The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 24, 2023

Filed:

Dec. 31, 2019
Applicant:

Radware, Ltd., Tel Aviv, IL;

Inventors:

Ehud Doron, Moddi'in, IL;

David Aviv, Tel Aviv, IL;

Eyal Rundstein, Giv'atayim, IL;

Lev Medvedovsky, Netanya, IL;

Assignee:

Radware, Ltd., Tel Aviv, IL;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); H04L 43/062 (2022.01); H04L 43/067 (2022.01); H04L 43/0876 (2022.01); H04L 43/16 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1458 (2013.01); H04L 43/062 (2013.01); H04L 43/067 (2013.01); H04L 43/0876 (2013.01); H04L 43/16 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); H04L 63/20 (2013.01);
Abstract

A method and system for protecting against quick UDP Internet connection (QUIC) based denial-of-service (DDoS) attacks. The system comprises extracting traffic features from at least traffic directed to a protected entity, wherein the traffic features demonstrate behavior of QUIC user datagram protocol (UDP) traffic directed to the protected entity, wherein the extract traffic features include at least one rate-base feature and at least one rate-invariant feature, and wherein the at least traffic includes QUIC packets; computing at least one baseline for each of the at least one rate-base feature and the at least one rate-invariant feature; and analyzing real-time samples of traffic directed to the protected entity to detect a deviation from each of the at least one computed baseline, wherein the deviation is indicative of a detected QUIC DDoS attack; and causing execution of at least one mitigation action when an indication of the detected QUIC DDoS attack is determined.


Find Patent Forward Citations

Loading…