IP Library Granted Patent US 11,539,740
Granted Patent B1
US 11,539,740 · App. 16/266,742 · Granted Dec 27, 2022

Methods for protecting CPU during DDoS attack and devices thereof

Inventors: Peter Finkelshtein (Tel Aviv, IL); Vadim Krishtal (Tel Aviv, IL)
Assignee: F5, INC.
H04L63/1458H04L41/065H04L41/28H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,539,740
App. No.
16/266,742
Granted
Dec 27, 2022
Kind
B1
Abstract

Methods, non-transitory computer readable media, and network traffic manager apparatus that assists with protecting a CPU during a DDOS attack includes monitoring network traffic data from plurality of client devices. Each of the plurality of client devices are classified as a valid device or a potential attacker device based on the monitoring. Next a determination of when CPU utilization of a network traffic manager apparatus is greater than a stored threshold value is made. The CPU utilization of the network traffic manager increases as a number of the plurality of client devices classified as the potential attacker device increases. One or more network actions are performed on the plurality of client devices classified as the potential attacker device to protect the CPU when the determination indicates the CPU utilization is greater than the stored threshold value.

Claims (40)

1. A method for protecting CPU during a DDOS attack, the method comprising:

monitoring network traffic data from a plurality of client devices;

classifying each of the plurality of client devices as a valid client device or a potential attacker device based on the monitoring;

in response to the classification of portion of the plurality of client devices as the potential attacker, determining when CPU utilization associated with the monitored network traffic from the portion of the plurality of client devices classified as the potential attacker of a network traffic manager apparatus is greater than a stored threshold value; and

performing one or more network actions on the portion of plurality of client devices classified as the potential attacker to protect the CPU when the determination indicates the CPU utilization is greater than the stored threshold value.

2. The method as set forth in claim 1 further comprising, adding the portion of the plurality of client devices classified as the potential attacker to a group including other potential attackers.

3. The method as set forth in claim 1 further comprising, deleting state information associated with the portion of the plurality of client devices classified as the potential attacker.

4. The method as set forth in claim 1 wherein the one or more network actions comprises:

rejecting one or more requests sent by the portion of the plurality of client devices classified as the potential attacker, or

accepting only a plurality of HTTP requests via a TCP connection and dropping the packets via the TCP connection.

5. A non-transitory computer readable medium having stored thereon instructions for protecting a CPU during a DDOS attack comprising executable code which when executed by one or more processors, causes the processors to:

monitor network traffic data from a plurality of client devices;

classify each of the plurality of client devices as a valid client device or a potential attacker device based on the monitoring;

in response to the classification of portion of the plurality of client devices as the potential attacker, determine when CPU utilization associated with the monitored network traffic from the portion of the plurality of client devices classified as the potential attacker of a network traffic manager apparatus is greater than a stored threshold value; and

perform one or more network actions on the portion of plurality of client devices classified as the potential attacker to protect the CPU when the determination indicates the CPU utilization is greater than the stored threshold value.

6. The medium as set forth in claim 5 further comprises, add the portion of the plurality of client devices classified as the potential attacker to a group including other potential attackers.

7. The medium as set forth in claim 5 further comprises, delete state information associated with the portion of the plurality of client devices classified as the potential attacker.

8. The medium as set forth in claim 5 wherein the network action comprises:

reject one or more requests sent by the portion of the plurality of client devices classified as the potential attacker, or

accept only a plurality of HTTP requests via a TCP connection and dropping the packets via the TCP connection.

9. A network traffic manager apparatus, comprising memory comprising programmed instructions stored in the memory and one or more processors configured to be capable of executing the programmed instructions stored in the memory to:

monitor network traffic data from a plurality of client devices;

classify each of the plurality of client devices as a valid client device or a potential attacker device based on the monitoring;

in response to the classification of portion of the plurality of client devices as the potential attacker, determine when CPU utilization associated with the monitored network traffic from the portion of the plurality of client devices classified as the potential attacker of a network traffic manager apparatus is greater than a stored threshold value; and

perform one or more network actions on the portion of plurality of client devices classified as the potential attacker to protect the CPU when the determination indicates the CPU utilization is greater than the stored threshold value.

10. The apparatus as set forth in claim 9 wherein the one or more processors are further configured to be capable of executing the programmed instructions stored in the memory to add the portion of the plurality of client devices classified as the potential attacker to a group including other potential attackers.

11. The apparatus as set forth in claim 9 wherein the one or more processors are further configured to be capable of executing the programmed instructions stored in the memory to delete state information associated with the portion of the plurality of client devices classified as the potential attacker.

12. The apparatus as set forth in claim 9 wherein the network action comprises:

reject one or more requests sent by the portion of the plurality of client devices classified as the potential attacker, or

accept only a plurality of HTTP requests via a TCP connection and dropping the packets via the TCP connection.

13. A network traffic management system, comprising memory comprising programmed instructions stored thereon and one or more processors configured to be capable of executing the stored programmed instructions to:

monitor network traffic data from a plurality of client devices;

classify each of the plurality of client devices as a valid client device or a potential attacker device based on the monitoring;

in response to the classification of portion of the plurality of client devices as the potential attacker, determine when CPU utilization associated with the monitored network traffic from the portion of the plurality of client devices classified as the potential attacker of a network traffic manager apparatus is greater than a stored threshold value; and

perform one or more network actions on the portion of plurality of client devices classified as the potential attacker to protect the CPU when the determination indicates the CPU utilization is greater than the stored threshold value.

14. The network traffic management system of claim 13 wherein the one or more processors are further configured to be capable of executing the programmed instructions stored in the memory to add the portion of the plurality of client devices classified as the potential attacker to a group including other potential attackers.

15. The network traffic management system of claim 13 wherein the one or more processors are further configured to be capable of executing the programmed instructions stored in the memory to delete state information associated with the portion of the plurality of client devices classified as the potential attacker.

16. The network traffic management system of claim 13 wherein the network action comprises:

reject one or more requests sent by the portion of the plurality of client devices classified as the potential attacker, or

accept only a plurality of HTTP requests via a TCP connection and dropping the packets via the TCP connection.

Assignments (3)
CHANGE OF NAME Recorded Nov 21, 2022
From: F5 NETWORKS, INC.
To: F5, INC.
Reel/Frame 061974/0765 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2020
From: FINKELSHTEIN, PETER
To: F5 NETWORKS (ISRAEL) LTD.
Reel/Frame 054467/0414 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2020
From: KRISHTAL, VADIM
To: F5 NETWORKS, INC.
Reel/Frame 053541/0687 →
Continuity (1)
Provisional Application 62625778 · Feb 2, 2018