IP Library Granted Patent US 12689652
Granted Patent B1
US 12689652 · App. 18/758,474 · Granted Jul 21, 2026

Methods and devices for protecting a network service device

Inventors: Judge K. Arora (Eastsound, WA); Sandeep Agarwal (San Jose, CA); Timothy S. Michels (Greenacres, WA); Bruce A Zurfluh (Newman Lake, WA)
Assignee: F5, Inc.
H04L63/1458H04L63/0236H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12689652
App. No.
18/758,474
Granted
Jul 21, 2026
Kind
B1
Abstract

Methods, non-transitory computer readable media, network traffic manager apparatuses, and systems that protects a network service device are disclosed. The method includes in response to receiving a notification indicating an attack risk to the network service device, activates a timer for a predetermined time period during which a first request to establish a connection with the network service device is received. The method determines whether the first request originated from a legitimate source and adds the legitimate source to a trust list. After expiration of the timer, the method receives a data packet to be transmitted to the network service device and determines whether the data packet originated from any of the trusted sources in the trust list. The method restricts a transmission of data packet(s) not originated from any of the trusted sources in the trust list to the network service device.

Claims (92)

1 . A method for protecting a network service device, the method implemented by a network traffic management system comprising one or more network traffic management apparatuses, client devices, or server devices, the method comprising:

activating a timer for a predetermined time period;

during the activation of the timer, receiving a first request to establish a connection with the network service device and determining whether the first request originated from a legitimate source;

in response to determining that the first request originated from the legitimate source, adding the legitimate source to a trust list comprising one or more trusted sources;

after expiration of the timer, receiving a data packet to be transmitted to the network service device and determining a type of connection request associated with the data packet;

in response to the determining the type of connection request associated with the data packet is a new connection request, determining whether the data packet originated from any of the trusted sources in the trust list;

in response to the determining indicating that the data packet originated from at least one of the trusted sources in the trust list, transmitting the data packet to the network service device; and

in response to the determining the type of connection request associated with the data packet is an established connection before the activation of the timer, transmitting the data packet to the network service device.

2 . The method of claim 1 , wherein the data packet comprises a second request to establish a connection with the network service device, the method further comprising:

in response to determining that the second request did not originate from any of the trusted sources in the trust list, determining whether another source the second request originated from is a legitimate source; and

in response to determining that the another source is not a legitimate source, restricting a transmission of the second request to the network service device.

3 . The method of claim 1 , further comprising:

in response to determining that the data packet did not originate from any of the trusted sources in the trust list, restricting a transmission of the data packet to the network service device, wherein the restricting the transmission of the data packet to the network service device comprising at least one of:

discarding the received data packet;

performing a further inspection of the data packet before transmitting the data packet to the network service device; or

reducing a transmission priority on the transmission of the data packet to the network service device.

4 . The method of claim 3 , wherein reducing the transmission priority comprises setting a transmission rate upper limit on the transmission of the data packet to the network service device based on at least one of the following:

an elapsed period of time after a switchover from the network service device to a backup network device;

a ratio of a number of new connection data packets to a number of existing connection data packets, the new connection data packets representing data packets for establishing a connection with the network service device within a set of the data packets received after the expiration of the timer, and the existing connection data packets representing data packets associated with the connection established before the activation of the timer within the set of the data packets; or

a ratio of the number of data packet originated from any trusted sources in the trust list to the number of data packet not originated from any trusted sources in the trust list.

5 . The method of claim 1 , wherein the determining whether the first request originated from a legitimate source comprises:

transmitting a response comprising an identifier for the requested connection to a source the first request originated from; and

in response to receiving a request to reset the requested connection from the source, determining that the first request originated from a legitimate source.

6 . An apparatus for protecting a network service device, comprising memory comprising programmed instructions stored in the memory and one or more processors configured to execute the programmed instructions stored in the memory to:

activate a timer for a predetermined time period;

during the activation of the timer, receive a first request to establish a connection with the network service device and determine whether the first request originated from a legitimate source;

in response to determining that the first request originated from the legitimate source, add the legitimate source to a trust list comprising one or more trusted sources;

after expiration of the timer, receive a data packet to be transmitted to the network service device and determine a type of connection request associated with the data packet;

in response to the determining the type of connection request associated with the data packet is a new connection request, determine whether the data packet originated from any of the trusted sources in the trust list;

in response to the determining indicating that the data packet originated from at least one of the trusted sources in the trust list, transmit the data packet to the network service device; and

in response to the determining the type of connection request associated with the data packet is an established connection before the activation of the timer, transmit the data packet to the network service device.

7 . The apparatus of claim 6 , wherein the data packet comprises a second request to establish a connection with the network service device, the one or more processors are further configured to,

in response to determining that the second request did not originate from any of the trusted sources in the trust list, determine whether another source the second request originated from is a legitimate source; and

in response to determining that the another source is not a legitimate source, restrict a transmission of the second request to the network service device.

8 . The apparatus of claim 6 , the one or more processors are further configured to:

in response to determining that the data packet did not originate from any of the trusted sources in the trust list, restrict a transmission of the data packet to the network service device, wherein the restricting the transmission of the data packet to the network service device comprising at least one of:

discarding the received data packet;

performing a further inspection of the data packet before transmitting the data packet to the network service device; or

reducing a transmission priority on the transmission of the data packet to the network service device.

9 . The apparatus of claim 8 , wherein reducing the transmission priority comprises set a transmission rate upper limit on the transmission of the data packet to the network service device based on at least one of the following:

an elapsed period of time after a switchover from the network service device to a backup network device;

a ratio of a number of new connection data packets to a number of existing connection data packets, the new connection data packets representing data packets for establishing a connection with the network service device within a set of the data packets received after the expiration of the timer, and the existing connection data packets representing data packets associated with the connection established before the activation of the timer within the set of the data packets; or

a ratio of the number of data packet originated from any trusted sources in the trust list to the number of data packet not originated from any trusted sources in the trust list.

10 . The apparatus of claim 6 , wherein the determining whether the first request originated from a legitimate source comprises:

transmitting a response comprising an identifier for the requested connection to a source the first request originated from; and

in response to receiving a request to reset the requested connection from the source, determining that the first request originated from a legitimate source.

11 . A non-transitory computer readable medium having stored thereon instructions for protecting a network service device, comprising executable code which when executed by one or more processors, causes the one or more processors to:

activate a timer for a predetermined time period;

during the activation of the timer, receive a first request to establish a connection with the network service device and determine whether the first request originated from a legitimate source;

in response to determining that the first request originated from the legitimate source, add the legitimate source to a trust list comprising one or more trusted sources;

after expiration of the timer, receive a data packet to be transmitted to the network service device and determine a type of connection request associated with the data packet;

in response to the determining the type of connection request associated with the data packet is a new connection request, determine whether the data packet originated from any of the trusted sources in the trust list;

in response to the determining indicating that the data packet originated from at least one of the trusted sources in the trust list, transmit the data packet to the network service device; and

in response to the determining the type of connection request associated with the data packet is an established connection before the activation of the timer, transmit the data packet to the network service device.

12 . The non-transitory computer readable medium of claim 11 , wherein the data packet comprises a second request to establish a connection with the network service device, the one or more processors are further configured to,

in response to determining that the second request did not originate from any of the trusted sources in the trust list, determine whether another source the second request originated from is a legitimate source; and

in response to determining that the another source is not a legitimate source, restrict a transmission of the second request to the network service device.

13 . The non-transitory computer readable medium of claim 11 , the one or more processors are further caused to:

in response to determining that the data packet did not originate from any of the trusted sources in the trust list, restrict a transmission of the data packet to the network service device, wherein the restricting the transmission of the data packet to the network service device comprising at least one of:

discarding the received data packet;

performing a further inspection of the data packet before transmitting the data packet to the network service device; or

reducing a transmission priority on the transmission of the data packet to the network service device.

14 . The non-transitory computer readable medium of claim 13 , wherein reduce the transmission priority comprises set a transmission rate upper limit on the transmission of the data packet to the network service device based on at least one of the following:

an elapsed period of time after a switchover from the network service device to a backup network device;

a ratio of a number of new connection data packets to a number of existing connection data packets, the new connection data packets representing data packets for establishing a connection with the network service device within a set of the data packets received after the expiration of the timer, and the existing connection data packets representing data packets associated with the connection established before the activation of the timer within the set of the data packets; or

a ratio of the number of data packet originated from any trusted sources in the trust list to the number of data packet not originated from any trusted sources in the trust list.

15 . The non-transitory computer readable medium of claim 11 , wherein the determining whether the first request originated from a legitimate source comprises:

transmitting a response comprising an identifier for the requested connection to a source the first request originated from; and

in response to receiving a request to reset the requested connection from the source, determining that the first request originated from a legitimate source.

16 . A network traffic management system, comprising one or more traffic management apparatuses, server devices, or client devices, the network traffic management system comprising memory comprising programmed instructions stored thereon and one or more processors configured to execute the stored programmed instructions to:

activate a timer for a predetermined time period;

during the activation of the timer, receive a first request to establish a connection with a network service device and determine whether the first request originated from a legitimate source;

in response to determining that the first request originated from the legitimate source, add the legitimate source to a trust list comprising one or more trusted sources;

after expiration of the timer, receive a data packet to be transmitted to the network service device and determine a type of connection request associated with the data packet;

in response to the determining the type of connection request associated with the data packet is a new connection request, determine whether the data packet originated from any of the trusted sources in the trust list;

in response to the determining indicating that the data packet originated from at least one of the trusted sources in the trust list, transmit the data packet to the network service device; and

in response to the determining the type of connection request associated with the data packet is an established connection before the activation of the timer, transmit the data packet to the network service device.

17 . The network traffic management system of claim 16 , wherein the data packet comprises a second request to establish a connection with the network service device, the one or more processors are further configured to,

in response to determining that the second request did not originate from any of the trusted sources in the trust list, determine whether another source the second request originated from is a legitimate source; and

in response to determining that the another source is not a legitimate source, restrict a transmission of the second request to the network service device.

18 . The network traffic management system of claim 16 , the one or more processors are further configured to:

in response to determining that the data packet did not originate from any of the trusted sources in the trust list, restrict a transmission of the data packet to the network service device, the restricting the transmission of the data packet to the network service device comprising at least one of:

discarding the received data packet;

performing a further inspection of the data packet before transmitting the data packet to the network service device; or

reducing a transmission priority on the transmission of the data packet to the network service device.

19 . The network traffic management system of claim 18 , wherein reduce the transmission priority comprises set a transmission rate upper limit on the transmission of the data packet to the network service device based on at least one of the following:

an elapsed period of time after a switchover from the network service device to a backup network device;

a ratio of a number of new connection data packets to a number of existing connection data packets, the new connection data packets representing data packets for establishing a connection with the network service device within a set of the data packets received after the expiration of the timer, and the existing connection data packets representing data packets associated with the connection established before the activation of the timer within the set of the data packets; or

a ratio of the number of data packet originated from any trusted sources in the trust list to the number of data packet not originated from any trusted sources in the trust list.

20 . The network traffic management system of claim 16 , wherein the determining whether the first request originated from a legitimate source comprises:

transmitting a response comprising an identifier for the requested connection to a source the first request originated from; and

in response to receiving a request to reset the requested connection from the source, determining that the first request originated from a legitimate source.