Invention Grant
- Patent Title: IPFIX-based detection of amplification attacks on databases
-
Application No.: US15444110Application Date: 2017-02-27
-
Publication No.: US10404738B2Publication Date: 2019-09-03
- Inventor: Mathias Scherman , Tomer Teller , Hanan Shteingart , Royi Ronen
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Workman Nydegger
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N20/00 ; H04L29/12

Abstract:
One embodiment illustrated herein includes a computer implemented method. The method includes acts for training an amplification attack detection system. The method includes obtaining a plurality of samples of IPFIX data. The method further includes using the IPFIX data to create a plurality of time-based, server samples on a per server basis such that each sample corresponds to a server and a period of time over which IPFIX data in the sample corresponds. The method further includes identifying a plurality of the server samples that are labeled positive for amplification attacks. The method further includes identifying a plurality of server samples that are labeled negative for amplification attacks. The method further includes automatically labeling at least some of the remaining server samples as positive or negative based on the previously identified labeled samples. The method further includes using the automatically labeled samples to train an amplification attack detection system.
Public/Granted literature
- US20180248906A1 IPFIX-Based Detection of Amplification Attacks on Databases Public/Granted day:2018-08-30
Information query