IP Library › Granted Patent US 12,244,640
Granted Patent B2
US 12,244,640 · App. 18/535,021 · Granted Mar 4, 2025

Automatic retraining of machine learning models to detect DDoS attacks

Inventors: K. Tirumaleswar Reddy (Bangalore, IN); Daniel G. Wing (San Jose, CA); Blake Harrell Anderson (Chapel Hill, NC); David McGrew (Poolesville, MD)
Assignee: Cisco Technology, Inc.
H04L63/1458G06N20/00H04L63/1425H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,640
App. No.
18/535,021
Filed
Dec 11, 2023
Granted
Mar 4, 2025
Kind
B2
Art Unit
2434
USPC
726/22
Abstract

In one embodiment, a device in a network receives an attack mitigation request regarding traffic in the network. The device causes an assessment of the traffic, in response to the attack mitigation request. The device determines that an attack detector associated with the attack mitigation request incorrectly assessed the traffic, based on the assessment of the traffic. The device causes an update to an attack detection model of the attack detector, in response to determining that the attack detector incorrectly assessed the traffic.

Claims (53)

1. A method comprising:

monitoring, at an attack detector in a network, network traffic to detect a Distributed Denial of Service (DDoS) attack by applying one or more first-level attack detection models against one or more attributes of the network traffic;

in response to detection of a DDoS attack,

causing network traffic associated with the DDoS attack to be diverted to an attack mitigation device, wherein the attack mitigation device is configured to perform a mitigation action on attack traffic in the network;

assessing, by the attack mitigation device, the network traffic associated with the DDoS attack using deep packet inspection and a second attack detection model;

providing, by the attack mitigation device, feedback to the attack detector regarding the detected DDoS attack, wherein the feedback indicates a false positive; and

refining at least one of the one or more first-level attack detection models applied by the attack detector based on the feedback.

2. The method of claim 1 wherein the feedback indicates a false negative or a false positive.

3. The method of claim 1 wherein the feedback indicates whether the attack detector incorrectly assesses the network traffic.

4. The method of claim 1 wherein refining at least one of the one or more first-level attack detection models applied by the attack detector comprises:

associating one or more labels with the traffic, based on the assessment of the traffic by the attack mitigation device; and

updating the at least one of the one or more first-level attack detection models using the one or more labels.

5. The method of claim 1 wherein refining at least one of the one or more first-level attack detection models applied by the attack detector comprises:

determining updated parameters for at least one of the one or more first-level attack detection models, based on the assessment of the traffic; and

updating the at least one of the one or more first-level attack detection models using the updated parameters.

6. The method of claim 1 , wherein the attack detector comprises a Distributed Denial of Service (DDoS) Open Threat Signaling (DOTS) client.

7. The method of claim 1 , wherein the attack mitigation device is a Distributed Denial of Service (DDoS) Open Threat Signaling (DOTS) attack mitigator.

8. The method of claim 1 wherein the attack detector comprises an attack detection device in communication with a router.

9. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed operable to perform a processing comprising:

monitoring, using an attack detector, network traffic to detect a Distributed Denial of Service (DDoS) attack by applying one or more first-level attack detection models against one or more attributes of the network traffic;

in response to detection of a DDoS attack,

causing network traffic associated with the DDoS attack to be diverted to an attack mitigation device, wherein the attack mitigation device is configured to perform a mitigation action on attack traffic in the network, the mitigation action comprising: assessing the network traffic associated with the DDoS attack using deep packet inspection and a second attack detection model;

receiving feedback from an attack mitigation device regarding the detected DDoS attack, wherein the feedback indicates a false positive; and

refining at least one of the one or more first-level attack detection models applied by the attack detector based on the feedback.

10. The apparatus of claim 9 wherein the feedback indicates a false negative or a false positive.

11. The apparatus of claim 9 wherein the feedback indicates whether the attack detector incorrectly assesses the network traffic.

12. The apparatus of claim 9 wherein refining at least one of the one or more first-level attack detection models applied by the attack detector comprises:

associating one or more labels with the traffic, based on the assessment of the traffic by the attack mitigation device; and

updating the at least one of the one or more first-level attack detection models using the one or more labels.

13. The apparatus of claim 9 wherein refining at least one of the one or more first-level attack detection models applied by the attack detector comprises:

determining updated parameters for at least one of the one or more first-level attack detection models, based on the assessment of the traffic; and

updating the at least one of the one or more first-level attack detection models using the updated parameters.

14. The apparatus of claim 9 wherein the attack detector comprises a Distributed Denial of Service (DDoS) Open Threat Signaling (DOTS) client.

15. The apparatus of claim 9 wherein the apparatus is a Distributed Denial of Service (DDoS) Open Threat Signaling (DOTS) attack mitigator.

16. The apparatus of claim 9 wherein the attack detector comprises an attack detection device in communication with a router.

17. A tangible, non-transitory computer-readable medium that stores program instructions configured to cause a device in a network to execute a process comprising:

monitoring network traffic to detect a Distributed Denial of Service (DDoS) attack by applying one or more first-level attack detection models against one or more attributes of the network traffic;

in response to detection of a DDoS attack,

causing network traffic associated with the DDoS attack to be diverted to an attack mitigation device, wherein the attack mitigation device is configured to perform a mitigation action on attack traffic in the network;

assessing the network traffic associated with the DDoS attack using deep packet inspection and a second attack detection model;

providing feedback regarding the detected DDoS attack, wherein the feedback indicates a false positive; and

refining at least one of the one or more first-level attack detection models based on the feedback.

18. The tangible, non-transitory computer-readable medium of claim 17 wherein the feedback indicates a false negative or a false positive.

19. The tangible, non-transitory computer-readable medium of claim 17 wherein the feedback indicates an incorrect assessment of the network traffic.

20. The tangible, non-transitory computer-readable medium of claim 17 wherein refining at least one of the one or more first-level attack detection models comprises:

associating one or more labels with the traffic, based on the assessment of the traffic by the attack mitigation device; and

updating the at least one of the one or more first-level attack detection models using the one or more labels.

21. The tangible, non-transitory computer-readable medium of claim 17 wherein refining at least one of the one or more first-level attack detection models comprises:

determining updated parameters for at least one of the one or more first-level attack detection models, based on the assessment of the traffic; and

updating the at least one of the one or more first-level attack detection models using the updated parameters.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2023
From: REDDY, K. TIRUMALESWAR; WING, DANIEL G.; ANDERSON, BLAKE HARRELL; MCGREW, DAVID
To: CISCO TECHNOLOGY, INC.
Reel/Frame 065826/0485 →
Continuity (6)
Continuation 18096143 · Jan 12, 2023
Continuation 17395264 · Aug 5, 2021
Continuation 16906302 · Jun 19, 2020
Continuation 15245886 · Aug 24, 2016
Provisional Application 62356023 · Jun 29, 2016
Related Publication 20240259422A1 · Aug 1, 2024
References Cited (19)
US 6301668B1 · Gleichauf et al. · 2001 [cited by applicant]
US 7823204B2 · Gupta et al. · 2010 [cited by applicant]
US 8635171B1 · Kennedy · 2014 [cited by applicant]
US 10104119B2 · Reddy et al. · 2018 [cited by applicant]
US 10581874B1 · Khalid et al. · 2020 [cited by applicant]
US 11444974B1 · Shakhzadyan et al. · 2022 [cited by applicant]
US 20020147694A1 · Dempsey et al. · 2002 [cited by applicant]
US 20150040232A1 · Oliphant et al. · 2015 [cited by applicant]
US 20150067857A1 · Symons et al. · 2015 [cited by applicant]
US 20150229661A1 · Balabine et al. · 2015 [cited by applicant]
US 20150254555A1 · Williams, Jr. et al. · 2015 [cited by applicant]
US 20170331854A1 · Reddy et al. · 2017 [cited by applicant]
US 20210073383A1 · Schmitt et al. · 2021 [cited by applicant]
Dobbins R., Ed., et al., “Use Cases for DDoS Open Threat Signaling,” Internet-Draft, Internet Engineering Task Force Trust, Mar. 21, 2016, 21 Pages. [cited by applicant]
Dobbins R., et al., “DDoS Open Threat Signaling (DOTS) Working Group,” 94th IETF, Nov. 1-6, 2015, 75 Pages. [cited by applicant]
Geller M., et al. “DF Client Integration within Cisco ISR,” Proof of Concept, Feb. 2016, pp. 1-25. [cited by applicant]
Mao C.H., et al., “Semi-Supervised Co-Training And Active Learning Based Approach For Multi-view Intrusion Detection,” SAC 09: Proceedings of the 2009 ACM symposium on Applied Computing, Mar. 8-12, 2009, pp. 2042-2048, … [cited by applicant]
Mortensen A., et al., “Distributed Denial of Service (DDoS) Open Threat Signaling Requirements: draft-ietf-dots-requirements-01,” DOTS, Mar. 18, 2016, 16 Pages, Internet Engineering Task Force Trust, Retrieved from the … [cited by applicant]
Reddy T., et al., “Co-operative DDoS Mitigation,” draft-reddy-dots-transport-06, Internet(IETF), Internet-Draft, Aug. 8, 2016, 29 Pages. [cited by applicant]