| CPC H04L 63/1458 (2013.01) [G06N 20/00 (2019.01); H04L 63/1425 (2013.01); H04L 2463/144 (2013.01)] | 21 Claims |

|
1. A method comprising:
monitoring, at an attack detector in a network, network traffic to detect a Distributed Denial of Service (DDoS) attack by applying one or more first-level attack detection models against one or more attributes of the network traffic;
in response to detection of a DDoS attack,
causing network traffic associated with the DDoS attack to be diverted to an attack mitigation device, wherein the attack mitigation device is configured to perform a mitigation action on attack traffic in the network;
assessing, by the attack mitigation device, the network traffic associated with the DDoS attack using deep packet inspection and a second attack detection model;
providing, by the attack mitigation device, feedback to the attack detector regarding the detected DDoS attack, wherein the feedback indicates a false positive; and
refining at least one of the one or more first-level attack detection models applied by the attack detector based on the feedback.
|