IP Library Granted Patent US 12689641
Granted Patent B2
US 12689641 · App. 18/486,709 · Granted Jul 21, 2026

Attack prevention for transmission control protocol layer

Inventors: Parminder Singh Sethi (Ludhiana, IN); Shree RamaKrishna Rathinasamy (Round Rock, TX); Anay Kishore (Bangalore, IN)
Assignee: Dell Products L.P.
H04L63/1425H04L63/0236H04L63/0281
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12689641
App. No.
18/486,709
Granted
Jul 21, 2026
Kind
B2
Abstract

A method comprises receiving one or more data packets corresponding to at least one communications protocol request, and scanning the one or more data packets to validate one or more elements corresponding to the at least one communications protocol request. The at least one communications protocol request is rejected in response to invalidating the one or more elements, and the at least one communications protocol request is forwarded to one or more servers in response to validating the one or more elements.

Claims (56)

1 . A method comprising:

receiving one or more data packets corresponding to at least one communications protocol request;

scanning the one or more data packets to validate one or more elements corresponding to the at least one communications protocol request;

rejecting the at least one communications protocol request in response to invalidating the one or more elements; and

forwarding the at least one communications protocol request to one or more servers of a data center in response to validating the one or more elements;

storing information corresponding to one or more rejected communications protocol requests and one or more forwarded communications protocol requests in one or more databases;

sending the one or more rejected communications protocol requests and one or more forwarded communications protocol requests to a machine learning model to generate one or more predictions of one or more improper requests based on the one or more stored rejected communications protocol requests and the one or more stored forwarded communications protocol requests; and

receiving the one or more predictions from the machine learning model and storing the one or more predictions in the one or more databases;

wherein the steps of the method are executed by a processing device operatively coupled to a memory, and the processing device resides in the data center and is connected behind a firewall component of the data center and between the firewall component and the one or more servers of the data center, and wherein the firewall component is further connected to a content delivery network server and to a backend server through the content delivery network server.

2 . The method of claim 1 wherein the at least one communications protocol request comprises a transmission control protocol request.

3 . The method of claim 1 wherein the one or more elements comprise at least one of one or more header fields and one or more flags.

4 . The method of claim 3 wherein validating the one or more elements comprises determining whether a size of the one or more header fields exceeds a designated threshold.

5 . The method of claim 3 wherein validating the one or more elements comprises verifying at least one of a source port and a destination port identified in the one or more header fields.

6 . The method of claim 3 wherein validating the one or more elements comprises verifying at least one of a sequence number and an acknowledgement number in the one or more header fields.

7 . The method of claim 1 wherein the at least one communications protocol request comprises a request to initiate a new connection and the one or more elements comprises a hash value for the request to initiate the new connection.

8 . The method of claim 1 further comprising:

identifying a plurality of the one or more data packets comprising a communications protocol request to initiate a new connection originating from the same Internet Protocol address;

determining whether a number of the plurality of the one or more data packets exceeds a designated threshold; and

rejecting the communications protocol requests to initiate the new connection corresponding to the plurality of the one or more data packets in response to determining that the number of the plurality of the one or more data packets exceeds the designated threshold.

9 . The method of claim 1 wherein validating the one or more elements comprises determining whether the one or more elements comply with one or more reverse proxy rules.

10 . The method of claim 1 further comprising:

receiving one or more additional data packets corresponding to at least one response to the at least one communications protocol request; and

scanning the one or more additional data packets to validate one or more elements corresponding to the at least one response.

11 . The method of claim 10 wherein validating the one or more elements corresponding to the at least one response comprises determining whether the one or more elements corresponding to the at least one response comply with one or more forward proxy rules.

12 . The method of claim 1 wherein the processing device comprises an edge device located at a same location as the one or more servers.

13 . An apparatus comprising:

a processing device comprising a processor operatively coupled to a memory and configured:

to receive one or more data packets corresponding to at least one communications protocol request;

to scan the one or more data packets to validate one or more elements corresponding to the at least one communications protocol request;

to reject the at least one communications protocol request in response to invalidating the one or more elements; and

to forward the at least one communications protocol request to one or more servers of a data center in response to validating the one or more elements;

storing information corresponding to one or more rejected communications protocol requests and one or more forwarded communications protocol requests in one or more databases;

sending the one or more rejected communications protocol requests and one or more forwarded communications protocol requests to a machine learning model to generate one or more predictions of one or more improper requests based on the one or more stored rejected communications protocol requests and the one or more stored forwarded communications protocol requests; and

receiving the one or more predictions from the machine learning model and storing the one or more predictions in the one or more databases;

wherein the processing device resides in the data center and is connected behind a firewall component of the data center and between the firewall component and the one or more servers of the data center, and wherein the firewall component is further connected to a content delivery network server and to a backend server through the content delivery network server.

14 . The apparatus of claim 13 wherein the at least one communications protocol request comprises a request to initiate a new connection and the one or more elements comprises a hash value for the request to initiate the new connection.

15 . The apparatus of claim 13 wherein the processing device is further configured:

to identify a plurality of the one or more data packets comprising a communications protocol request to initiate a new connection originating from the same Internet Protocol address;

to determine whether a number of the plurality of the one or more data packets exceeds a designated threshold; and

to reject the communications protocol requests to initiate the new connection corresponding to the plurality of the one or more data packets in response to determining that the number of the plurality of the one or more data packets exceeds the designated threshold.

16 . The apparatus of claim 13 wherein the at least one communications protocol request comprises a transmission control protocol request.

17 . The apparatus of claim 13 wherein the one or more elements comprise at least one of one or more header fields and one or more flags.

18 . An article of manufacture comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said at least one processing device to perform the steps of:

receiving one or more data packets corresponding to at least one communications protocol request;

scanning the one or more data packets to validate one or more elements corresponding to the at least one communications protocol request;

rejecting the at least one communications protocol request in response to invalidating the one or more elements; and

forwarding the at least one communications protocol request to one or more servers of a data center in response to validating the one or more elements;

storing information corresponding to one or more rejected communications protocol requests and one or more forwarded communications protocol requests in one or more databases;

sending the one or more rejected communications protocol requests and one or more forwarded communications protocol requests to a machine learning model to generate one or more predictions of one or more improper requests based on the one or more stored rejected communications protocol requests and the one or more stored forwarded communications protocol requests; and

receiving the one or more predictions from the machine learning model and storing the one or more predictions in the one or more databases;

wherein the processing device resides in the data center and is connected behind a firewall component of the data center and between the firewall component and the one or more servers of the data center, and wherein the firewall component is further connected to a content delivery network server and to a backend server through the content delivery network server.

19 . The article of manufacture of claim 18 wherein the at least one communications protocol request comprises a request to initiate a new connection and the one or more elements comprises a hash value for the request to initiate the new connection.

20 . The article of manufacture of claim 18 wherein the program code further causes said at least one processing device to perform the steps of:

identifying a plurality of the one or more data packets comprising a communications protocol request to initiate a new connection originating from the same Internet Protocol address;

determining whether a number of the plurality of the one or more data packets exceeds a designated threshold; and

rejecting the communications protocol requests to initiate the new connection corresponding to the plurality of the one or more data packets in response to determining that the number of the plurality of the one or more data packets exceeds the designated threshold.