US2013254886A1PendingUtilityA1
Mitigating Low-Rate Denial-Of-Service Attacks in Packet-Switched Networks
Est. expiryNov 18, 2029(~3.3 yrs left)· nominal 20-yr term from priority
H04L 63/1458G06F 21/55
49
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method includes determining, at a network routing device, an average packet drop rate for a plurality of aggregations of packet flows. The method also determines a threshold packet drop rate based on the average packet drop rate, a current packet drop rate for a select aggregation of the plurality of aggregations, and whether at least one packet flow of the select aggregation is potentially subject to a denial-of-service attack based on a comparison of the current packet drop rate to the threshold packet drop rate.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system for mitigating low-rate denial-of-service attacks in packet-switched networks, the system comprising:
a memory that stores instructions; a processor that executes the instructions to perform operations, the operations comprising: determining an average packet drop rate for a plurality of aggregations of packet flows; determining a threshold packet drop rate based on the average packet drop rate determined for the plurality of aggregations of the packet flows; determining a current packet drop rate for a select aggregation of the plurality of aggregations of the packet flows; and determining whether a packet flow of the select aggregation is potentially subject to a denial-of-service attack based on a comparison of the current packet drop rate to the threshold packet drop rate.
2 . The system of claim 1 , wherein the operations further comprise selecting packets for transmission that have a higher priority status over packets having a lower priority status.
3 . The system of claim 1 , wherein the operations further comprise assigning a higher priority status to packets of the packet flow of the select aggregation for transmission based on determining that the packet flow of the select aggregation is subject to the denial-of-service attack.
4 . The system of claim 1 , wherein the operations further comprise assigning a lower priority status to packets of the packet flow of the select aggregation for transmission based on determining that the packet flow of the select aggregation is not subject to the denial-of-service attack.
5 . The system of claim 1 , wherein the operations further comprise determining the average packet drop rate for the plurality of aggregations of packet flows based on a time sliding window composed of a contiguous set of time intervals.
6 . The system of claim 1 , wherein the operations further comprise determining that the packet flow of the select aggregation is subject to the denial-of-service attack if the comparison indicates that the current packet drop rate is greater than the threshold packet drop rate.
7 . The system of claim 1 , wherein the operations further comprise determining that the packet flow of the select aggregation is not subject to the denial-of-service attack if the comparison indicates that the current packet drop rate is less than the threshold packet drop rate.
8 . The system of claim 1 , wherein the operations further comprise adjusting the threshold packet drop rate based a type of application associated with the select aggregation.
9 . The system of claim 1 , wherein the operations further comprise selecting packets of the packet flow for transmission based on an active queue management policy.
10 . The system of claim 1 , wherein the operations further comprise selecting packets of the packet flow for transmission based on a weighted random early detection policy.
11 . The system of claim 1 , wherein the operations further comprise determining the average packet drop rate for the plurality of aggregations of the packet flows by utilizing an arrival counter and a drop counter.
12 . A system for mitigating low-rate denial-of-service attacks in packet-switched networks, the system comprising:
a memory that stores instructions; a processor that executes the instruction to perform operations, the operations comprising:
determining a first average packet drop rate for a plurality of aggregations of packet flows for a first interval;
determining a first threshold packet drop rate based on the first average packet drop rate;
assigning a higher priority status to packets of packet flows of a select aggregation of the plurality of aggregations at a first time in response to determining that a current packet drop rate of the select aggregation at the first time is greater than the first threshold packet drop rate; and
selecting, for transmission, packets of the packet flows having the higher priority status over packets of the packet flows having a lower priority status.
13 . The system of claim 12 , wherein the operations further comprise determining a second average packet drop rate for the plurality of aggregations of packet flows for a second interval that is after the first interval.
14 . The system of claim 13 , wherein the operations further comprise determining a second threshold packet drop rate based on the second average packet drop rate.
15 . The system of claim 14 , wherein the operations further comprise assigning a lower priority status to packets of the packet flows of the select aggregation at a second time in response to determining a current packet drop rate of the select aggregation at the second time is greater than the second threshold packet drop rate.
16 . The system of claim 15 , wherein the second time is subsequent to the first time.
17 . The system of claim 12 , wherein the operations further comprise adjusting the first threshold packet drop rate based a type of application associated with the select aggregation.
18 . The system of claim 12 , wherein the operations further comprise selecting packets of the packet flow for transmission based on an active queue management policy.
19 . The system of claim 12 , wherein the operations further comprise determining first the average packet drop rate for the plurality of aggregations of packet flows based on a time sliding window composed of a contiguous set of time intervals.
20 . A method for mitigating low-rate denial-of-service attacks in packet-switched networks, the method comprising:
determining, by utilizing instructions from memory that are executed by a processor, a first average packet drop rate for a plurality of aggregations of packet flows for a first interval; determining a first threshold packet drop rate based on the first average packet drop rate; assigning a lower priority status to packets of packet flows of a select aggregation of the plurality of aggregations at a first time in response to determining that a current packet drop rate of the select aggregation at the first time is less than the first threshold packet drop rate; and selecting, for transmission, packets of the packet flows having a higher priority status over packets of the packet flows having the lower priority status.Join the waitlist — get patent alerts
Track US2013254886A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.