Neural network based spoofing detection

US10911488B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10911488-B2
Application numberUS-201816101794-A
CountryUS
Kind codeB2
Filing dateAug 13, 2018
Priority dateSep 22, 2017
Publication dateFeb 2, 2021
Grant dateFeb 2, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for mitigating a spoofing-based attack include calculating a travel distance between a source Internet Protocol (IP) address and a target IP address from a received packet based on time-to-live information from the received packet. An expected travel distance between the source IP address and the target IP address is estimated based on a sparse set of known source/target distances. It is determined that the received packet has a spoofed source IP address based on a comparison between the calculated travel distance and the expected travel distance. A security action is performed responsive to the determination that the received packet has a spoofed source IP address.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for mitigating a spoofing-based attack, comprising: calculating a travel distance between a source Internet Protocol (IP) address and a target IP address from a received packet based on time-to-live (TTL) information from the received packet; estimating an expected travel distance between the source IP address and the target IP address based on a sparse set of known source/target distances, by determining structural correspondences between the source IP address and one or more known source IP addresses, including splitting the source IP address into at least a beginning portion and an end portion and padding the beginning portion and the end portion to form a normalized IP source address; determining that the received packet has a spoofed source IP address using a hardcore processor based on a comparison between the calculated travel distance and the expected travel distance; and performing a security action responsive to the determination that the received packet has a spoofed source IP address, wherein the security action is selected from the group consisting of blocking traffic from the source IP address of the received packet, changing a system security policy, changing a packet filtering setting on an upstream device, discarding the packet, and performing deep packet inspection. 2. The method of claim 1 , wherein estimating the expected travel distance comprises providing the source IP address and the target IP address to a neural network, where an activation function for neurons in the neural network is determined as: f i = { i = 1 softsign ⁡ ( w d × 256 i = 0 × B 256 × 1 i = 0 + b d × 1 i = 0 ) i ∈ { 1 , … ⁢ , n } softsign ⁡ ( w d × ( 256 + d ) i ∈ { 1 , ⁢ … ⁢ , ⁢ n } × concat ⁡ ( B 256 × 1 i ∈ { 1 , ⁢ … ⁢ , n }

Assignees

Inventors

Classifications

  • H04L69/22Primary

    Parsing or analysis of headers · CPC title

  • service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title

  • Recurrent networks, e.g. Hopfield networks · CPC title

  • Matching criteria, e.g. proximity measures · CPC title

  • Feedforward networks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10911488B2 cover?
Methods and systems for mitigating a spoofing-based attack include calculating a travel distance between a source Internet Protocol (IP) address and a target IP address from a received packet based on time-to-live information from the received packet. An expected travel distance between the source IP address and the target IP address is estimated based on a sparse set of known source/target dis…
Who is the assignee on this patent?
Nec Lab America Inc, Nec Corp
What technology area does this patent fall under?
Primary CPC classification H04L69/22. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 02 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).