Health monitor based distributed denial of service attack mitigation

US9294503B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9294503-B2
Application numberUS-201314010221-A
CountryUS
Kind codeB2
Filing dateAug 26, 2013
Priority dateAug 26, 2013
Publication dateMar 22, 2016
Grant dateMar 22, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Provided are methods and systems for mitigating a DDoS event. The method may comprise receiving an indication of a collapse of a collapsible virtual data circuit associated with network data traffic. In response to the received indication of the collapse, the collapse may be attributed to the DDoS event. Furthermore, the method may comprise redirecting the network data traffic to one or more DDoS mitigation services. The method may further comprise mitigating the DDoS event by the one or more DDoS mitigation services.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for mitigating a distributed denial of service (DDoS) event, the method comprising: sending, by a processor, a request to a health monitor regarding a state of a remote network resource, the health monitor associated with a collapsible virtual data circuit that normally conveys network data traffic and collapses in response to a DDoS event by stopping flow of the network data traffic; in response to the request, receiving a notification at the processor from the health monitor of an interruption of the network data traffic due to the collapse of the collapsible virtual data circuit; in response to the notification, attributing the interruption of the network data traffic due to the collapse of the collapsible virtual data circuit to the DDoS event; changing a Domain Name System (DNS) name upon receiving the notification of the collapse of the collapsible virtual data circuit; redirecting the network data traffic to one or more DDoS mitigation services; sending a request to the health monitor associated with the collapsible virtual data circuit regarding the status of the network data traffic flow; and in response to the request regarding the status of the network data traffic flow, receiving a notification from the health monitor indicating a presence of the network data traffic in the collapsible virtual data circuit, the notification of the presence of the network data traffic in the collapsible virtual data circuit being attributed to a successful mitigation of the DDoS event. 2. The method of claim 1 , wherein the health monitor is implemented by one or more of the following: software, hardware, signaling, and database query. 3. The method of claim 1 , wherein the one or more DDoS mitigation services analyzes the network data traffic to detect DDoS data packages, and filters the DDoS data packages to provide filtered network data traffic. 4. The method of claim 1 , further comprising: receiving an indication from the health monitor of reestablishment of the network data traffic through the collapsible virtual data circuit; and directing the network data traffic back to the collapsible virtual data circuit. 5. The method of claim 4 , wherein the network data traffic includes filtered network data traffic. 6. The method of claim 1 , wherein the receiving of the notification of the collapse of the collapsible virtual data circuit is performed via at least one of the following: Ethernet, Internet Protocol (IP), and software defined network (SDN). 7. A system for mitigating a DDoS event, the system comprising a processor that: sends a request to a health monitor regarding a state of a remote network resource, the health monitor associated with a collapsible virtual data circuit that normally conveys network data traffic and collapses in response to a DDoS event by stopping flow of the network data traffic; in response to the request, receives a notification at the processor from the health monitor of an interruption of the network data traffic due to the collapse of the collapsible virtual data circuit; in response to the notification, attributes the interruption of the network data traffic due to the collapse of the collapsible virtual data circuit to the DDoS event; changes a Domain Name System (DNS) name upon receiving the notification of the collapse of the collapsible virtual data circuit; redirects the network data traffic to one or more DDoS mitigation services; sends a request to the health monitor associated with the collapsible virtual data circuit regarding the status of the network data traffic flow; and in response to the request regarding the status of the network data traffic flow, receives a notification from the health monitor indicating a presence of the network data traffic in the collapsible virtual data circuit, the notification of the presence of the network data traffic in the collapsible virtual data circuit being attributed to a successful mitigation of the DDoS event. 8. The system of claim 7 , wherein the health monitor is implemented by one or more of the following: software, hardware, signaling, and database query. 9. The system of claim 7 , wherein the one or more DDoS mitigation service: analyzes the network data traffic to detect DDoS data packages; and filters the DDoS data packages to provide filtered network data traffic. 10. The system of claim 7 , wherein the processor further: receives an indication from the health monitor of reestablishment of the network data traffic through the collapsible virtual data circuit; and directs the network data traffic back to the collapsible virtual data circuit. 11. The system of claim 10 , wherein the network data traffic includes filtered network data traffic. 12. The system of claim 7 , wherein the receiving of the notification of the collapse of the collapsible virtual data circuit is performed via at least one of Ethernet, Internet Protocol (IP), and software defined network (SDN). 13. A non-transitory machine-readable medium comprising instructions which, when executed by one or more processors, perform the following operations: send, by a processor, a request to a health monitor associated with a collapsible virtual data circuit regarding a state of a remote network resource, the collapsible virtual data circuit normally conveying network data traffic and collapsing in response to a DDoS event by stopping flow of the network data traffic; in response to the request, receive a notification at the processor from the health monitor of an interruption of the network data traffic due to the collapse of the collapsible virtual data circuit; in response to the notification, attribute the interruption of the network data traffic due to the collapse of the collapsible virtual data circuit to the DDoS event; change a Domain Name System (DNS) name upon receiving the notification of the collapse of the collapsible virtual data circuit; redirect the network data traffic to one or more DDoS mitigation services; send a request to the health monitor associated with the collapsible virtual data circuit regarding the status of the network data traffic flow; and in response to the request regarding the status of the network data traffic flow, receive a notification from the health monitor indicating a presence of the network data traffic in the collapsible virtual data circuit, the notification of the presence of the network data traffic in the collapsible virtual data circuit being attributed to a successful mitigation of the DDoS event. 14. The method of claim 1 further comprising mitigating, by the one or more DDoS mitigation services, the DDoS event.

Assignees

Inventors

Classifications

  • Denial of Service · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9294503B2 cover?
Provided are methods and systems for mitigating a DDoS event. The method may comprise receiving an indication of a collapse of a collapsible virtual data circuit associated with network data traffic. In response to the received indication of the collapse, the collapse may be attributed to the DDoS event. Furthermore, the method may comprise redirecting the network data traffic to one or more DD…
Who is the assignee on this patent?
Thompson Micheal, Groves Rich, A10 Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1458. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 22 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).