IP Library Granted Patent US 10,505,952
Granted Patent B2
US 10,505,952 · App. 15/320,171 · Granted Dec 10, 2019

Attack detection device, attack detection method, and attack detection program

Inventors: Hiroyuki Nooka (Musashino, JP); Yuji Yamada (Chiyoda-ku, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
H04L63/1416H04L63/1425H04L69/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,505,952
App. No.
15/320,171
Granted
Dec 10, 2019
Kind
B2
Abstract

An attack detection device including a packet collection unit that collects packets to be transmitted from a user terminal to a service providing server, a header-information acquisition unit that acquires header information from the packets, and an attack detection unit that determines whether each session is an attacking session by using the header information, wherein the attack detection unit compares a window size of a collected arbitrary packet and window sizes of other packets to one another for each of sessions, and when a comparison result satisfies a predetermined first condition, a corresponding session is detected as an attacking session.

Claims (31)

1. An attack detection device comprising:

processing circuitry configured to

collect packets to be transmitted from a client to a server;

acquire header information from the packets; and

determine whether each session is an attacking session by using the header information, wherein

the processing circuitry, for a corresponding session, determines if a predetermined condition occurs based on at least one of

(i) a window size of an arbitrary SYN packet is greater than the window size of a subsequent packet within the corresponding session by a threshold; and

(ii) after collecting a plurality of packets for the corresponding session, a ratio of a window size average value to a window size maximum value within the corresponding session is smaller than a predetermined threshold,

when the predetermined condition is determined to occur, the corresponding session is detected as an attacking session, and

wherein upon detection of the attacking session, the processing circuitry transmits attack detection information including information for specifying the attacking session to a manager terminal or transmits a reset packet to the server and the client to discontinue the attacking session.

2. The attack detection device according to claim 1 , wherein when a session establishing duration calculated by using the header information for each of sessions is larger than a predetermined threshold, the processing circuitry detects a corresponding session as an attacking session.

3. The attack detection device according to claim 1 , wherein the processing circuitry calculates a throughput by using the header information for each of the sessions, and when the throughput is smaller than a predetermined threshold, the processing circuitry detects a corresponding session as an attacking session.

4. The attack detection device according to claim 1 , wherein the processing circuitry determines if a predetermined condition occurs based on at least both of (i) and (ii).

5. An attack detection method executed by an attack detection device, comprising:

collecting packets to be transmitted from a client to a server;

acquiring header information from the packets;

determining whether each session is an attacking session by using the header information, wherein

for a corresponding session, determining if a predetermined condition occurs based on at least one of

(i) a window size of an arbitrary SYN packet is greater than the window size of a subsequent packet within the corresponding session by a threshold; and

(ii) after collecting a plurality of packets for the corresponding session, a ratio of a window size average value to a window size maximum value within the corresponding session is smaller than a predetermined threshold,

when the predetermined condition is determined to occur, the corresponding session is detected as an attacking session, and

wherein upon detection of the attacking session, the method includes transmitting attack detection information including information for specifying the attacking session to a manager terminal or transmits a reset packet to the server and the client to discontinue the attacking session.

6. A non-transitory computer-readable recording medium having stored an attack detection program that causes a computer to perform a method comprising:

collecting packets to be transmitted from a client to a server;

acquiring header information from the packets;

determining whether each session is an attacking session by using the header information, wherein

for a corresponding session, determining if a predetermined condition occurs based on at least one of

(i) a window size of an arbitrary SYN packet is greater than the window size of a subsequent packet within the corresponding session by a threshold; and

(ii) after collecting a plurality of packets for the corresponding session, a ratio of a window size average value to a window size maximum value within the corresponding session is smaller than a predetermined threshold,

when the predetermined condition is determined to occur, the corresponding session is detected as an attacking session, and

wherein upon detection of the attacking session, the method includes transmitting attack detection information including information for specifying the attacking session to a manager terminal or transmits a reset packet to the server and the client to discontinue the attacking session.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2016
From: NOOKA, HIROYUKI; YAMADA, YUJI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 040672/0659 →
Priority Claims (1)
JP 2014-138659 · Jul 4, 2014 · national
Continuity (1)
Related Publication 20170126714A1 · May 4, 2017