US2006075084A1PendingUtilityA1

Voice over internet protocol data overload detection and mitigation system and method

Assignee: LYON BARRETTPriority: Oct 1, 2004Filed: Sep 30, 2005Published: Apr 6, 2006
Est. expiryOct 1, 2024(expired)· nominal 20-yr term from priority
H04L 63/1458H04L 65/1101H04L 65/103H04L 65/1069H04L 65/80H04L 65/104H04L 63/1416H04L 63/02
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method is disclosed for detecting and/or mitigating an attempted overload condition targeting a voice over data or Internet protocol system, and the like. A network connection receives a plurality of VOIP or IPTV requests, for example. A processor detects whether two or more of the requests are substantially duplicate. The processor discards further received requests that are determined to be substantially duplicate.

Claims

exact text as granted — not AI-modified
1 . A system for detecting and mitigating an attempted overload condition targeting a voice over data system, comprising: 
 a network connection for receiving a plurality of VOIP requests;    a processor for determining whether two or more of the VIOP requests are substantially duplicate;    the processor further for discarding received VOIP requests that are determined to be substantially duplicate.    
   
   
       2 . The system of  claim 1 , wherein the processor discards any VOIP request that does not pass a sanity check.  
   
   
       3 . The system of  claim 1 , wherein the processor discards each request containing a domain name that is not on a list as a valid domain name.  
   
   
       4 . The system of  claim 4 , wherein the processor detects whether a threshold number of VOIP requests are duplicate by storing the received requests in a database, counting the number of requests that are substantially duplicate to produce a hit count over a period of time, and comparing the hit count against a threshold value.  
   
   
       5 . The system of  claim 4 , wherein the processor detects whether a threshold number of VOIP requests are duplicate by comparing one or more attributes of the VOIP requests.  
   
   
       6 . The system of  claim 1 , wherein the processor comprises an application specific integrated circuit.  
   
   
       7 . The system of  claim 1 , wherein the processor comprises a data center.  
   
   
       8 . A method for detecting and mitigating an attempted overload condition targeting a voice over data system, comprising: 
 receiving a plurality of VOIP requests;    determining whether two or more of the VOIP requests are substantially duplicate;    discarding received VOIP requests that are determined to be substantially duplicate.    
   
   
       9 . The method of  claim 8 , comprising discarding any of VOIP request that does not pass a sanity check.  
   
   
       10 . The method of  claim 8 , comprising each VOIP request containing a domain name that is not on a list as a valid domain name.  
   
   
       11 . The method of  claim 8 , wherein the step of detecting whether a threshold number of the plurality of VOIP requests received are duplicate comprises storing the received requests in a database, counting the number of requests that are substantially duplicate to produce a hit count over a period of time, and comparing the hit count against a threshold value.  
   
   
       12 . The system of  claim 11 , wherein the step of detecting whether a threshold number of VOIP requests are duplicate is performed by comparing one or more attributes of the VOIP requests.  
   
   
       13 . A system for detecting an attempted overload condition targeting a voice over data system, comprising: 
 a network connection for receiving a plurality of VOIP requests;    a processor for determining whether two or more of the VOIP requests are substantially duplicate;    the processor further for discarding received VOIP requests that are determined to be substantially duplicate.    
   
   
       14 . A method for detecting an attempted overload condition targeting a voice over data system, comprising: 
 receiving a plurality of VOIP requests;    determining whether two or more of the VOIP requests are substantially duplicate;    discarding received VOIP requests that are determined to be substantially duplicate.    
   
   
       15 . A system for mitigating an attempted overload condition targeting a voice over data system, comprising: 
 a network connection for receiving a plurality of VOIP requests;    a processor for determining whether two or more of the VOIP requests are substantially duplicate, the processor further for discarding received VOIP requests that are determined to be substantially duplicate.    
   
   
       16 . A method for mitigating an attempted overload condition targeting a voice over data system, comprising: 
 receiving a plurality of SIP requests;    determining whether two or more of the SIP requests are substantially duplicate;    discarding received SIP requests that are determined to be substantially duplicate.    
   
   
       17 . A system for mitigating an attempted overload condition targeting a voice over data system, comprising: 
 a network connection for receiving a plurality of SIP packets;    a processor for determining whether two or more of the SIP packets are substantially duplicate, the processor further for discarding received SIP packets that are determined to be substantially duplicate.    
   
   
       18 . A system for mitigating an attempted overload condition targeting an IPTV system, comprising: 
 a network connection for receiving a plurality of IPTV requests;    a processor for determining whether two or more of the IPTV requests are substantially duplicate;    the processor further for discarding received IPTV requests that are determined to be substantially duplicate.    
   
   
       19 . A method for mitigating an attempted overload condition targeting an IPTV system, comprising: 
 receiving a plurality of IPTV requests;    determining whether two or more of the IPTV requests are substantially duplicate;    discarding received IPTV requests that are determined to be substantially duplicate.    
   
   
       20 . A system for mitigating an attempted overload condition targeting a voice over data system, comprising: 
 a network connection for receiving a plurality of VOIP requests;    a processor for determining whether two or more of the VOIP requests are substantially duplicate;    the processor further for applying a rate limit to limit the rate at which packets are received from a sender sending the VOIP requests that are determined to be substantially duplicate.    
   
   
       21 . A method for detecting an attempted overload condition targeting a voice over data system, comprising: 
 receiving a plurality of VOIP requests;    determining whether two or more of the VOIP requests are substantially duplicate;    applying a rate limit to limit the rate at which packets are received from a sender sending the VOIP requests that are determined to be substantially duplicate.    
   
   
       22 . A system for detecting an attempted overload condition targeting a networked computer system, comprising: 
 a network connection for receiving a volume of data;    a meter for measuring a current data rate, and to compare an average data rate of two or more previous measured data rates to the current data rate, wherein the meter is further to provide an alert to indicate a potential attack if the current data rate is substantially different than the average data rate.    
   
   
       23 . A method for detecting an attempted attack targeting a networked computer system, comprising: 
 receiving a volume of data;    measuring a current data rate;    comparing an average data rate of two or more previous measured data rates to the current data rate;    providing an alert to indicate a potential attack if the current data rate is substantially different than the average data rate.    
   
   
       24 . A method for mitigating an attempted attack targeting a networked computer system, comprising: 
 receiving network data; and    detecting a suspected attack;    mitigating the attack by providing synthesized responses in response to the attack, thereby masking mitigation of the attack.    
   
   
       25 . A system for mitigating an attempted overload condition targeting a networked computer system, comprising: 
 a network connection for receiving network data; and    a processor for detecting a suspected attack, wherein the processor is further to mitigate the attack by providing synthesized responses in response to the attack, thereby masking that the processor mitigates the attack.    
   
   
       26 . A method for mitigating an attempted attack targeting a networked computer system, comprising: 
 receiving a volume of network data over a period of time;    tracking the volume of network data over the period of time thereby detecting one or more trends in the network data;    detecting a suspected attack by detecting changes in the one or more trends in the network data.    
   
   
       27 . The method of  claim 26 , wherein the detecting is performed by a human viewing a graph illustrating the one or more trends in the network.  
   
   
       28 . The method of  claim 26 , wherein the detecting is performed by a computerized data trend monitor that detects the changes in the one or more trends in the network data.  
   
   
       29 . A system for mitigating an attempted attack targeting a networked computer system, comprising: 
 a network connection to receive a volume of network data over a period of time; and    a processor to track the volume of network data over the period of time to detect one or more trends in the network data, the processor further to detect a suspected attack by detecting changes in the one or more trends in the network data.    
   
   
       30 . The system of  claim 29 , further comprising a graph to present to a human to detect the changes in the one or more trends.  
   
   
       31 . The system of  claim 29 , wherein the processor includes a computerized data trend monitor to detect the changes in the one or more trends in the network data.

Join the waitlist — get patent alerts

Track US2006075084A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.