IP Library Granted Patent US 12701122
Granted Patent B1
US 12701122 · App. 17/643,797 · Granted Aug 4, 2026

Managing network mitigation techniques

Inventors: Patrick Collard (Seattle, WA); Stephen Goodman (Seattle, WA); John Paul Schweitzer (Seattle, WA); Luke Kenneth Schubert (Seattle, WA); William Kupersanin (Seattle, WA); Jacob Nguyen (Seattle, WA); Elisabeth Margaret Nagy (Seattle, WA); Wayne Alan Fullen (Seattle, WA); Michael Lowney (Seattle, WA); Jared Sylvester (Seattle, WA); Thomas Bradley Scholl (Seattle, WA); Kushal Mall (Seattle, WA); Darshan Narayana Reddy (Seattle, WA); Bradford Sachin Chatterjee (Seattle, WA); Gregory Stephen Molchany (Seattle, WA); Ravi Karnam (Seattle, WA); Edward Brindley (Seattle, WA)
Assignee: AMAZON TECHNOLOGIES, INC.
H04L63/108H04L41/142H04L43/16H04L63/0876H04L63/1416H04L63/1458H04L67/51
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12701122
App. No.
17/643,797
Granted
Aug 4, 2026
Kind
B1
Abstract

The present disclosure generally relates to systems and methods for the monitoring and characterization of network access activities as indicative of enumeration of network resources. A monitoring and mitigation service can monitor attributes of network resource access to characterize or identify the likelihood of enumeration activities. The characterization can be expressed as a confidence value based on historical access information. For characterizations that exceed a threshold, the monitoring and mitigation service can then identify network mitigation techniques to mitigate the impact or potential for enumeration.

Claims (44)

1 . A system for managing network-based services, the system comprising:

one or more computing devices associated with a processor and a memory for executing computer-executable instructions to implement a monitoring and mitigation service, wherein the monitoring and mitigation service is configured to:

obtain one or more attributes of network resource utilization corresponding to communications with network-based resources by a computing device;

monitor the one or more attributes of the network resource utilization of the computing device as indicative of enumeration activity;

characterize a likelihood of enumeration activity, wherein characterizing the likelihood of enumeration activity includes:

determining whether the computing device has been authorized within a prescribed time window to access the network-based resources; and

assigning a confidence value that quantitatively expresses a likelihood that the computing device performed an enumeration on the network-based resources based on an input of a determination of whether the computing device has been authorized within the prescribed time window to access the network-based resources and the monitored one or more attributes of the network resource utilization of the computing device, wherein the enumeration identifies potential vulnerabilities for a distributed denial of service attack on the network-based resources;

identify network mitigation techniques responsive to the confidence value exceeding a threshold, wherein the network mitigation techniques are dependent on historical analysis of enumeration of the network-based resources; and

cause an implementation of the network mitigation techniques in one or more routing components associated with the network-based resources such that the communications with the network-based resources by the computing device are mitigated.

2 . The system as recited in claim 1 , wherein the prescribed time window corresponds to a twenty-four hour time window.

3 . The system as recited in claim 1 , wherein the network resource utilization corresponding to the communications with the network-based resources by the computing device corresponds to one or more attributes of network access communications.

4 . The system as recited in claim 1 , wherein the network mitigation techniques correspond to a throttling of network communications.

5 . The system as recited in claim 1 , wherein the network mitigation techniques correspond to suppression of acknowledge messages.

6 . The system as recited in claim 1 , wherein the network mitigation techniques correspond to a selection of a non-responsive communication.

7 . The system as recited in claim 1 , wherein the determination of whether the computing device has been authorized within the prescribed time window includes detecting an authentication of the computing device.

8 . A method for managing for network-based services comprising:

obtaining one or more attributes of network resource utilization corresponding to communications with network-based resources;

monitoring the one or more attributes of network resource utilization of a computing device indicative of enumeration activity;

characterizing a likelihood of enumeration activity, wherein characterizing the likelihood of enumeration activity includes:

determining whether the computing device has been authorized within a prescribed time window to access the network-based resources; and

assigning a confidence value that quantitatively expresses a likelihood that the computing device performed an enumeration on the network-based resources based on an input of whether the computing device has been authorized within the prescribed time window to access the network-based resources and the monitored one or more attributes of the network resource utilization of the computing device, wherein the enumeration identifies potential vulnerabilities for a distributed denial of service attack on the network-based resources;

identifying one or more responsive actions, the one or more responsive actions corresponding to the confidence value; and

causing an implementation of the one or more responsive actions in one or more routing components associated with the network-based resources.

9 . The method as recited in claim 8 , wherein identifying the one or more responsive actions includes identifying the one or more responsive actions when the confidence value exceeds a threshold.

10 . The method as recited in claim 9 , wherein the threshold is a dynamic threshold.

11 . The method as recited in claim 10 , wherein the prescribed time window corresponds to a twenty-four hour time window.

12 . The method as recited in claim 8 , wherein monitoring the one or more attributes of the network resource utilization includes monitoring network traffic for a period of time to identify attributes of at least one of a shared network address or a dedicated network address.

13 . The method as recited in claim 8 , wherein the network resource utilization corresponding to communications with the network-based resources by the computing device corresponds to one or more attributes of network access communications.

14 . The method as recited in claim 8 , wherein the one or more responsive actions corresponds to at least one network mitigation technique, wherein the at least one network mitigation technique causes a mitigation of network communications between the computing device and the network-based resources.

15 . The method as recited in claim 14 , wherein the at least one network mitigation technique corresponds to a throttling of the network communications.

16 . The method as recited in claim 14 , wherein the at least one network mitigation technique corresponds to suppression of acknowledge messages.

17 . The method as recited in claim 14 , wherein the at least one network mitigation technique corresponds to a selection of a non-responsive communication.

18 . The method as recited in claim 8 , wherein the one or more responsive actions corresponds to at least one network monitoring technique, wherein the at least one network monitoring technique causes a capture of network communications between the computing device and the network-based resources.

19 . The method as recited in claim 8 , wherein the input of whether the computing device has been authorized within the prescribed time window includes detecting an authentication of the computing device.

20 . A non-transitory computer-readable storage medium storing computer executable instructions that when executed by one or more computer hardware processors perform operations comprising:

obtaining one or more attributes of network resource utilization corresponding to communications with network-based resources;

monitoring the one or more attributes of network resource utilization of a computing device indicative of enumeration activity;

characterizing a likelihood of enumeration activity, wherein characterizing the likelihood of enumeration activity includes:

determining whether the computing device has been authorized within a prescribed time window to access the network-based resources; and

assigning a confidence value that quantitatively expresses a likelihood that the computing device performed an enumeration on the network-based resources based on an input of whether the computing device has been authorized within the prescribed time window to access the network-based resources and the monitored one or more attributes of the network resource utilization of the computing device, wherein the enumeration identifies potential vulnerabilities for a distributed denial of service attack on the network-based resources;

identifying one or more responsive actions, the one or more responsive actions corresponding to the confidence value; and

causing an implementation of the one or more responsive actions in one or more routing components associated with the network-based resources.

21 . The non-transitory computer-readable storage medium of claim 20 , wherein the prescribed time window corresponds to a twenty-four hour time window.

22 . The non-transitory computer-readable storage medium of claim 20 , wherein the input of whether the computing device has been authorized within the prescribed time window includes detecting an authentication of the computing device.