IP Library Granted Patent US 9,854,067
Granted Patent B2
US 9,854,067 · App. 14/319,218 · Granted Dec 26, 2017

Controlling client access to a server application

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,854,067
App. No.
14/319,218
Granted
Dec 26, 2017
Kind
B2
Abstract

An approach is provided for controlling a rate at which requests from a client computer will be received by a server application executed on a server computer. Requests are received by the server computer at different times from the client computer and time intervals between different pairs of successive requests are measured. Based on the time intervals, (1) a historical rate of requests from the client computer is determined and a limit on a rate for the server application to receive subsequent requests from the client computer is determined and enforced based on the historical rate of requests, or (2) a range of the time intervals is determined to be within a predefined range of time intervals and based on the range being within the predefined range, a denial of service attack or an overload of requests from the client computer is determined and blocked.

Claims (43)

1. A method of controlling a rate at which requests from a client computer will be received by a server application, executed on a server computer, for processing, the method comprising the steps of:

the server computer receiving a multiplicity of requests at a respective multiplicity of different times from the client computer and measuring a multiplicity of time intervals between different pairs of successive requests of the multiplicity of requests;

the server computer determining a historical rate of requests from the client computer based in part on the multiplicity of time intervals; and

based in part on the historical rate of requests from the client computer, the server computer determining and enforcing a limit on a rate for the server application to receive subsequent requests from the client computer for processing.

2. The method of claim 1 , wherein the step of enforcing the limit on the rate for the server application to receive the subsequent requests includes sending a warning return code to indicate an excessive usage of the server application and warn the client computer to decrease a rate at which the client computer sends the subsequent requests to the server computer.

3. The method of claim 1 , wherein the step of enforcing the limit on the rate for the server application to receive the subsequent requests includes delaying a processing of a current request from the client computer for a predefined delay time interval.

4. The method of claim 1 , wherein the step of enforcing the limit on the rate for the server application to receive the subsequent requests includes temporarily halting a processing of the subsequent requests from the client computer until an end of a predefined reset time interval.

5. The method of claim 1 , wherein the step of enforcing the limit on the rate for the server application to receive the subsequent requests includes:

terminating a connection between the client computer and the server computer; and

permanently denying the subsequent requests from the client computer.

6. The method of claim 1 , further comprising the steps of:

the server computer receiving a first multiplicity of requests that include a user identifier which identifies a user who utilizes the client computer, and measuring a first multiplicity of time intervals between different pairs of successive requests of the first multiplicity of requests;

the server computer receiving a second multiplicity of requests from a network address of the client computer, and measuring a second multiplicity of time intervals between different pairs of successive requests of the second multiplicity of requests;

the server computer determining a first historical rate of requests based in part on the first multiplicity of time intervals; and

the server computer determining a second historical rate of requests based in part on the second multiplicity of time intervals,

wherein the step of enforcing the limit on the rate for the server application to receive the subsequent requests from the client computer is based in part on the first and second historical rates.

7. The method of claim 1 , further comprising the steps of:

the server computer receiving a pair of successive requests subsequent to the multiplicity of requests, the pair including a most recent request and a second most recent request, the most recent request being received by the server computer at a current time;

the server computer measuring a time interval between the most recent request and the second most recent request;

the server computer determining the time interval indicates a current rate of requests that is less than the historical rate of requests; and

based on the time interval indicating the current rate of requests being less than the historical rate of requests, the server computer stopping an enforcement of the limit on the rate for the server application to receive the subsequent requests from the client computer for processing.

8. A computer program product for controlling a rate at which requests from a client computer will be received by a server application, executed on a server computer, for processing, the computer program product comprising:

one or more computer-readable storage devices and program instructions stored on the one or more storage devices, the program instructions comprising:

program instructions to receive a multiplicity of requests at a respective multiplicity of different times from the client computer and measure a multiplicity of time intervals between different pairs of successive requests of the multiplicity of requests;

program instructions to determine a historical rate of requests from the client computer based in part on the multiplicity of time intervals; and

program instructions to determine and enforce, based in part on the historical rate of requests from the client computer, a limit on a rate for the server application to receive subsequent requests from the client computer for processing.

9. The computer program product of claim 8 , wherein the program instructions to enforce the limit on the rate for the server application to receive the subsequent requests send a warning return code to indicate an excessive usage of the server application and warn the client computer to decrease a rate at which the client computer sends the subsequent requests to the server computer.

10. The computer program product of claim 8 , wherein the program instructions to enforce the limit on the rate for the server application to receive the subsequent requests delay a processing of a current request from the client computer for a predefined delay time interval.

11. The computer program product of claim 8 , wherein the program instructions to enforce the limit on the rate for the server application to receive the subsequent requests temporarily halt a processing of the subsequent requests from the client computer until an end of a predefined reset time interval.

12. The computer program product of claim 8 , wherein the program instructions to enforce the limit on the rate for the server application to receive the subsequent requests:

terminate a connection between the client computer and the server computer; and

permanently deny the subsequent requests from the client computer.

13. The computer program product of claim 8 , further comprising program instructions, stored on the one or more storage devices, to:

receive a first multiplicity of requests that include a user identifier which identifies a user who utilizes the client computer, and measure a first multiplicity of time intervals between different pairs of successive requests of the first multiplicity of requests;

receive a second multiplicity of requests from a network address of the client computer, and measure a second multiplicity of time intervals between different pairs of successive requests of the second multiplicity of requests;

determine a first historical rate of requests based in part on the first multiplicity of time intervals; and

determine a second historical rate of requests based in part on the second multiplicity of time intervals,

wherein the program instructions to enforce the limit on the rate for the server application to receive the subsequent requests from the client computer enforce the limit on the rate based in part on the first and second historical rates.

14. The computer program product of claim 8 , further comprising program instructions, stored on the one or more storage devices, to:

receive a pair of successive requests subsequent to the multiplicity of requests, the pair including a most recent request and a second most recent request, the most recent request being received by the server computer at a current time;

measure a time interval between the most recent request and the second most recent request;

determine the time interval indicates a current rate of requests that is less than the historical rate of requests; and

based on the time interval indicating the current rate of requests being less than the historical rate of requests, stop an enforcement of the limit on the rate for the server application to receive the subsequent requests from the client computer for processing.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 057885/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2014
From: PURPURA, ROBERT J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 033211/0329 →