Patents by Inventor Donald N. Cohen

Donald N. Cohen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8806634
    Abstract: The invention computes approximate origins of data packets transmitted over the Internet. Law enforcement agencies and network operators can use it to assign responsibility for observed Internet activities. The invention uses a small number of cooperative locations (incoming links on routers or switches) to provide link identification data: whether a packet or did or did not traverse that location. The system uses these cooperative places to generate the link signature of a data packet—which cooperative locations observed and did not observe the packet. Potential origin locations are divided into pre-computed blocks that have the same link signatures to given destination locations. The blocks are used to generate reverse routing data, potential source addresses for different link signatures. Variations of the invention store relevant link identification and reverse routing data to find the origins of past packets or to compute the origins of packets from partial information about packets of interest.
    Type: Grant
    Filed: January 27, 2012
    Date of Patent: August 12, 2014
    Inventors: Donald N. Cohen, Krishnamurthy Narayanaswamy
  • Publication number: 20130028259
    Abstract: The invention computes approximate origins of data packets transmitted over the Internet. Law enforcement agencies and network operators can use it to assign responsibility for observed Internet activities. The invention uses a small number of cooperative locations (incoming links on routers or switches) to provide link identification data: whether a packet or did or did not traverse that location. The system uses these cooperative places to generate the link signature of a data packet—which cooperative locations observed and did not observe the packet. Potential origin locations are divided into pre-computed blocks that have the same link signatures to given destination locations. The blocks are used to generate reverse routing data, potential source addresses for different link signatures. Variations of the invention store relevant link identification and reverse routing data to find the origins of past packets or to compute the origins of packets from partial information about packets of interest.
    Type: Application
    Filed: January 27, 2012
    Publication date: January 31, 2013
    Inventors: Donald N. Cohen, Krishnamurthy Narayanaswamy
  • Patent number: 7523497
    Abstract: The invention prevents “packet flooding”, where an attacker uses up all available bandwidth to a victim with useless data. It can also be used to prevent some other related denial of service attacks. The defense is distributed among cooperating sites and routers. The sites identify data they don't want. The routers help sites to determine which routers forward that data. The sites then ask these routers to reduce the rate at which such data is forwarded. Variations of the defense protect against packet flooding attacks on routers and attacks in which an attacker tries to use up some service offered by a site.
    Type: Grant
    Filed: May 7, 2004
    Date of Patent: April 21, 2009
    Inventor: Donald N. Cohen
  • Publication number: 20040230839
    Abstract: The invention prevents “packet flooding”, where an attacker uses up all available bandwidth to a victim with useless data. It can also be used to prevent some other related denial of service attacks. The defense is distributed among cooperating sites and routers. The sites identify data they don't want. The routers help sites to determine which routers forward that data. The sites then ask these routers to reduce the rate at which such data is forwarded. Variations of the defense protect against packet flooding attacks on routers and attacks in which an attacker tries to use up some service offered by a site.
    Type: Application
    Filed: May 7, 2004
    Publication date: November 18, 2004
    Inventor: Donald N. Cohen
  • Patent number: 6789190
    Abstract: The invention prevents “packet flooding”, where an attacker uses up all available bandwidth to a victim with useless data. It can also be used to prevent some other related denial of service attacks. The defense is distributed among cooperating sites and routers. The sites identify data they don't want. The routers help sites to determine which routers forward that data. The sites then ask these routers to reduce the rate at which such data is forwarded. Variations of the defense protect against packet flooding attacks on routers and attacks in which an attacker tries to use up some service offered by a site.
    Type: Grant
    Filed: November 16, 2000
    Date of Patent: September 7, 2004
    Assignee: Computing Services Support Solutions, Inc.
    Inventor: Donald N. Cohen
  • Publication number: 20030084317
    Abstract: The invention is designed to eliminate or minimize the liability associated with “packet flooding” attacks originating from within a local area network connected to an external network such as one controlled by a university or governmental organization. In these attacks, an attacker uses up all available bandwidth to a victim with useless data. The invention performs its function by identifying and classifying data packets arriving at a “Reverse Firewall” for transmission to the external network using various techniques. For example, data packets that are sent in response to data packets received from the external network will receive a different classification and thus allocation of resources than data packets not sent in response to previously received packets.
    Type: Application
    Filed: October 31, 2001
    Publication date: May 1, 2003
    Inventor: Donald N. Cohen