Systems and methods for monitoring and mitigating network attacks
Abstract:
In a system for detecting and optionally blocking packets from an attacker, an improved multi-hash process, in which rate information for one or more packet signatures is computed by individual modules, where each module corresponds to a different hash function, and is shared across the modules to determine maximum observed rates for the signatures within a specified observation window. A moving average of the maximum rates can be computed across several observation windows, to optimize false negative and false positive detections. The modules may designate certain packets as potentially harmful and/or may block such packets, according to a corresponding maximum rate and specified threshold.
Public/Granted literature
Information query
Patent Agency Ranking
0/0