IP Library › Granted Patent US 9,635,051
Granted Patent B2
US 9,635,051 · App. 15/055,995 · Granted Apr 25, 2017

Detecting and preventing flooding attacks in a network environment

Inventors: Shaohong Wei (Sunnyvale, CA); Gang Duan (San Jose, CA); Zhong Qiang Chen (Sunnyvale, CA); Bing Xie (Beijing, CN)
Assignee: Fortinet, Inc.
H04L63/1458H04L41/28H04L63/0236H04L63/14H04L63/1408H04L63/1416H04L63/1466H04L1/1835H04L43/16H04L2463/143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,635,051
App. No.
15/055,995
Granted
Apr 25, 2017
Kind
B2
Abstract

A method for processing network traffic data includes receiving a packet, and determining whether the packet is a previously dropped packet that is being retransmitted. A method for processing network traffic content includes receiving a plurality of headers, the plurality of headers having respective first field values, and determining whether the first field values of the respective headers form a first prescribed pattern. A method for processing network traffic content includes receiving a plurality of packets, and determining an existence of a flooding attack without tracking each of the plurality of packets with a SYN bit.

Claims (32)

1. A computer-implemented method for processing network traffic data in a gateway device for a computer network, the method comprising the steps of:

receiving a packet;

identifying whether the packet complies with a protocol having a retransmission protocol;

responsive to the packet complying, determining whether the packet is a previously dropped packet that is being retransmitted according to the retransmission protocol; and

dropping the packet responsive to the packet not being a retransmission of a previously dropped packet.

2. The method of claim 1 , further comprising:

forwarding the packet as safe responsive to the packet being a retransmission of the previously dropped packet.

3. The method of claim 1 , further comprising:

flagging the packet as potentially unsafe or as unsafe, responsive to multiple packets being dropped and of a certain characteristic in common.

4. The method of claim 1 , further comprising:

flagging the packet as potentially unsafe or as unsafe, responsive to multiple packets being dropped and of a certain characteristic in common.

5. The method of claim 1 , further comprising:

flagging the packet as part of a flooding attack, responsive to multiple packets being dropped and of a certain characteristic in common.

6. A non-transitory device-readable storage medium including a set of instructions stored thereon which when executed by a processor of a device, performs a method for processing network traffic data in a gateway device for a computer network, the method comprising the steps of:

receiving a packet;

identifying whether the packet complies with a protocol having a retransmission protocol;

responsive to the packet complying, determining whether the packet is a previously dropped packet that is being retransmitted according to the retransmission protocol; and

dropping the packet responsive to the packet not being a retransmission of a previously dropped packet.

7. The device-readable medium of claim 6 , wherein the method further comprises:

forwarding the packet as safe responsive to the packet being a retransmission of the previously dropped packet.

8. The device-readable medium of claim 6 , further comprising:

flagging the packet as potentially unsafe or as unsafe, responsive to multiple packets being dropped and of a certain characteristic in common.

9. The method of claim 1 , further comprising:

flagging the packet as part of a flooding attack, responsive to multiple packets being dropped and of a certain characteristic in common.

10. A gate way device having at least some hardware for processing network traffic data for a computer network, the method comprising the steps of:

a processor;

a network interface; and

a memory device, storing:

a first module to receive a packet;

a second module to identify whether the packet complies with a protocol having a retransmission protocol;

a third module to, responsive to the packet complying, determine whether the packet is a previously dropped packet that is being retransmitted according to the retransmission protocol; and

a fourth module to drop the packet responsive to the packet not being a retransmission of a previously dropped packet.

Continuity (8)
Continuation 14692707 · Apr 21, 2015
Continuation 14067575 · Oct 30, 2013
Continuation 13795429 · Mar 12, 2013
Continuation 13670585 · Nov 7, 2012
Continuation 12640985 · Dec 17, 2009
Continuation 12566371 · Sep 24, 2009
Continuation 11176494 · Jul 6, 2005
Related Publication 20160294865A1 · Oct 6, 2016