IP Library Granted Patent US 11,277,439
Granted Patent B2
US 11,277,439 · App. 15/652,108 · Granted Mar 15, 2022

Systems and methods for mitigating and/or preventing distributed denial-of-service attacks

Inventor: Brian R. Knopf (Woodland Hills, CA)
Assignee: Neustar, Inc.
H04L63/1458H04L9/088H04L9/0891H04L9/14H04L9/321H04L9/3247H04L63/0209H04L63/0236H04L2463/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,277,439
App. No.
15/652,108
Granted
Mar 15, 2022
Kind
B2
Abstract

Systems and methods are described that mitigate and/or prevent distributed denial-of-service (DDOS) attacks. In one implementation, a gateway include one or more processors that obtain network data from one or more entities associated with the gateway, provide the network data to a server, and obtain a set of entity identifiers from the server. The set of entity identifiers may be generated based on at least the network data. The one or more processors may further filter communications based on the set of entity identifiers.

Claims (38)

1. A gateway for mitigating and/or preventing distributed denial-of-service (DDOS) attack, the gateway comprising:

one or more processors configured to:

obtain network data from one or more entities associated with the gateway, wherein the network data includes data derived from at least one of historical, current, or predicted network traffic data;

provide the network data to a server using a trusted process, wherein the trusted process includes:

obtaining a server signature from the server;

providing the server signature to a second server;

obtaining a second server signature from the second server; and

verifying the server signature from the server and the second server signature from a second server, wherein the server signature is generated based on at least a first portion of a set of entity identifiers, and wherein the second server signature is generated based on at least a second portion of the set of entity identifiers and provided to the gateway after the second server verifies the server signature;

obtain the set of entity identifiers from the server using the trusted process, wherein the set of entity identifiers comprises one or more entity identifiers identifying one or more DDOS compromised nodes and one or more entity identifiers identifying one or more DDOS target nodes, and wherein the set of entity identifiers is generated based on at least the at least one of historical, current, or predicted network traffic data; and

subsequent to verifying the second server signature, filter communications from a first DDOS compromised node of the one or more DDOS compromised nodes to a first DDOS target node of the one or more DDOS target nodes based at least in part on the set of entity identifiers.

2. The gateway of claim 1 , wherein the one or more processors are further configured to provide a gateway signature to the server, wherein the gateway signature is generated based on at least a first portion of the network data, and wherein the set of entity identifiers is generated after the server verifies the gateway signature.

3. The gateway of claim 1 , wherein the one or more DDS target nodes comprise one or more nodes that are determined by the server as being targets or potential targets of a DDOS attack, and wherein the filtering of the communications includes rejecting the communications from the first DDOS compromised node to the first DDOS target node.

4. The gateway of claim 1 , wherein the set of entity identifiers includes one or more identifiers associated with entities that are determined by the server as being trusted entities, and wherein the filtering of the communications include rejecting communications that are destined for entities other than the entities that are determined by the server as being trusted entities.

5. A method for mitigating and/or preventing distributed denial-of-service (DDOS) attacks, the method comprising:

obtaining network data from one or more entities associated with a gateway, wherein the network data includes data derived from at least one of historical, current, or predicted network traffic data;

providing the network data to a server using a trusted process, wherein the trusted process includes:

obtaining a server signature from the server;

providing the server signature to a second server;

obtaining a second server signature from the second server; and

verifying the server signature from the server and the second server signature from a second server, wherein the server signature is generated based on at least a first portion of a set of entity identifiers, and wherein the second server signature is generated based on at least a second portion of the set of entity identifiers and provided to the gateway after the second server verifies the server signature;

obtaining the set of entity identifiers from the server using the trusted process, wherein the set of entity identifiers comprises one or more entity identifiers identifying one or more DDOS compromised nodes and one or more entity identifiers identifying one or more DDOS target nodes, and wherein the set of entity identifiers is generated based on at least the at least one of historical, current, or predicted network traffic data; and

subsequent to verifying the second server signature, filtering communications from a first DDOS compromised node of the one or more DDOS compromised nodes to a first DDOS target node of the one or more DDOS target nodes based at least in part on the set of entity identifiers.

6. The method of claim 5 , further comprising:

providing a gateway signature to the server, wherein the gateway signature is generated based on at least a first portion of the network data, and wherein the set of entity identifiers is generated after the server verifies the gateway signature.

7. The method of claim 5 , wherein the one or more DDS target nodes comprise one or more nodes that are determined by the server as being targets or potential targets of a DDOS attack, and wherein the filtering of the communications includes rejecting the communications from the first DDOS compromised node to the first DDOS target node.

8. The method of claim 5 , wherein the set of entity identifiers includes one or more identifiers associated with entities that are determined by the server as being trusted entities, and wherein the filtering of the communications include rejecting communications that are destined for entities other than the entities that are determined by the server as being trusted entities.

9. A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for mitigating and/or preventing distributed denial-of-service (DDOS) attacks, the method comprising:

obtaining network data from one or more entities associated with a gateway, wherein the network data includes data derived from at least one of historical, current, or predicted network traffic data;

providing the network data to a server using a trusted process, wherein the trusted process includes:

obtaining a server signature from the server;

providing the server signature to a second server;

obtaining a second server signature from the second server; and

verifying the server signature from the server and the second server signature from a second server, wherein the server signature is generated based on at least a first portion of a set of entity identifiers, and wherein the second server signature is generated based on at least a second portion of the set of entity identifiers and provided to the gateway after the second server verifies the server signature;

obtaining the set of entity identifiers from the server using the trusted process, wherein the set of entity identifiers comprises one or more entity identifiers identifying one or more DDOS compromised nodes and one or more entity identifiers identifying one or more DDOS target nodes, and wherein the set of entity identifiers is generated based on at least the at least one of historical, current, or predicted network traffic data; and

filtering communications from a first DDOS compromised node of the one or more DDOS compromised nodes to a first DDOS target node of the one or more DDOS target nodes based at least in part on the set of entity identifiers.

10. The non-transitory computer-readable storage medium of claim 9 , the method further comprising:

providing a gateway signature to the server, wherein the gateway signature is generated based on at least a first portion of the network data, and wherein the set of entity identifiers is generated after the server verifies the gateway signature.

11. The non-transitory computer-readable storage medium of claim 9 , wherein the one or more DDS target nodes comprise one or more nodes that are determined by the server as being targets or potential targets of a DDOS attack, and wherein the filtering of the communications includes rejecting the communications from the first DDOS compromised node to the first DDOS target node.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NO. 16/990,698 PREVIOUSLY RECORDED ON REEL 058294 FRAME 0010. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 21, 2022
From: TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR DATA SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
To: DEUTSCHE BANK AG NEW YORK BRANCH
Reel/Frame 059846/0157 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 058294, FRAME 0161 Recorded Dec 27, 2021
From: JPMORGAN CHASE BANK, N.A.
To: EBUREAU, LLC; IOVATION, INC.; SIGNAL DIGITAL, INC.; TRANS UNION LLC; TRANSUNION INTERACTIVE, INC.; TRANSUNION RENTAL SCREENING SOLUTIONS, INC.; TRANSUNION TELEDATA LLC; AGGREGATE KNOWLEDGE, LLC; TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
Reel/Frame 058593/0852 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Dec 1, 2021
From: TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR DATA SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
To: DEUTSCHE BANK AG NEW YORK BRANCH
Reel/Frame 058294/0010 →
GRANT OF SECURITY INTEREST IN UNITED STATES PATENTS Recorded Dec 1, 2021
From: EBUREAU, LLC; IOVATION, INC.; SIGNAL DIGITAL, INC.; TRANS UNION LLC; TRANSUNION HEALTHCARE, INC.; TRANSUNION INTERACTIVE, INC.; TRANSUNION RENTAL SCREENING SOLUTIONS, INC.; TRANSUNION TELEDATA LLC; AGGREGATE KNOWLEDGE, LLC; TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
To: JPMORGAN CHASE BANK, N.A
Reel/Frame 058294/0161 →
EMPLOYEE AGREEMENT Recorded Jul 22, 2021
From: KNOPF, BRIAN
To: NEUSTAR, INC.
Reel/Frame 056962/0188 →
Cited By (6)
US 12,190,327 US 12,205,076 US 12,333,623 US 12,346,984 US 12,353,482 US 12,657,589