Methods and apparatus for controllably suppressing, at a network
management system, SNMP event trap messages received from network nodes
in a communications network are presented. The rate at which the traps
are received from the network nodes is monitored and if the rate exceeds
a threshold all subsequent traps received over a set time interval are
not processed. The rate is calculated by counting received event traps
over a time interval which is either preset or programmed. After the set
time interval has passed all newly received traps are monitored.
Information regarding traps received during the set time interval may be
logged. Additionally, nodes from which excessive traps are received and
indicating an event such as a Denial of Service (DoS) attack, are
identified so that remedial action can be taken.