Invention Grant
US09083730B2 Methods and apparatus to identify an internet protocol address blacklist boundary
有权
识别互联网协议地址黑名单边界的方法和装置
- Patent Title: Methods and apparatus to identify an internet protocol address blacklist boundary
- Patent Title (中): 识别互联网协议地址黑名单边界的方法和装置
-
Application No.: US14099600Application Date: 2013-12-06
-
Publication No.: US09083730B2Publication Date: 2015-07-14
- Inventor: Baris Coskun , Suhrid Balakrishnan , Suhas Mathur
- Applicant: AT&T Intellectual Property I, L.P.
- Applicant Address: US GA Atlanta
- Assignee: AT&T Intellectual Property I., L.P.
- Current Assignee: AT&T Intellectual Property I., L.P.
- Current Assignee Address: US GA Atlanta
- Agency: Hanley, Flight & Zimmerman, LLC
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; H04L29/06

Abstract:
Methods, apparatus, systems and articles of manufacture are disclosed to identify an Internet protocol address blacklist boundary. An example method includes identifying a netblock associated with a malicious Internet protocol address, the netblock having a lower boundary and an upper boundary, collecting netflow data associated with a plurality of Internet protocol addresses in the netblock, establishing a first window associated with a lower portion of Internet protocol addresses numerically lower than a candidate Internet protocol address, establishing a second window associated with an upper portion of Internet protocol addresses numerically higher than a candidate Internet protocol address, calculating a breakpoint score based on a comparison between a behavioral profile of the first window and a behavioral profile of the second window, and identifying a first sub-netblock when the breakpoint score exceeds a threshold value.
Public/Granted literature
- US20150163235A1 METHODS AND APPARATUS TO IDENTIFY AN INTERNET PROTOCOL ADDRESS BLACKLIST BOUNDARY Public/Granted day:2015-06-11
Information query