- Patent Title: Systems and methods for monitoring and mitigating network attacks
-
Application No.: US15056254Application Date: 2016-02-29
-
Publication No.: US10341364B2Publication Date: 2019-07-02
- Inventor: Thomas J. Teixeira , Thomas C. Porcher
- Applicant: Corero Networks Security, Inc.
- Applicant Address: US MA Hudson
- Assignee: Corero Networks Security, Inc.
- Current Assignee: Corero Networks Security, Inc.
- Current Assignee Address: US MA Hudson
- Agency: Goodwin Procter LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/911

Abstract:
In a system for detecting and optionally blocking packets from an attacker, an improved multi-hash process, in which rate information for one or more packet signatures is computed by individual modules, where each module corresponds to a different hash function, and is shared across the modules to determine maximum observed rates for the signatures within a specified observation window. A moving average of the maximum rates can be computed across several observation windows, to optimize false negative and false positive detections. The modules may designate certain packets as potentially harmful and/or may block such packets, according to a corresponding maximum rate and specified threshold.
Public/Granted literature
- US20160323302A1 SYSTEMS AND METHODS FOR MONITORING AND MITIGATING NETWORK ATTACKS Public/Granted day:2016-11-03
Information query