Method and apparatus for large-scale automated distributed denial of service attack detection

Number of patents in Portfolio can not be more than 2000

United States of America Patent

PATENT NO 8001601
APP PUB NO 20070283436A1
SERIAL NO

11452623

Stats

ATTORNEY / AGENT: (SPONSORED)

Importance

Loading Importance Indicators... loading....

Abstract

See full text

A multi-staged framework for detecting and diagnosing Denial of Service attacks is disclosed in which a low-cost anomaly detection mechanism is first used to collect coarse data, such as may be obtained from Simple Network Management Protocol (SNMP) data flows. Such data is analyzed to detect volume anomalies that could possibly be indicative of a DDoS attack. If such an anomaly is suspected, incident reports are then generated and used to trigger the collection and analysis of fine grained data, such as that available in Netflow data flows. Both types of collection and analysis are illustratively conducted at edge routers within the service provider network that interface customers and customer networks to the service provider. Once records of the more detailed information have been retrieved, they are examined to determine whether the anomaly represents a distributed denial of service attack, at which point an alarm is generated.

Loading the Abstract Image... loading....

First Claim

See full text

Family

Loading Family data... loading....

Patent Owner(s)

Patent OwnerAddress
AT&T INTELLECTUAL PROPERTY II L P754 PEACHTREE STREET NE SUITE 7C ATLANTA GA 30308

International Classification(s)

Inventor(s)

Inventor Name Address # of filed Patents Total Citations
Duffield, Nicholas Summit, US 36 1044
Sekar, Vyas Pittsburgh, US 10 147
Spatscheck, Oliver Randolph, US 189 4391
Van, Der Merwe Jacobus New Providence, US 59 3137

Cited Art Landscape

Load Citation

Patent Citation Ranking

Forward Cite Landscape

Load Citation