Patents Assigned to Arbor Networks, Inc.
  • Patent number: 7058015
    Abstract: A number of sensors are distributively deployed in a network, either integrally disposed in a number of routing devices of the network or externally disposed and coupled to the routing devices, to monitor and report on network traffic routed through the routing devices. A director is provided to receive network traffic reports from the sensors for the routing devices, and to determine whether moderating actions are to be taken to moderate an amount of network traffic, based at least in part on some of the network traffic reports received from the sensors. In one embodiment, upon determining moderating actions are to be taken, the director further determines what kind of moderating actions are to be taken, including where the moderating actions are to be taken. In one embodiment, the director further instructs appropriate ones of the sensors to cause the desired moderating actions to be applied on the network traffic going through some of the routing devices.
    Type: Grant
    Filed: August 4, 2000
    Date of Patent: June 6, 2006
    Assignee: Arbor Networks, Inc.
    Inventors: David J. Wetherall, Thomas E. Anderson, Stefan R. Savage
  • Patent number: 6965574
    Abstract: An apparatus is equipped to receive descriptive data for network traffic. In one embodiment, the apparatus is equipped to conditionally modify timing data of the network traffic to conform the timing data to the timing patterns of previously network traffic, when determined that the timing data of the network traffic are aberrations. Further, the apparatus is equipped with a query facility that supports a network oriented query language. The language includes specific network oriented language elements.
    Type: Grant
    Filed: June 20, 2001
    Date of Patent: November 15, 2005
    Assignee: Arbor Networks, Inc.
    Inventors: Christopher L. Cook, Gretta E. Bartels
  • Publication number: 20050216956
    Abstract: Technique for protecting a communications network, such a computer network, from attack such as self-propagating code violations of security policies, in which the network is divided into “compartments” that are separated by access control devices such as firewalls. The access control devices are then used to stop the spread of self-propagating attack code, the “zero-day” worms, for example. However, the access control devices are configured such that upon activation legitimate in-use network services will not be jeopardized.
    Type: Application
    Filed: July 8, 2004
    Publication date: September 29, 2005
    Applicant: Arbor Networks, Inc.
    Inventors: Douglas Orr, Thomas Ptacek, Douglas Song
  • Publication number: 20050018608
    Abstract: An apparatus is equipped to receive network traffic data for network traffic routed through a number of routing devices with one or more degrees of separation from a network node. The network traffic data include at least network traffic data for network traffic destined for the network node which meet a traffic type selection criteria and are routed by the routing devices to the network node. The apparatus is further equipped to progressively regulate and de-regulate network traffic routing by the routing devices based at least in part on the received network traffic data and the degrees of separation of the routing devices from the network node. Regulation extends from routing devices with the lowest degree of separation from the network node to routing devices with the highest degree of separation, following in the reverse direction of the routing paths traversed by the packets to reach the network node. In one embodiment, the extension or push back is made one degree of separation at a time.
    Type: Application
    Filed: August 24, 2004
    Publication date: January 27, 2005
    Applicant: Arbor Networks, Inc.
    Inventors: David Wetherall, Stefan Savage, Thomas Anderson
  • Publication number: 20050005017
    Abstract: Technique for protecting a communications network, such a computer network, from attack such as self-propagating code violations of security policies, in which the network is divided into “compartments” that are separated by access control devices such as firewalls. The access control devices are then used to stop the spread of self-propagating attack code, the “zero-day” worms, for example. However, the access control devices are configured such that upon activation legitimate in-use network services will not be jeopardized.
    Type: Application
    Filed: October 14, 2003
    Publication date: January 6, 2005
    Applicant: Arbor Networks, Inc.
    Inventors: Thomas Ptacek, Douglas Song, Jose Nazario
  • Patent number: 6801503
    Abstract: An apparatus is equipped to receive network traffic data for network traffic routed through a number of routing devices with one or more degrees of separation from a network node. The network traffic data include at least network traffic data for network traffic destined for the network node which meet a traffic type selection criteria and are routed by the routing devices to the network node. The apparatus is further equipped to progressively regulate and de-regulate network traffic routing by the routing devices based at least in part on the received network traffic data and the degrees of separation of the routing devices from the network node. Regulation extends from routing devices with the lowest degree of separation from the network node to routing devices with the highest degree of separation, following in the reverse direction of the routing paths traversed by the packets to reach the network node. In one embodiment, the extension or push back is made one degree of separation at a time.
    Type: Grant
    Filed: October 9, 2000
    Date of Patent: October 5, 2004
    Assignee: Arbor Networks, Inc.
    Inventors: David J. Wetherall, Stefan R. Savage, Thomas E. Anderson