Patent · US Active

Applying blocking measures progressively to malicious network traffic

US7707633B2 · kind B2 · utility

285Cited by
10References
10Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 12, 2007
Grant dateApr 27, 2010
Priority date
Expiry dateJul 20, 2028

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1458
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method of progressive response for invoking and suspending blocking measures that defend against network anomalies such as malicious network traffic so that false positives and false negatives are minimized. When an anomaly is detected, the detector notifies protective equipment such as a firewall or a router to invoke a blocking measure. The blocking measure is maintained for an initial duration, after which it is suspended while another test for the anomaly is made. If the anomaly is no longer evident, the method returns to the state of readiness. Otherwise, a loop is executed to re-apply the blocking measure for a specified duration, then suspend the blocking measure and test again for the anomaly. If the anomaly is detected, the blocking measure is re-applied, and its duration is adapted. If the anomaly is no longer detected, the method returns to the state of readiness.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.