IP Library › Granted Patent US 12,316,672
Granted Patent B2
US 12,316,672 · App. 18/383,351 · Granted May 27, 2025

Bot detection in an edge network using transport layer security (TLS) fingerprint

Inventors: David Senecal (Santa Clara, CA); Andrew Kahn (San Francisco, CA); Ory Segal (Herzliya, IL); Elad Shuster (Herzliya, IL); Duc Nguyen (Santa Clara, CA)
Assignee: Akamai Technologies, Inc.
H04L63/1483G06N20/00H04L63/166H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,672
App. No.
18/383,351
Filed
Oct 24, 2023
Granted
May 27, 2025
Kind
B2
Art Unit
2408
USPC
726/23
Abstract

This disclosure describes a technique to fingerprint TLS connection information to facilitate bot detection. The notion is referred to herein as “TLS fingerprinting.” Preferably, TLS fingerprinting herein comprises combining different parameters from the initial “Hello” packet send by the client. In one embodiment, the different parameters from the Hello packet that are to create the fingerprint (the “TLS signature”) are: record layer version, client version, ordered TLS extensions, ordered cipher list, ordered elliptic curve list, and ordered signature algorithms list. Preferably, the edge server persists the TLS signature for the duration of a session.

Claims (19)

1. A computer program product in a non-transitory computer readable medium, the computer program product comprising program code executable in and across a set of hardware processors, the program code comprising:

first program code executable in a first hardware processor and configured to execute a script and, responsive to execution of the script, to output a set of transport layer security parameters;

second program code executable in a second hardware processor and configured to receive and extract the set of transport layer security parameters, to process the extracted set of transport layer security parameters into a hash value, and to selectively output the hash value; and

third program code executable in a third hardware processor and configured to receive the hash value, based on a machine learning model, carry out a determination whether an entity that generated the set of transport layer security parameters as reflected by the hash value has a characteristic associated with a bot, and to provide the second program code an indication based on the determination;

wherein the second program code is further configured to receive and to take a given action based on the indication.

2. The computer program product as described in claim 1 wherein the set of transport layer security parameters are associated with a Transport Layer Security (TLS) connection initiated by a client entity associated with the first hardware processor.

3. The computer program product as described in claim 2 wherein the TLS connection is initiated by the client entity by a client hello message.

4. The computer program product as described in claim 3 wherein the set of transport layer security parameters comprise information derived from the client hello message, the information being at least one of: a record layer version, a client version, a set of ordered TLS extensions, an ordered cipher list, an ordered elliptic curve list, and an ordered signature algorithms list.

5. The computer program product as described in claim 1 wherein the third program code is further configured to persist the hash value for a duration of a session associated with a client request.

6. The computer program product as described in claim 1 wherein the given action is one of: denying a client request, tarpit the client request, serving alternative content in response to the client request, passing the client request forward to an origin, and serving a response to the client request.

7. The computer program product as described in claim 1 wherein the second program code is further configured to check the hash value against a data set of known bad hash values.

8. The computer program product as described in claim 7 wherein the third program code is further configured to generate the data set of known bad hash values, and to provide the data set of known bad hash values to a server entity associated with the second hardware processor.

9. The computer program product as described in claim 1 wherein the third program code is further configured to generate the machine learning model using supervised learning.

10. The computer program product as described in claim 1 wherein the first hardware processor is associated with a client entity, the second hardware processor is associated with a server entity, and the third hardware processor is associated with a bot detection service entity.

11. The computer program product as described in claim 10 wherein the server entity is one of a set of server entities of a content delivery network (CDN).

12. The computer program product as described in claim 10 wherein the second progam code of the server entity is further configured to deliver the script to the client entity.

13. The computer program product as described in claim 1 wherein the first hardware processor is located remote from the second hardware processor.

14. The computer program product as described in claim 1 wherein the second hardware processor is located remote from the third hardware processor.

15. The computer program product as described in claim 1 wherein the set of transport layer security parameters comprise a fingerprint.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2023
From: SENECAL, DAVID; KAHN, ANDREW; SEGAL, ORY; SHUSTER, ELAD; NGUYEN, DUC
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 065366/0976 →
Continuity (4)
Continuation 17533185 · Nov 23, 2021
Continuation 15973585 · May 8, 2018
Provisional Application 62599845 · Dec 18, 2017
Related Publication 20240056479A1 · Feb 15, 2024
References Cited (5)
US 9906544B1 · Kurupati · 2018 [cited by examiner]
US 20140033317A1 · Barber · 2014 [cited by examiner]
US 20160005029A1 · Ivey · 2016 [cited by examiner]
US 20170288987A1 · Pasupathy · 2017 [cited by examiner]
Zhu et al., “Connection-Oriented DNS to Improve Privacy and Security”, 2015 IEEE Symposium on Security and Privacy, Date of Conference: May 17-21 (Year: 2015). [cited by examiner]
Cited By (3)
US 12,470,598 US 12,621,344 US 12,652,331