IP Library Granted Patent US 8,358,592
Granted Patent B2
US 8,358,592 · App. 12/470,000 · Granted Jan 22, 2013

Network controller and control method with flow analysis and control function

Inventors: Yoshinori Watanabe (Chigasaki, JP); Takashi Isobe (Machida, JP); Hidemitsu Higuchi (Ebina, JP); Takeshi Aimoto (Kawasaki, JP)
Assignee: Alaxala Networks Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,358,592
App. No.
12/470,000
Granted
Jan 22, 2013
Kind
B2
Abstract

A network controller, capable of high-speed extraction of malicious traffic from networks and determining characteristics of such traffic, includes a unit for accumulating a number of packets for each arbitrary itemset included in the header portions of packets to be transferred, and a unit for determining whether the accumulated value obtained by the accumulating unit exceeds a predetermined threshold, and determines the types of packets to be transferred from accumulated values of the itemset and an itemset different from the itemset when the number of packets exceed a threshold.

Claims (26)

1. A network controller for controlling a network that transmits and receives packets, comprising:

a first count section for counting the number of received packets having the same values for a first item group, the first item group consisting of a selected one or more items within a plurality of items contained in a flow information of the received packets,

a second count section for counting the number of received packets having the same values for a predetermined one or more items in addition to the first item group of the flow information of the received packets, and

a specific traffic detecting section that determines whether the count by the first count section exceeds a threshold and, if the count by the first count section exceeds the threshold, referring to the count by the second count section to determine abnormality types based on the count by the second count section,

wherein both of the count by the first count section and the count by the second count section are always incremented every time the network controller receives a packet having the same values for the first item group and for the predetermined one or more items in addition to the first item group of the flow information.

2. The network controller according to claim 1 , further comprising:

a packet receiving section that receives packets from the network, and

a flow information acquiring section that acquires the flow information from the received packets at the packet receiving section.

3. The network controller according to claim 1 , wherein:

the flow information includes at least one item of a source IP address, a destination IP address, a source port number and a destination port number.

4. The network controller according to claim 1 , wherein:

the specific traffic detecting section determines whether the count of the received packets having the same values for a second item group which includes items of a source address, a destination port number and a destination address, counted by the second count section, exceeds a predetermined value if the count of first packets having the same values for the first item group which includes items of a source address and a destination port number, counted by the first count section, exceeds the threshold.

5. The network controller according to claim 4 , wherein:

the specific traffic detecting section determines that an abnormality type of the received packets is a network worm when determining that the count of the received packets having the same values for the second item group exceeds the predetermined value.

6. The network controller according to claim 1 , wherein:

the specific traffic detecting section determines whether the count of the received packets having the same values for a second item group which includes items of a destination address, a destination port number and a source address, counted by the second count section, exceeds a predetermined value, if the count of first packets having the same values for the first item group which includes items of a destination address and a destination port number, counted by the first count section, exceeds the threshold.

7. The network controller according to claim 6 , wherein:

the specific traffic detecting section determines that an abnormality type of the received packets is a DDoS attack when determining that the count of the received packets having the same values for the second item group exceeds the predetermined value.

8. The network controller according to claim 1 , wherein:

the specific traffic detecting section determines whether the count of the received packets having the same source address, destination port number and destination address, counted by the second count section, satisfies a predetermined condition if the count of the received packets having the same values for the first item group which includes items of a source address and a destination port number, counted by the first count section, exceeds the threshold.

9. The network controller according to claim 8 , wherein:

the specific traffic detecting section determines that an abnormality type of the received packets is a network worm when determining that the count of the received packets, counted by the second count section, satisfies the predetermined condition.

10. The network controller according to claim 1 , wherein:

the specific traffic detecting section determines whether the count of the received packets having the same destination address, destination port number and source address, counted by the second count section, satisfies a predetermined condition if the count of the received packets having the same values for the first item group which includes items of a destination address and a destination port number, counted by the first count section, exceeds the threshold.

11. The network controller according to claim 10 , wherein:

the specific traffic detecting section determines that an abnormality type of the received packets is a DDoS attack when determining that the count of the received packets, counted by the second count section, satisfies the predetermined condition.

Priority Claims (2)
JP 2005-109744 · Apr 6, 2005 · national
JP 2006-019980 · Jan 30, 2006 · national
Continuity (2)
Continuation 11365609 · Mar 2, 2006
Related Publication 20090232000A1 · Sep 17, 2009