Invention Grant
- Patent Title: Avoidance of over-mitigation during automated DDOS filtering
-
Application No.: US16800874Application Date: 2020-02-25
-
Publication No.: US11330011B2Publication Date: 2022-05-10
- Inventor: Brian St. Pierre
- Applicant: Arbor Networks, Inc.
- Applicant Address: US MA Westford
- Assignee: Arbor Networks, Inc.
- Current Assignee: Arbor Networks, Inc.
- Current Assignee Address: US MA Westford
- Agency: Locke Lord LLP
- Agent Scott D. Wofsy; Christopher J. Capelli
- Main IPC: G06F21/64
- IPC: G06F21/64 ; H04L29/06

Abstract:
A method of detecting patterns for automated filtering of data is provided. The method includes receiving network traffic including bad traffic and good traffic, wherein an attack is known to be applied to the bad traffic, and the good traffic is known to be free of an applied attack. Processing the good and bad traffic includes generating, for each unique packet, each potential unique combination of the packet's fields, storing each combination with associated bad match and good match counters, and incrementing a combination's respective good and bad match counters for each occurrence it matches one of the packets of the respective good and bad traffic. The combinations are sorted based on the good match counter associated with each combination, a number of fields in each combination, and the bad match counter associated with each combination. One or more combination is selected based on results of the sorting for provision to a network traffic filtering component.
Public/Granted literature
- US20210266343A1 AVOIDANCE OF OVER-MITIGATION DURING AUTOMATED DDOS FILTERING Public/Granted day:2021-08-26
Information query