Patents by Inventor Mark A. Shayman

Mark A. Shayman has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8443105
    Abstract: A device and method of routing traffic in a network by receiving the network, assigning a maximum temperature value to gateway nodes, calculating temperature values for router nodes, determining self-utilization values for nodes, determining neighborhood-utilization values for router nodes, determining pressure values for gateway nodes, determining pressure values for router nodes, identifying router node sent traffic, identifying neighboring nodes having higher temperatures than router node, identifying neighboring node with lowest pressure value, sending traffic to neighboring node with lowest pressure value, and stopping if the neighboring node is a gateway node, otherwise identifying the node as a router node and returning to the step of finding neighboring nodes.
    Type: Grant
    Filed: December 12, 2011
    Date of Patent: May 14, 2013
    Assignee: The United States of America as Represented by the Director, National Security Agency
    Inventors: Todd B. Finkler, Mark A. Shayman
  • Patent number: 8397284
    Abstract: A denial-of-service network attack detection system is deployable in single-homed and multi-homed stub networks. The detection system maintains state information of flows entering and leaving the stub domain to determine if exiting traffic exceeds traffic entering the system. Monitors perform simple processing tasks on sampled packets at individual routers in the network at line speed and perform more intensive processing at the routers periodically. The monitors at the routers form an overlay network and communicate pertinent traffic state information between nodes. The state information is collected and analyzed to determine the presence of an attack.
    Type: Grant
    Filed: January 17, 2007
    Date of Patent: March 12, 2013
    Assignee: University of Maryland
    Inventors: Chris Kommareddy, Samrat Bhattacharjee, Mark A. Shayman, Richard La
  • Patent number: 7992208
    Abstract: An estimate of a portion of network traffic that is nonconforming to a communication transmission control protocol is used to signal that a distributed denial of service attack may be occurring. Traffic flows are aggregated and packets are intentionally dropped from the flow aggregate in accordance with an assigned perturbation signature. The flow aggregates are observed to determine if the rate of arrival of packets that have a one-to-one transmission correspondence with the dropped packets are similarly responsive to the perturbation signature. By assigning orthogonal perturbation signatures to different routers, multiple routers may perform the test on the aggregate and the results of the test will be correctly ascertained at each router. Nonconforming aggregates may be redefined to finer granularity to determine the node on the network that is under attack, which may then take mitigating action.
    Type: Grant
    Filed: September 19, 2006
    Date of Patent: August 2, 2011
    Assignee: University of Maryland
    Inventors: Mehdi Kalantari Khandani, Mark A. Shayman
  • Patent number: 7391740
    Abstract: In a communication network, the responsiveness of the transmission rate of data packets to packet drops is quantified for an aggregate of flows as opposed to on a per-flow basis. In an Aggregate Perturbation Method (APM), a small number of data packets is intentionally dropped from the aggregate at a switching node and a response thereto is measured. Traffic not conforming to the predetermined transmission control protocol may be discovered as a decrement in the reduction in traffic rate compared to that anticipated based on the rate of dropped packets. To prevent interference from the simultaneous application of APM at multiple switching nodes, an orthogonal drop rate signature defining the instantaneous drop rate is assigned thereto. The orthogonal drop rate signature is based on the code division multiple access (CDMA) coding of data, and for that reason, APM with the application of orthogonal drop rate signatures is termed CDMA-based APM, or CAPM.
    Type: Grant
    Filed: April 16, 2004
    Date of Patent: June 24, 2008
    Assignee: University of Maryland
    Inventors: Mehdi K. Khandani, Mark A. Shayman
  • Publication number: 20080028467
    Abstract: A denial-of-service network attack detection system is deployable in single-homed and multi-homed stub networks. The detection system maintains state information of flows entering and leaving the stub domain to determine if exiting traffic exceeds traffic entering the system. Monitors perform simple processing tasks on sampled packets at individual routers in the network at line speed and perform more intensive processing at the routers periodically. The monitors at the routers form an overlay network and communicate pertinent traffic state information between nodes. The state information is collected and analyzed to determine the presence of an attack.
    Type: Application
    Filed: January 17, 2007
    Publication date: January 31, 2008
    Inventors: Chris Kommareddy, Samrat Bhattacharjee, Mark Shayman, Richard La
  • Publication number: 20070133420
    Abstract: Multiple paths in a communication network are provided between at least one source node and at least one destination node. The network arrangement may thus support either unicast transmission of data or multicast transmission. Measurements are made at nodes of the network to determine a partial network cost for data traversing the links in the multiple paths. An optimization procedure determines a distribution of the network traffic over the links between the at least one source node and the at least one destination node that incurs the minimum network cost.
    Type: Application
    Filed: October 24, 2006
    Publication date: June 14, 2007
    Inventors: Tuna Guven, Mark Shayman, Richard La, Samrat Bhattachargee
  • Publication number: 20070064610
    Abstract: An estimate of a portion of network traffic that is nonconforming to a communication transmission control protocol is used to signal that a distributed denial of service attack may be occurring. Traffic flows are aggregated and packets are intentionally dropped from the flow aggregate in accordance with an assigned perturbation signature. The flow aggregates are observed to determine if the rate of arrival of packets that have a one-to-one transmission correspondence with the dropped packets are similarly responsive to the perturbation signature. By assigning orthogonal perturbation signatures to different routers, multiple routers may perform the test on the aggregate and the results of the test will be correctly ascertained at each router. Nonconforming aggregates may be redefined to finer granularity to determine the node on the network that is under attack, which may then take mitigating action.
    Type: Application
    Filed: September 19, 2006
    Publication date: March 22, 2007
    Inventors: Mehdi Khandani, Mark Shayman
  • Publication number: 20040233846
    Abstract: In a communication network, the responsiveness of the transmission rate of data packets to packet drops is quantified for an aggregate of flows as opposed to on a per-flow basis. In an Aggregate Perturbation Method (APM), a small number of data packets is intentionally dropped from the aggregate at a switching node and a response thereto is measured. Traffic not conforming to the predetermined transmission control protocol may be discovered as a decrement in the reduction in traffic rate compared to that anticipated based on the rate of dropped packets. To prevent interference from the simultaneous application of APM at multiple switching nodes, an orthogonal drop rate signature defining the instantaneous drop rate is assigned thereto. The orthogonal drop rate signature is based on the code division multiple access (CDMA) coding of data, and for that reason, APM with the application of orthogonal drop rate signatures is termed CDMA-based APM, or CAPM.
    Type: Application
    Filed: April 16, 2004
    Publication date: November 25, 2004
    Inventors: Mehdi K. Khandani, Mark A. Shayman