request for executing the defending process,

wherein, when predetermined specific data included in the received defending request is valid, the controller instructs the mitigation device to execute the defending process at an earlier timing after the reception of the defending request than when the specific data is not valid or the specific data is not included in the defending request by instructing the mitigation device to execute the defending process without executing some or all of processes executed when the specific data is not valid or the specific data is not included,

wherein the specific data is defined in advance between a first subject providing the defending process by the mitigation device and a second subject receiving a provided defending process, and

wherein the specific data indicates that the type of the attack the second subject is receiving matches one type of attack or a plurality of types of attacks decided in advance.

Assignments (2)
CHANGE OF NAME Recorded Dec 19, 2025
From: NTT COMMUNICATIONS CORPORATION
To: NTT DOCOMO BUSINESS, INC.
Reel/Frame 073800/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2020
From: NISHIZUKA, KANAME
To: NTT COMMUNICATIONS CORPORATION
Reel/Frame 051807/0465 →
Priority Claims (1)
JP JP2017-158154 · Aug 18, 2017 · national
Continuity (1)
Related Publication 20210136103A1 · May 6, 2021