发明授权
- 专利标题: Automatic detection of malicious packets in DDoS attacks using an encoding scheme
-
申请号: US16379240申请日: 2019-04-09
-
公开(公告)号: US11153334B2公开(公告)日: 2021-10-19
- 发明人: Steinthor Bjarnason , Andrew Ralph Beard , David Turnbull
- 申请人: Arbor Networks, Inc.
- 申请人地址: US MA Westford
- 专利权人: Arbor Networks, Inc.
- 当前专利权人: Arbor Networks, Inc.
- 当前专利权人地址: US MA Westford
- 代理机构: Locke Lord LLP
- 代理商 Scott D. Wofsy; Christopher J. Capelli
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; H04L29/06
摘要:
A method of detecting patterns in network traffic is provided. The method includes receiving packets of network traffic, performing a frequency analysis per field of the packets as a function of frequency of the occurrence of the same data in the corresponding field, and selecting top values which are values associated with each field of the set of fields that satisfy a criterion as having occurred most frequently in the packets as a function of a result of the frequency analysis. The method further includes assigning a bit encoding scheme that uses variable bit encoding to encode each of the top values for each field that has a top value, encoding into a single value each packet of the packets based on a bitfield representation that uses the encoding scheme for values associated with each field that has a top value, storing each potential combination of fields of the set of fields being processed, with all bits set per field when the field is an active field and no bits set when the field is inactive, performing a bitwise operation on each encoded packet with the stored potential combinations, sorting the results of the bitwise operation based on a number of the active fields and a number of occurrences of each same result of the bitwise operation, and providing the results of the sorting to a mitigation device for determining whether an attack is underway and/or for filtering network traffic for mitigating an attack.
公开/授权文献
信息查询