IP Library Granted Patent US 12,212,594
Granted Patent B1
US 12,212,594 · App. 17/455,641 · Granted Jan 28, 2025

Assessing vulnerability to denial-of-service attacks

Inventors: Shawn Wallis (Fremont, CA); David Lorenzi (Phoenix, AZ); Matthew Michael Rogers (Charlotte, NC); Francisco Perez Salguero (Indian Trail, NC)
Assignee: Wells Fargo Bank, N.A.
H04L63/1433H04L63/1458H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,594
App. No.
17/455,641
Granted
Jan 28, 2025
Kind
B1
Abstract

This disclosure describes techniques that include evaluating websites and web services to identify those that are at risk for a denial-of-service attack or a distributed denial-of-service attack. In one example, this disclosure describes a method that includes interacting, by an assessment computing system, with a target computing system, wherein interacting includes issuing a plurality of requests to the target computing system and receiving a plurality of responses to the plurality of requests; identifying, by the assessment computing system and based on the plurality of responses, a plurality of latency values that are attributable to processing performed by the target computing system; and determining, by the assessment computing system and based on the plurality of latency values, whether the target computing system is vulnerable to a denial-of-service attack.

Claims (56)

1. A method comprising:

interacting, by an assessment computing system, with a first target computing system, wherein interacting includes issuing a first plurality of requests to the first target computing system and receiving a first plurality of responses to the first plurality of requests;

identifying, by the assessment computing system and based on the first plurality of responses, a first plurality of latency values that are attributable to processing performed by the first target computing system rather than network congestion;

determining, by the assessment computing system and based on the first plurality of latency values, whether the first target computing system is vulnerable to a denial-of-service attack, wherein determining whether the first target computing system is vulnerable includes generating a first score representing an assessment of how vulnerable the first target computing systems is to a denial-of-service attack;

interacting, by the assessment computing system, with a second target computing system, wherein interacting includes issuing a second plurality of requests to the second target computing system and receiving a second plurality of responses to the second plurality of requests;

identifying, by the assessment computing system and based on the second plurality of responses, a second plurality of latency values that are attributable to processing performed by the second target computing system; and

determining, by the assessment computing system and based on the second plurality of latency values, whether the second target computing system is vulnerable to a denial-of-service attack, wherein determining whether the second target computing system is vulnerable includes generating a second score representing an assessment of how vulnerable the second target computing systems is to a denial-of-service attack.

2. The method of claim 1 , wherein the assessment computing system comprises an analysis computing system and a plurality of probe computing systems, and wherein issuing the first plurality of requests includes:

issuing, by the plurality of probe computing systems and in a coordinated manner, the first plurality of requests.

3. The method of claim 2 , wherein interacting with the first target computing system includes:

interacting, by the probe computing systems, with the first target computing system; and

reporting, by the probe computing systems and to the analysis computing system, information about the interactions.

4. The method of claim 1 , wherein the first target computing system is a production computing system available on a public network, and wherein the method further comprises:

configuring, by the assessment computing system, a validation computing system to simulate operations performed by the first target computing system;

interacting, by the assessment computing system, with the validation computing system; and

validating, by the assessment computing system and based on the interactions with the validation computing system, the determination of whether the first target computing system is vulnerable to a denial-of-service attack.

5. The method of claim 4 , wherein validating the determination includes generating information about the validation computing system, and wherein the method further comprises:

remediating, by the assessment computing system and based on the generated information, the first target computing system.

6. The method of claim 1 , wherein determining whether the first target computing system is vulnerable includes:

generating, based on the first plurality of latency values, a score representing an assessment of how vulnerable the target computing systems is to a denial-of-service attack.

7. The method of claim 6 , wherein the first target computing system is a target website, and wherein generating the score includes generating the score additionally based on at least one of:

a count of elements included within web pages available at the target website, a size associated with elements included within web pages available at the target website, an evaluation of how form input is handled by the target website, an evaluation of whether reflection is present within one or more web pages available at the target website, an assessment of whether database queries are generated by one or more web pages available at the target website, or an assessment of how the target website handles connections made by the assessment computing system.

8. The method of claim 1 , further comprising:

identifying, by the assessment computing system and based on the first score and the second score, the first target computing system for further analysis;

configuring, by the assessment computing system, a validation computing system to simulate operations performed by the first target computing system;

interacting, by the assessment computing system, with the validation computing system; and

validating, by the assessment computing system, the determination of whether the first target computing system is vulnerable to a denial-of-service attack.

9. A computing system comprising processing circuitry and a storage device, wherein the processing circuitry has access to the storage device and is configured to:

interact with a first target computing system, wherein interacting includes issuing a first plurality of requests to the first target computing system and receiving a first plurality of responses to the first plurality of requests;

identify, based on the first plurality of responses, a first plurality of latency values that are attributable to processing performed by the first target computing system rather than network congestion;

determine, based on the first plurality of latency values, whether the first target computing system is vulnerable to a denial-of-service attack, wherein to determine whether the first target computing system is vulnerable, the processing circuitry is further configured to generate, based on the first plurality of latency values, a first score representing an assessment of how vulnerable the first target computing systems is to a denial-of-service attack;

interact with a second target computing system, wherein interacting includes issuing a second plurality of requests to the second target computing system and receiving a second plurality of responses to the second plurality of requests;

identify, based on the second plurality of responses, a second plurality of latency values that are attributable to processing performed by the second target computing system; and

determine, based on the second plurality of latency values, whether the second target computing system is vulnerable to a denial-of-service attack, wherein to determine whether the second target computing system is vulnerable, the processing circuitry is further configured to generate, based on the second plurality of latency values, a second score representing an assessment of how vulnerable the second target computing systems is to a denial-of-service attack.

10. The computing system of claim 9 , wherein the computing system comprises an analysis computing system and a plurality of probe computing systems, and wherein to issue the first plurality of requests, the processing circuitry is further configured to:

enable the plurality of probe computing systems to issue, in a coordinated manner, the first plurality of requests.

11. The computing system of claim 10 , wherein to interact with the first target computing system, the processing circuitry is further configured to:

enable the probe computing systems to interact with the first target computing system;

enable the probe computing systems to communicate the information about the interactions to the analysis computing system.

12. The computing system of claim 9 , wherein the first target computing system is a production computing system available on a public network, and wherein the processing circuitry is further configured to:

configure a validation computing system to simulate operations performed by the first target computing system;

interact with the validation computing system; and

validate, based on the interactions with the validation computing system, the determination of whether the first target computing system is vulnerable to a denial-of-service attack.

13. The computing system of claim 12 , wherein to validate the determination, the processing circuitry generates information about the validation computing system, and wherein the processing circuitry is further configured to:

remediate, based on the generated information, the first target computing system.

14. The computing system of claim 9 , wherein to determine whether the first target computing system is vulnerable, the processing circuitry is further configured to:

generate, based on the first plurality of latency values, a score representing an assessment of how vulnerable the first target computing system is to a denial-of-service attack.

15. The computing system of claim 14 , wherein the first target computing system is a target website, and wherein to generate the score, the processing circuitry is further configured to generate the score further based on at least one of:

a count of elements included within web pages available at the target website, a size associated with elements included within web pages available at the target website, an evaluation of how form input is handled by the target website, an evaluation of whether reflection is present within one or more web pages available at the target website, an assessment of whether database queries are generated by one or more web pages available at the target website, or an assessment of how the target website handles connections made by the assessment computing system.

16. A non-transitory computer-readable medium comprising instructions that, when executed, configure processing circuitry of a computing system to:

interact with a first target computing system, wherein interacting includes issuing a first plurality of requests to the first target computing system and receiving a first plurality of responses to the first plurality of requests;

identify, based on the first plurality of responses, a first plurality of latency values that are attributable to processing performed by the first target computing system rather than network congestion; and

determine, based on the plurality of first latency values, whether the first target computing system is vulnerable to a denial-of-service attack, wherein to determine whether the first target computing system is vulnerable, the processing circuitry is further configured to generate, based on the first plurality of latency values, a first score representing an assessment of how vulnerable the first target computing systems is to a denial-of-service attack;

interact with a second target computing system, wherein interacting includes issuing a second plurality of requests to the second target computing system and receiving a second plurality of responses to the second plurality of requests;

identify, based on the second plurality of responses, a second plurality of latency values that are attributable to processing performed by the second target computing system; and

determine, based on the second plurality of latency values, whether the second target computing system is vulnerable to a denial-of-service attack, wherein to determine whether the second target computing system is vulnerable, the processing circuitry is further configured to generate, based on the second plurality of latency values, a second score representing an assessment of how vulnerable the second target computing systems is to a denial-of-service attack.

Assignments (2)
REQUEST FOR ADDRESS CHANGE Recorded Dec 5, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 073895/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2022
From: WALLIS, SHAWN; LORENZI, DAVID; ROGERS, MATTHEW MICHAEL; PEREZ SALGUERO, FRANCISCO
To: WELLS FARGO BANK, N.A.
Reel/Frame 059297/0787 →
References Cited (23)
US 8516595B2 · Oro Garcia · 2013 [cited by examiner]
US 8997235B2 · De Barros et al. · 2015 [cited by applicant]
US 9118713B2 · Bisht et al. · 2015 [cited by applicant]
US 10298611B1 · Caldwell · 2019 [cited by examiner]
US 10749896B2 · Gadot · 2020 [cited by applicant]
US 10951635B2 · Rayes · 2021 [cited by examiner]
US 11023295B2 · Ding et al. · 2021 [cited by applicant]
US 11716343B2 · Rao · 2023 [cited by examiner]
US 20100100962A1 · Boren · 2010 [cited by examiner]
US 20100125649A1 · Day · 2010 [cited by examiner]
US 20130312101A1 · Lotem · 2013 [cited by examiner]
US 20140380488A1 · Datta Ray · 2014 [cited by examiner]
US 20180109573A1 · Munger · 2018 [cited by examiner]
US 20180255094A1 · Doron · 2018 [cited by examiner]
US 20190158371A1 · Dillon · 2019 [cited by examiner]
US 20200201679A1 · Wentz · 2020 [cited by examiner]
US 20210392155A1 · Waplington · 2021 [cited by examiner]
CN 103647678A · 2014 [cited by applicant]
CN 106330954A · 2017 [cited by applicant]
EP 3343867A1 · 2018 [cited by examiner]
Kalkan et al, (“SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment,” IEEE Explore/IEEE Symposium on Computers and Communications (ISCC), pp. 1-7 (Year: 2017). [cited by examiner]
Anand et al., “IoVT: Internet of Vulnerable Things? Threat Architecture, Attack Surfaces, and Vulnerabilities in Internet of Things and Its Applications towards Smart Grids”, Energies, Sep. 15, 2020, 24 pp. [cited by applicant]
Livshits et al., “Finding Security Vulnerabilities in Java Applications with Static Analysis”, USENIX Security Symposium, vol. 14, Jul. 31-Aug. 5, 2005, pp. 271-286. [cited by applicant]