Patent · US Active

Detection and mitigation DDoS attacks performed over QUIC communication protocol

US11563772B2 · kind B2 · utility

10Cited by
4References
45Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 31, 2019
Grant dateJan 24, 2023
Priority date
Expiry dateDec 11, 2040

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/166
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method and system for protecting against quick UDP Internet connection (QUIC) based denial-of-service (DDoS) attacks. The system comprises extracting traffic features from at least traffic directed to a protected entity, wherein the traffic features demonstrate behavior of QUIC user datagram protocol (UDP) traffic directed to the protected entity, wherein the extract traffic features include at least one rate-base feature and at least one rate-invariant feature, and wherein the at least traffic includes QUIC packets; computing at least one baseline for each of the at least one rate-base feature and the at least one rate-invariant feature; and analyzing real-time samples of traffic directed to the protected entity to detect a deviation from each of the at least one computed baseline, wherein the deviation is indicative of a detected QUIC DDoS attack; and causing execution of at least one mitigation action when an indication of the detected QUIC DDoS attack is determined.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.