IP Library Granted Patent US 8,307,430
Granted Patent B1
US 8,307,430 · App. 12/022,729 · Granted Nov 6, 2012

Method and system for UDP flood attack detection

Assignee: Riorey, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,307,430
App. No.
12/022,729
Granted
Nov 6, 2012
Kind
B1
Abstract

A system and method is provided to identify UDP attacks. A processor determines a spectral density of packet timing intervals, a natural distance between the spectral density and a uniform distribution, and a non-linear amplifier applying a non-linear amplification to the natural distance to detect a denial-of-service attack. It uses the concept of traffic statistics analysis, i.e., spectral densities of arrived-packet timing intervals, calculates the KL-distance measurement and makes decision based on the output of a non-linear Gaussian amplifier, with which one can easily adjust the amplifier via selecting different parameters of mean and variance to satisfy system requirements of false-positive and false-negative UDP attack detections.

Claims (10)

1. A method for detecting distributed denial-of-service attacks, the method comprising:

determining a spectral density of packet timing intervals using a computer processor,

determining, using the computer processor, a natural distance between the spectral density and a uniform distribution, and

detecting, using the computer processor, a denial-of-service attack based on a non-linear amplification of the natural distance.

2. The method of claim 1 , wherein the natural distance has side values and center values, and the non-linear amplification suppresses the side values and amplifies the center values.

3. A detector for detecting distributed denial-of-service attacks, the system comprising: a computer processor configured to determine a spectral density of packet timing intervals, a natural distance between the spectral density and a uniform distribution, and a non-linear amplifier configured to apply a non-linear amplification to the natural distance to detect a denial-of-service attack.

4. The detector of claim 3 , wherein said processor is configured to determine a Kullback-Leibler distance between the spectral density and the uniform distribution.

5. The detector of claim 3 , wherein said processor is configured to determine that a denial-of-service attack is detected if the non-linear amplification of the natural distance is above a threshold.

6. The method of claim 1 , wherein said step of determining a natural distance comprises determining a Kullback-Leibler distance between the spectral density and the uniform distribution.

7. The method of claim 1 , further comprising determining that a denial-of-service attack is detected if the non-linear amplification of the natural distance is above a threshold.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2020
From: RR TEXAS DC HOLDINGS, INC.
To: RRAC, LLC
Reel/Frame 053003/0985 →
CHANGE OF NAME Recorded Jun 22, 2020
From: RIOREY, INC.
To: RR TEXAS DC HOLDINGS, INC.
Reel/Frame 053591/0995 →
CHANGE OF NAME Recorded Jun 22, 2020
From: RRAC, LLC
To: RIOREY LLC
Reel/Frame 053591/0998 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2008
From: CHEN, HONGDA; LU, LIJIN
To: RIOREY, INC.
Reel/Frame 020901/0603 →
Continuity (1)
Provisional Application 60898110 · Jan 30, 2007