IP Library Granted Patent US 10,505,974
Granted Patent B2
US 10,505,974 · App. 15/653,157 · Granted Dec 10, 2019

Network attack defense system and method

Inventors: Xiao Han (Beijing, CN); Shuning Ge (Beijing, CN)
Assignee: Alibaba Group Holding Limited
H04L63/145H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,505,974
App. No.
15/653,157
Granted
Dec 10, 2019
Kind
B2
Abstract

Network attack defense includes: obtaining a set of one or more statistical attributes for a protected site by gathering statistics for a set of one or more site attributes of the protected site, the site attributes indicating an operation mode of the protected site; determining, based on the set of one or more statistical attributes, that the protected site is to transition from a current operation mode to a target operation mode, wherein the current operation mode has a current defense strategy different from a target defense strategy of the target operation mode; and if the protected site is to transition from the current operation mode to the target operation mode, transitioning from the current operation mode to the target operation mode and applying the target defense strategy for the protected site instead of the current operation mode.

Claims (62)

1. A network attack defense method comprising:

obtaining a set of one or more statistical attributes for a protected site by gathering statistics for a set of one or more site attributes of the protected site, the set of one or more site attributes of the protected site indicating an operation mode of the protected site;

determining, based at least in part on the set of one or more statistical attributes, that the protected site is to transition from a current operation mode to a target operation mode, wherein the current operation mode has a current defense strategy and the target operation mode has a target defense strategy, and wherein the current defense strategy differs from the target defense strategy, and the determining that the protected site is to transition from the current operation mode to the target operation mode comprises:

obtaining rolling averages for the set of one or more statistical attributes; and

using the one or more statistical attributes, and the rolling averages for the one or more statistical attributes to determine whether the protected site is to transition from the current operation mode to the target operation mode; and

in response to the determination that the protected site is to transition from the current operation mode to the target operation mode, transitioning from the current operation mode to the target operation mode and applying the target defense strategy for the protected site.

2. The method of claim 1 , wherein the obtaining of the set of one or more statistical attributes for the protected site comprises:

obtaining a plurality of HTTP packets received by the protected site within a specified time interval; and

extracting site attributes from the HTTP packets to gather statistics for site attributes of a same type of HTTP headers to obtain the set of the one or more statistical attributes.

3. The method of claim 2 , wherein the obtaining of the plurality of HTTP packets comprises:

obtaining a set of HTTP packets from a plurality of data sources; and

categorizing the set of HTTP packets based on their respective destination sites to determine the plurality of HTTP packets for the protected site.

4. The method of claim 1 , wherein the determining of the protected site is to transition from the current operation mode to the target operation mode further comprises:

obtaining a time duration during which the protected site has been in the current operation mode; and

determining whether the protected site is to transition from the current operation mode to the target operation mode based at least in part on: the one or more statistical attributes, the rolling averages for the one or more statistical attributes, and the time duration.

5. The method of claim 1 , wherein the determining of the protected site is to transition from the current operation mode to the target operation mode comprises:

inputting the rolling averages, the one or more statistical attributes, and a time duration during which the protected site has been in the current operation mode into a Boolean function corresponding to the protected site to generate an output value; and

determining, by using the output value, that the protected site is to transition from the current operation mode to the target operation mode.

6. The method of claim 1 , wherein the current defense strategy comprises a plurality of defense algorithms, wherein a defense algorithm in the plurality of defense algorithms has a corresponding plurality of defense levels, and wherein the corresponding plurality of defense levels indicates extents to which the protected site is protected.

7. The method of claim 6 , wherein the set of one or more statistical attributes for the protected site indicates an operation mode of the protected site within a first pre-determined time interval; and wherein the method further comprises:

gathering statistics to obtain a false positive rate for the protected site during a second pre-determined time interval, wherein the protected site is deployed with the current defense strategy; and

adjusting the current defense strategy when the false positive rate exceeds a corresponding threshold value.

8. The method of claim 7 , wherein the adjusting of the current defense strategy includes adjusting a corresponding defense algorithm, adjusting a corresponding defense level, or both.

9. The method of claim 1 , wherein the set of one or more statistical attributes for the protected site indicates an operation mode of the protected site within a specified time interval.

10. A system, comprising:

one or more hardware processors configured to:

obtain a set of one or more statistical attributes for a protected site by gathering statistics for a set of one or more site attributes of the protected site, the set of one or more site attributes indicating an operation mode of the protected site;

determine, based on the set of one or more statistical attributes, that the protected site is to transition from a current operation mode to a target operation mode, wherein the current operation mode has a current defense strategy and the target operation mode has a target defense strategy, and wherein the current defense strategy differs from the target defense strategy, and to determine that the protected site is to transition from the current operation mode to the target operation mode comprises:

obtain rolling averages for the set of one or more statistical attributes; and

use the one or more statistical attributes, and the rolling averages for the one or more statistical attributes to determine whether the protected site is to transition from the current operation mode to the target operation mode; and

in response to the determination that the protected site is to transition from the current operation mode to the target operation mode, transition from the current operation mode to the target operation mode and apply the target defense strategy for the protected site instead of the current operation mode; and

one or more memories coupled to the one or more processors and configured to provide the one or more processors with instructions.

11. The system of claim 10 , wherein to obtain the set of one or more statistical attributes for the protected site comprises to:

obtain a plurality of HTTP packets received by the protected site within a specified time interval; and

extract site attributes from the plurality of HTTP packets to gather statistics for site attributes of a same type of HTTP headers to obtain the set of the one or more statistical attributes.

12. The system of claim 11 , wherein to obtain the plurality of HTTP packets comprises to:

obtain a set of HTTP packets from a plurality of data sources; and

categorize the set of HTTP packets based on destination sites to determine the plurality of HTTP packets for the protected site.

13. The system of claim 10 , wherein to determine that the protected site is to transition from the current operation mode to the target operation mode comprises to:

obtain a time duration during which the protected site has been in the current operation mode; and

determine whether the protected site is to transition from the current operation mode to the target operation mode based at least in part on: the one or more statistical attributes, the rolling averages for the one or more statistical attributes, and the time duration.

14. The system of claim 10 , wherein to determine that the protected site is to transition from the current operation mode to the target operation mode comprises to:

input the rolling averages, the one or more statistical attributes, and a time duration during which the protected site has been in the current operation mode into a Boolean function corresponding to the protected site to generate an output value; and

determine, by using the output value, that the protected site is to transition from the current operation mode to the target operation mode.

15. The system of claim 10 , wherein the current defense strategy comprises a plurality of defense algorithms, wherein a defense algorithm in the plurality of defense algorithms has a corresponding plurality of defense levels, and wherein the corresponding plurality of defense levels indicates extents to which the protected site is protected.

16. The system of claim 15 , wherein the set of one or more statistical attributes for the protected site indicates an operation mode of the protected site within a first pre-determined time interval; and wherein the one or more processors are further configured to:

gather statistics to obtain a false positive rate for the protected site during a second pre-determined time interval, wherein the protected site is deployed with the current defense strategy; and

adjust the current defense strategy when the false positive rate exceeds a corresponding threshold value.

17. The system of claim 16 , wherein to adjust the current defense strategy includes to adjust a corresponding defense algorithm, adjust a corresponding defense level, or both.

18. The System of claim 11 , wherein the set of one or more statistical attributes for the protected site indicates an operation mode of the protected site within a specified time interval.

19. A computer program product for network attack defense, the computer program product being embodied in a non-transitory tangible computer readable storage medium and comprising computer instructions for:

obtaining a set of one or more statistical attributes for a protected site by gathering statistics for a set of one or more site attributes of the protected site, the set of one or more site attributes indicating an operation mode of the protected site;

determining, based on the set of one or more statistical attributes, that the protected site is to transition from a current operation mode to a target operation mode, wherein the current operation mode has a current defense strategy and the target operation mode has a target defense strategy, and wherein the current defense strategy differs from the target defense strategy, and the determining that the protected site is to transition from the current operation mode to the target operation mode comprises:

obtaining rolling averages for the set of one or more statistical attributes; and

using the one or more statistical attributes, and the rolling averages for the one or more statistical attributes to determine whether the protected site is to transition from the current operation mode to the target operation mode; and

in response to the determination that the protected site is to transition from the current operation mode to the target operation mode, transitioning from the current operation mode to the target operation mode and applying the target defense strategy for the protected site instead of the current operation mode.

20. A method, comprising:

obtaining a set of one or more statistical attributes for a protected site by gathering statistics for a set of one or more site attributes of the protected site, the set of one or more site attributes of the protected site indicating an operation mode of the protected site within a first pre-determined time interval;

determining, based at least in part on the set of one or more statistical attributes, that the protected site is to transition from a current operation mode to a target operation mode, wherein the current operation mode has a current defense strategy and the target operation mode has a target defense strategy, and wherein the current defense strategy differs from the target defense strategy;

in response to the determination that the protected site is to transition from the current operation mode to the target operation mode, transitioning from the current operation mode to the target operation mode and applying the target defense strategy for the protected site;

gathering statistics to obtain a false positive rate for the protected site during a second pre-determined time interval, wherein the protected site is deployed with the current defense strategy; and

adjusting the current defense strategy when the false positive rate exceeds a corresponding threshold value.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2026
From: ALIBABA GROUP HOLDING LIMITED
To: CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PRIVATE LIMITED
Reel/Frame 075478/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2017
From: HAN, XIAO; GE, SHUNING
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 043705/0610 →
Priority Claims (1)
CN 2016 1 0586673 · Jul 22, 2016 · national
Continuity (1)
Related Publication 20180026994A1 · Jan 25, 2018