METHOD OF PROTECTION AGAINST DDOS-ATTACK ON BASIS OF TRAFFIC CLASSIFICATION Russian patent published in 2019 - IPC H04L12/26 H04L12/853 

Abstract RU 2704741 C2

FIELD: physics.

SUBSTANCE: invention relates to the computer equipment. Method of protection against DDoS attacks based on traffic classification is disclosed, which includes the steps of: receiving packets or packet streams from external devices attempting to access protected devices in a secure network; classifying received packets, determining whether they relate to one or more of the many types of traffic; applying countermeasures depending on the result of the classification. At the stage of classification: forming probabilistic statistics separately on the values of parameters as address fields of data packet headers, as well as the values of the characteristics of load fields thereof, forming the values of the address informative features as packets of the variability of the values of the parameters of the address fields of the data packet headers; estimating for representative samples and memorizing for all given types of traffic frequencies (empirical probabilities) of all formed targeted informative features; forming the values of the load informative features by packet streams as functions of the variability of the parameter values of the load fields of data packet headers; estimating for representative samples and remember for all given types of traffic frequencies (empirical probabilities) of all generated informative load characteristics; forming the likelihood values of belonging sets of values of address and load informative features to a given type of traffic based on their estimated frequencies; registering the flow of traffic packets and producing the additions thereto successively, forming a sequence of sets of values of address and load informative features; assessing the likelihood values of belonging to a sequence of sets of values of address and load informative features to a given type of traffic; assessing the likelihood of attributing traffic to a given type of attack; making the selection of the minimum value of the number of observations that provide in advance the specified values of the detection errors of the 1st and 2nd kinds for all estimated likelihood ratios, varying the number of added traffic packets; estimating the posterior probabilities of the specified types of traffic for each received packet stream; at the stage of applying multiple countermeasures, for each received packet stream, the estimated a posteriori probabilities of the specified types of traffic are taken into account.

EFFECT: technical result is an extension of the functionality of methods for detecting DDoS attacks and countering them by providing the ability to detect network attacks of various types on the basis of joint consideration of probabilistic statistics, formed separately by the values of parameters of both the address fields of the data packet headers and the load fields.

4 cl, 5 dwg

Similar patents RU2704741C2

Title Year Author Number
METHOD OF DETECTING NETWORK ATTACKS BASED ON ANALYSIS OF TRAFFIC TIME STRUCTURE 2017
  • Repin Dmitrij Sergeevich
  • Krasnov Andrej Evgenevich
  • Nadezhdin Evgenij Nikolaevich
  • Nikolskij Dmitrij Nikolaevich
  • Galyaev Vladimir Sergeevich
RU2680756C1
METHOD FOR DETECTING DESTABILIZING EFFECT ON COMPUTER NETWORK 2015
  • Andreyanov Sergej Nikolaevich
  • Marusov Dmitrij Valentinovich
  • Semenov Sergej Sergeevich
  • Stukalov Igor Vladislavovich
  • Truskov Stanislav Sergeevich
RU2611243C1
METHOD OF DETECTING NETWORK ATTACKS BASED ON ANALYZING FRACTAL TRAFFIC CHARACTERISTICS IN AN INFORMATION COMPUTER NETWORK 2019
  • Repin Dmitrij Sergeevich
  • Filaretov Gennadij Fedorovich
  • Chervova Almira Asnafovna
RU2713759C1
METHOD OF COMPUTER NETWORKS PROTECTION 2018
  • Gavrilov Aleksej Leonidovich
  • Katuntsev Sergej Leonidovich
  • Maksimov Roman Viktorovich
  • Orekhov Dmitrij Nikolaevich
  • Prokopenko Andrej Valerevich
  • Proskuryakov Igor Sergeevich
  • Sokolovskij Sergej Petrovich
RU2680038C1
METHOD FOR DETECTING NORMAL REACTIONS OF COMPUTER NETWORK NODES TO NETWORK PACKETS RELATED TO UNKNOWN TRAFFIC 2022
  • Antipinskii Andrei Sergeevich
  • Domukhovskii Nikolai Anatolevich
  • Komarov Denis Evgenevich
  • Sinadskii Aleksei Nikolaevich
RU2802164C1
METHOD OF PROTECTING COMPUTER NETWORKS 2018
  • Gavrilov Aleksej Leonidovich
  • Katuntsev Sergej Leonidovich
  • Maksimov Roman Viktorovich
  • Orekhov Dmitrij Nikolaevich
  • Malenkov Evgenij Sergeevich
  • Platov Nikolaj Evgenevich
  • Sokolovskij Sergej Petrovich
  • Shamanov Aleksej Igorevich
RU2690749C1
METHOD OF PROTECTING COMPUTER NETWORKS 2018
  • Barabanov Vladislav Valerevich
  • Efremov Anton Andreevich
  • Maksimov Roman Viktorovich
  • Orekhov Dmitrij Nikolaevich
  • Voronchikhin Ivan Sergeevich
  • Sokolovskij Sergej Petrovich
RU2696330C1
VOLUME DDOS ATTACKS PROTECTION SYSTEM AND METHOD 2022
  • Vakhrameev Leonid Aleksandrovich
  • Chernetsov Maksim Viktorovich
RU2791869C1
METHOD OF PROTECTING COMPUTER NETWORKS 2018
  • Gavrilov Aleksej Leonidovich
  • Katuntsev Sergej Leonidovich
  • Maksimov Roman Viktorovich
  • Orekhov Dmitrij Nikolaevich
  • Pryakhin Vyacheslav Petrovich
  • Timashenko Dmitrij Valerevich
  • Sokolovskij Sergej Petrovich
  • Timashenko Vladimir Konstantinovich
RU2686023C1
METHOD FOR DYNAMIC FILTRATION OF INTERNET PROTOCOL DATAGRAMS 2013
  • Larkin Evgenij Ivanovich
  • Slyshev Aleksandr Aleksandrovich
  • Kutuzov Aleksandr Viktorovich
  • Ivanov Jurij Borisovich
  • Basov Oleg Olegovich
RU2580808C2

RU 2 704 741 C2

Authors

Repin Dmitrij Sergeevich

Krasnov Andrej Evgenevich

Nadezhdin Evgenij Nikolaevich

Nikolskij Dmitrij Nikolaevich

Galyaev Vladimir Sergeevich

Zykova Evgeniya Andreevna

Dates

2019-10-30Published

2018-03-16Filed