The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.
The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.
Patent No.:
Date of Patent:
Aug. 16, 2011
Filed:
Jun. 14, 2006
Nicholas Duffield, Summit, NJ (US);
Jacobus Van Der Merwe, New Providence, NJ (US);
Vyas Sekar, Pittsburgh, PA (US);
Oliver Spatscheck, Randolph, NJ (US);
Nicholas Duffield, Summit, NJ (US);
Jacobus Van Der Merwe, New Providence, NJ (US);
Vyas Sekar, Pittsburgh, PA (US);
Oliver Spatscheck, Randolph, NJ (US);
AT&T Intellectual Property II, L.P., Atlanta, GA (US);
Abstract
A multi-staged framework for detecting and diagnosing Denial of Service attacks is disclosed in which a low-cost anomaly detection mechanism is first used to collect coarse data, such as may be obtained from Simple Network Management Protocol (SNMP) data flows. Such data is analyzed to detect volume anomalies that could possibly be indicative of a DDoS attack. If such an anomaly is suspected, incident reports are then generated and used to trigger the collection and analysis of fine grained data, such as that available in Netflow data flows. Both types of collection and analysis are illustratively conducted at edge routers within the service provider network that interface customers and customer networks to the service provider. Once records of the more detailed information have been retrieved, they are examined to determine whether the anomaly represents a distributed denial of service attack, at which point an alarm is generated.