The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 26, 2023

Filed:

Sep. 10, 2020
Applicant:

Arbor Networks, Inc., Westford, MA (US);

Inventors:

Steinthor Bjarnason, Fjerdingby, NO;

Brian St. Pierre, Acworth, NH (US);

Assignee:

ARBOR NETWORKS, INC., Westford, MA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); H04L 41/142 (2022.01); G06F 18/22 (2023.01); G06F 18/211 (2023.01);
U.S. Cl.
CPC ...
H04L 63/1458 (2013.01); G06F 18/211 (2023.01); G06F 18/22 (2023.01); H04L 41/142 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01);
Abstract

A method of automated filtering includes receiving a network traffic snapshot having packets with data stored in respective fields, generating a statistical data structure storing each potential unique combination of data stored in respective fields with an associated counter that is incremented for each occurrence that the combination matches one of the packets of the network traffic snapshot and one or more observation timestamps. Determining an observed vector from the statistical data structure, wherein the observed vector has associated attribute/value pairs and counters that satisfy a predetermined criterion. The observed vector's attribute/value pairs are compared to known attribute/value pairs associated with known DDoS attack vectors of an attack vector database. In response to finding a matching known attack vector as a result of the comparison, mitigation parameters associated with the known attack vector are selected and used for applying a countermeasure to the network traffic for mitigating an attack.


Find Patent Forward Citations

Loading…