Managing network mitigation techniques
The present disclosure generally relates to systems and methods for the monitoring and characterization of network access activities as indicative of enumeration of network resources. A monitoring and mitigation service can monitor attributes of network resource access to characterize or identify the likelihood of enumeration activities. The characterization can be expressed as a confidence value based on historical access information. For characterizations that exceed a threshold, the monitoring and mitigation service can then identify network mitigation techniques to mitigate the impact or potential for enumeration.
1 . A system for managing network-based services, the system comprising:
one or more computing devices associated with a processor and a memory for executing computer-executable instructions to implement a monitoring and mitigation service, wherein the monitoring and mitigation service is configured to:
obtain one or more attributes of network resource utilization corresponding to communications with network-based resources by a computing device;
monitor the one or more attributes of the network resource utilization of the computing device as indicative of enumeration activity;
characterize a likelihood of enumeration activity, wherein characterizing the likelihood of enumeration activity includes:
determining whether the computing device has been authorized within a prescribed time window to access the network-based resources; and
assigning a confidence value that quantitatively expresses a likelihood that the computing device performed an enumeration on the network-based resources based on an input of a determination of whether the computing device has been authorized within the prescribed time window to access the network-based resources and the monitored one or more attributes of the network resource utilization of the computing device, wherein the enumeration identifies potential vulnerabilities for a distributed denial of service attack on the network-based resources;
identify network mitigation techniques responsive to the confidence value exceeding a threshold, wherein the network mitigation techniques are dependent on historical analysis of enumeration of the network-based resources; and
cause an implementation of the network mitigation techniques in one or more routing components associated with the network-based resources such that the communications with the network-based resources by the computing device are mitigated.
2 . The system as recited in claim 1 , wherein the prescribed time window corresponds to a twenty-four hour time window.
3 . The system as recited in claim 1 , wherein the network resource utilization corresponding to the communications with the network-based resources by the computing device corresponds to one or more attributes of network access communications.
4 . The system as recited in claim 1 , wherein the network mitigation techniques correspond to a throttling of network communications.
5 . The system as recited in claim 1 , wherein the network mitigation techniques correspond to suppression of acknowledge messages.
6 . The system as recited in claim 1 , wherein the network mitigation techniques correspond to a selection of a non-responsive communication.
7 . The system as recited in claim 1 , wherein the determination of whether the computing device has been authorized within the prescribed time window includes detecting an authentication of the computing device.
8 . A method for managing for network-based services comprising:
obtaining one or more attributes of network resource utilization corresponding to communications with network-based resources;
monitoring the one or more attributes of network resource utilization of a computing device indicative of enumeration activity;
characterizing a likelihood of enumeration activity, wherein characterizing the likelihood of enumeration activity includes:
determining whether the computing device has been authorized within a prescribed time window to access the network-based resources; and
assigning a confidence value that quantitatively expresses a likelihood that the computing device performed an enumeration on the network-based resources based on an input of whether the computing device has been authorized within the prescribed time window to access the network-based resources and the monitored one or more attributes of the network resource utilization of the computing device, wherein the enumeration identifies potential vulnerabilities for a distributed denial of service attack on the network-based resources;
identifying one or more responsive actions, the one or more responsive actions corresponding to the confidence value; and
causing an implementation of the one or more responsive actions in one or more routing components associated with the network-based resources.
9 . The method as recited in claim 8 , wherein identifying the one or more responsive actions includes identifying the one or more responsive actions when the confidence value exceeds a threshold.
10 . The method as recited in claim 9 , wherein the threshold is a dynamic threshold.
11 . The method as recited in claim 10 , wherein the prescribed time window corresponds to a twenty-four hour time window.
12 . The method as recited in claim 8 , wherein monitoring the one or more attributes of the network resource utilization includes monitoring network traffic for a period of time to identify attributes of at least one of a shared network address or a dedicated network address.
13 . The method as recited in claim 8 , wherein the network resource utilization corresponding to communications with the network-based resources by the computing device corresponds to one or more attributes of network access communications.
14 . The method as recited in claim 8 , wherein the one or more responsive actions corresponds to at least one network mitigation technique, wherein the at least one network mitigation technique causes a mitigation of network communications between the computing device and the network-based resources.
15 . The method as recited in claim 14 , wherein the at least one network mitigation technique corresponds to a throttling of the network communications.
16 . The method as recited in claim 14 , wherein the at least one network mitigation technique corresponds to suppression of acknowledge messages.
17 . The method as recited in claim 14 , wherein the at least one network mitigation technique corresponds to a selection of a non-responsive communication.
18 . The method as recited in claim 8 , wherein the one or more responsive actions corresponds to at least one network monitoring technique, wherein the at least one network monitoring technique causes a capture of network communications between the computing device and the network-based resources.
19 . The method as recited in claim 8 , wherein the input of whether the computing device has been authorized within the prescribed time window includes detecting an authentication of the computing device.
20 . A non-transitory computer-readable storage medium storing computer executable instructions that when executed by one or more computer hardware processors perform operations comprising:
obtaining one or more attributes of network resource utilization corresponding to communications with network-based resources;
monitoring the one or more attributes of network resource utilization of a computing device indicative of enumeration activity;
characterizing a likelihood of enumeration activity, wherein characterizing the likelihood of enumeration activity includes:
determining whether the computing device has been authorized within a prescribed time window to access the network-based resources; and
assigning a confidence value that quantitatively expresses a likelihood that the computing device performed an enumeration on the network-based resources based on an input of whether the computing device has been authorized within the prescribed time window to access the network-based resources and the monitored one or more attributes of the network resource utilization of the computing device, wherein the enumeration identifies potential vulnerabilities for a distributed denial of service attack on the network-based resources;
identifying one or more responsive actions, the one or more responsive actions corresponding to the confidence value; and
causing an implementation of the one or more responsive actions in one or more routing components associated with the network-based resources.
21 . The non-transitory computer-readable storage medium of claim 20 , wherein the prescribed time window corresponds to a twenty-four hour time window.
22 . The non-transitory computer-readable storage medium of claim 20 , wherein the input of whether the computing device has been authorized within the prescribed time window includes detecting an authentication of the computing device.