US2012260337A1PendingUtilityA1
System and Method for Avoiding and Mitigating a DDoS Attack
Est. expiryDec 14, 2025(expired)· nominal 20-yr term from priority
Inventors:Jacobus Van Der Merwe
H04L 63/1458H04L 69/22H04L 67/306
49
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Described is a system and method for receiving a data packet including a destination address and a source address, categorizing the data packet into a community based on the source address, wherein the community is predefined by a user corresponding to the destination address and selecting a treatment for the data packet based on the community. The method may be implemented on a router to avoid and/or mitigate the harmful effects of a Distributed Denial of Service (“DDoS”) attack on a computer system or network.
Claims
exact text as granted — not AI-modified1 .- 23 . (canceled)
24 . A non-transitory computer-readable storage medium storing a set of instructions executable by a processor, the set of instructions performing a method comprising:
selecting Internet Protocol (“IP”) prefixes for a community from a list of IP prefixes, the list being ranked by a most recent attack related to each of the IP prefixes on the list; storing a per-customer table for the community based on a destination address; receiving a data packet including the destination address and a source address; categorizing the data packet into the community based on the source address; and selecting a treatment for the data packet based on the community.
25 . The non-transitory computer-readable storage medium of claim 24 , wherein the treatment includes restricting further transmission of the data packet.
26 . The non-transitory computer-readable storage medium of claim 24 , wherein the treatment includes limiting the rate of the transmission of the data packet.
27 . The non-transitory computer-readable storage medium of claim 24 , wherein the treatment includes prioritizing the transmission of the data packet.
28 . The non-transitory computer-readable storage medium of claim 24 , wherein the treatment includes transmitting the data packet to a customer router corresponding to the destination address.
29 . The non-transitory computer-readable storage medium of claim 24 , wherein the per-customer table includes a plurality of communities.
30 . The non-transitory computer-readable storage medium of claim 24 , wherein the selecting includes performing a longest prefix match on the destination address.
31 . The non-transitory computer-readable storage medium of claim 24 , wherein the categorizing includes performing a longest prefix match on the source address.
32 . The non-transitory computer-readable storage medium of claim 24 , wherein the source and destination addresses are IP addresses.
33 . The non-transitory computer-readable storage medium of claim 24 , wherein the method further comprises:
comparing the destination address of the data packet to a customer address; retrieving the per-customer table based on the customer address; comparing the source IP address to the per-customer table to categorize the packet.
34 . A router, comprising:
a memory storing a set of computer readable instructions, a routing table that includes a correspondence between a plurality of communities and source addresses, and a plurality of per-customer tables having each community predefined by a user corresponding to destination addresses, the predefining of each community comprises selecting Internet Protocol (“IP”) prefixes for each community from a list of IP prefixes, the list being ranked by a most recent attack related to each of the IP prefixes on the list; and a processor executing the set of computer readable instructions to perform a method comprising,
categorizing each of a plurality of received data packet into one of the plurality of communities based on the source address of each data packet and the routing table,
selecting a treatment for each data packet based on the destination address of each data packet and a selected per-customer table.
35 . The router of claim 34 , wherein the processor compares the destination address of each data packet to a customer address and retrieves the selected per-customer table based on the customer address.
36 . The router of claim 35 , wherein the processor compares the destination address based on a longest prefix match on the destination address.
37 . The router of claim 34 , wherein the processor categorizes each data packet by comparing the source address based on a longest prefix match on the source address.
38 . The router of claim 34 , wherein the treatment includes restricting further transmission of the data packet.
39 . The router of claim 34 , wherein the treatment includes limiting the rate of the transmission of the data packet.
40 . The router of claim 34 , wherein the treatment includes prioritizing the transmission of the data packet.
41 . The router of claim 34 , wherein the treatment includes transmitting the data packet to a customer router corresponding to the destination address.
42 . The router of claim 34 , wherein the per-customer table includes a plurality of communities.
43 . A method, comprising:
receiving, from a service provider, a list of IP prefixes, the list being ranked by a most recent attack related to each of the IP prefixes; selecting one or more IP prefixes from the list; generating a per-customer table using the selected one or more IP prefixes, wherein the per-customer table includes a community corresponding to each of the one or more IP prefixes; and sending the per-customer table to the service provider.Join the waitlist — get patent alerts
Track US2012260337A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.