首页> 外国专利> Statistical automatic detection of malicious packets in DDoS attacks using an encoding scheme associated with payload content

Statistical automatic detection of malicious packets in DDoS attacks using an encoding scheme associated with payload content

机译:使用与有效载荷内容相关联的编码方案统计自动检测DDOS攻击中的恶意数据包

摘要

A method of detecting patterns in network traffic is provided. The method includes receiving a plurality of packets of network traffic, each packet having a payload populated with payload data and selecting payload lengths that occurred most frequently. For each of the selected payload lengths, a pattern template is generated using characters per position of the payload that satisfy a frequency criterion. A bit encoding scheme is assigned for each of the selected payload lengths and its associated pattern template. Each packet of the plurality of packets that has a payload length equal to any of the selected payload lengths and payload content that matches a pattern template generated for the payload is encoded into a single value. The single value uses the bit encoding scheme for the payload length and the pattern template matched. Each potential combination of fields representing the respective payload length and the pattern template is stored, with either all bits set per field when the field is active or no bits set per field when the field is inactive. A bitwise operation is performed on each encoded packet with the stored potential combinations. Results of the bitwise operation are stored in a sparse memory array. The results of the sparse array are sorted based on a number of the active fields and a number of occurrences of the respective results of the bitwise operation. The results of the sorting are provided to a mitigation device as an indication of whether an attack is underway and/or what type of attack is underway.
机译:提供了一种检测网络流量的模式的方法。该方法包括接收多个网络流量分组,每个分组具有填充有有效载荷数据的有效载荷并选择最频繁发生的有效载荷长度的分组。对于每个所选有效载荷长度,使用满足频率标准的有效载荷的每个位置的字符生成模式模板。为每个所选择的有效载荷长度及其相关的模式模板分配比特编码方案。多个分组的每个分组具有等于与所选择的有效载荷长度和与有效载荷生成的模式模板匹配的所选择的有效载荷长度和有效载荷内容被编码成单个值。单个值使用用于有效载荷长度的位编码方案和模式模板匹配。存储代表各自有效载荷长度和模式模板的每个潜在的字段组合,当该字段处于处于活动状态或者当该字段处于非活动状态时,当字段处于活动状态或未设置每个字段时,每个字段设置的所有位。在具有存储的潜在组合的每个编码分组上执行位操作。位操作的结果存储在稀疏存储器阵列中。稀疏阵列的结果基于多个活动场进行排序,以及按位操作的各个结果的各个出现的次数。分类的结果被提供给缓解装置,以指示攻击是否正在进行攻击和/或正在进行什么类型的攻击。

著录项

  • 公开/公告号US10951649B2

    专利类型

  • 公开/公告日2021-03-16

    原文格式PDF

  • 申请/专利权人 ARBOR NETWORKS INC.;

    申请/专利号US201916379028

  • 发明设计人 STEINTHOR BJARNASON;

    申请日2019-04-09

  • 分类号H04L29/06;G06N7/02;H04L12/24;

  • 国家 US

  • 入库时间 2022-08-24 17:42:35

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号