Quarantine-based mitigation of effects of a local DoS attack

US9286473B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9286473-B2
Application numberUS-201414165439-A
CountryUS
Kind codeB2
Filing dateJan 27, 2014
Priority dateDec 31, 2013
Publication dateMar 15, 2016
Grant dateMar 15, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In one embodiment, techniques are shown and described relating to quarantine-based mitigation of effects of a local DoS attack. A management device may receive data indicating that one or more nodes in a shared-media communication network are under attack by an attacking node. The management device may then communicate a quarantine request packet to the one or more nodes under attack, the quarantine request packet providing instructions to the one or more nodes under attack to alter their frequency hopping schedule without allowing the attacking node to learn of the altered frequency hopping schedule.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising: receiving, at a management device, data indicating that one or more nodes in a shared-media communication network are under attack by an attacking node; and communicating a quarantine request packet to the one or more nodes under attack, the quarantine request packet providing instructions to the one or more nodes under attack to alter their frequency hopping schedule without allowing the attacking node to learn of the altered frequency hopping schedule by encrypting the frequency hopping schedule. 2. The method as in claim 1 , wherein the quarantine request packet includes a secret key that determines the altered frequency hopping schedule. 3. The method as in claim 1 , wherein the quarantine request packet includes a list of the one or more nodes under attack to be quarantined. 4. The method as in claim 1 , wherein the quarantine request packet determines the duration for which the one or more nodes under attack will be quarantined. 5. The method as in claim 1 , wherein the quarantine request packet is unicast or multicast to the one or more nodes under attack. 6. The method as in claim 1 , wherein the quarantine request packet is broadcast to the one or more nodes under attack. 7. The method as in claim 6 , wherein the quarantine request packet includes a compressed list of the one or more nodes under attack to be quarantined. 8. The method as in claim 1 , further comprising: communicating a quarantine state message to one or more shared-media networks to ensure the one or more shared-media networks are accepting new nodes. 9. A method, comprising: receiving a quarantine request packet at a node in a shared-media communication network; altering, based on the quarantine request packet, a frequency hopping schedule of the node without allowing an attacking node to learn of the altered frequency hopping schedule by encrypting the frequency hopping schedule. 10. The method as in claim 9 , further comprising: communicating a discovery beacon to indicate a public frequency schedule. 11. The method as in claim 10 , wherein the discovery beacon includes a quarantine flag. 12. The method as in claim 10 , wherein the discovery beacon includes an indication that the communicating node is in quarantine. 13. The method as in claim 9 , wherein the quarantine request packet includes a duration period for quarantine. 14. The method as in claim 13 , wherein the duration period for quarantine is dynamically adjusted. 15. An apparatus, comprising: one or more network interfaces to communicate within a computer network; a processor coupled to the network interfaces and configured to execute one or more processes; and a memory configured to store a process executable by the processor, the process when executed operable to: receive, at a management device, data indicating that one or more nodes in a shared-media communication network are under attack by an attacking node; and communicate a quarantine request packet to the one or more nodes under attack, the quarantine request packet providing instructions to the one or more nodes under attack to alter their frequency hopping schedule without allowing the attacking node to learn of the altered frequency hopping schedule by encrypting the frequency hopping schedule. 16. The apparatus as in claim 15 , wherein the quarantine request packet includes a secret key that determines the altered frequency hopping schedule. 17. The apparatus as in claim 15 , wherein the quarantine request packet includes a list of the one or more nodes under attack to be quarantined. 18. The apparatus as in claim 15 , wherein the quarantine request packet determines the duration for which the one or more nodes under attack will be quarantined. 19. The apparatus as in claim 15 , wherein the quarantine request packet is unicast or multicast to the one or more nodes under attack. 20. The apparatus as in claim 15 , wherein the quarantine request packet includes a compressed list of the one or more nodes under attack to be quarantined.

Assignees

Inventors

Classifications

  • Detection or prevention of fraud · CPC title

  • G06F21/554Primary

    involving event detection and direct action · CPC title

  • H04W12/125Primary

    Protection against power exhaustion attacks · CPC title

  • H04W12/122Primary

    Counter-measures against attacks; Protection against rogue devices · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9286473B2 cover?
In one embodiment, techniques are shown and described relating to quarantine-based mitigation of effects of a local DoS attack. A management device may receive data indicating that one or more nodes in a shared-media communication network are under attack by an attacking node. The management device may then communicate a quarantine request packet to the one or more nodes under attack, the quara…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/554. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Mar 15 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).