IP Library › Granted Patent US 12,627,706
Granted Patent B2
US 12,627,706 · App. 18/521,565 · Granted May 12, 2026

Volumetric distributed denial of service attack mitigation

Inventors: Vadim Krishtal (Rishon le Zion, IL); Tomer Pasman (Holon, IL); Eyal Pery (Ramat Gan, IL)
Assignee: F5, Inc.
H04L63/1458H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,706
App. No.
18/521,565
Granted
May 12, 2026
Kind
B2
Abstract

Technologies related to mitigation of volumetric distributed denial of service attacks are disclosed. Malicious network connection request detection can be performed using a first network traffic management module (NTMM) that executes before network connection resources are allocated and a second NTMM that executes after connection resource allocation. The second NTMM can be used to determine whether a connection request is from a potential bad actor. If the request is from a potential bad actor, the second NTMM can add an identifier for the potential bad actor to a list of potential bad actors. When a subsequent connection request is received, the first NTMM can generate the identifier based on the subsequent request and determine whether it is stored in the list of potential bad actors. If it is, the first NTMM can drop the subsequent request before connection resources for establishing the second request are allocated.

Claims (79)

1 . A method implemented by a network traffic management system, the method comprising:

receiving a first request to establish a first network connection using a first network traffic management module, wherein the first network traffic management module executes after an allocation of resources for establishing the first network connection;

determining, using the first network traffic management module, that the first request is from a potential bad actor;

generating, using the first network traffic management module, an identifier using the first request, wherein the identifier comprises a source network address of the first request and an additional identifier based on contents of the first request;

storing, using the first network traffic management module, the identifier in a list of potential bad actor identifiers;

receiving a second request to establish a second network connection using a second network traffic management module, wherein the second network traffic management module executes before an allocation of resources for establishing the second network connection;

generating, using the second network traffic management module, the identifier using the second request;

determining, using the second network traffic management module, that the identifier is in the list of potential bad actor identifiers; and

based on the determining:

dropping the second request, and

preventing the resources for establishing the second network connection from being allocated.

2 . The method of claim 1 , further comprising:

transmitting, using the first network traffic management module, a challenge in a response to the potential bad actor;

receiving, using the first network traffic management module, an answer to the challenge that indicates that the potential bad actor is not a bad actor; and

removing, using the first network traffic management module, the identifier from the list of potential bad actor identifiers.

3 . The method of claim 1 , further comprising:

storing, using the first network traffic management module, a timestamp in association with the identifier; and

wherein dropping the second request and preventing the resources for establishing the second network connection from being allocated are further based on a determining, using the second network traffic management module, that the timestamp associated with the identifier is older than a specified time threshold time.

4 . The method of claim 1 , wherein:

the additional identifier comprises a hash based on transport layer security (TLS) handshake information.

5 . The method of claim 1 , wherein:

the network traffic management module comprises an extended Berkeley Packet Filter (eBPF) express data path (XDP) program.

6 . A system comprising one or more network traffic management modules, a memory comprising programmed instructions stored thereon, and one or more processors configured to be capable of executing the stored programmed instructions to:

receive a first request to establish a first network connection using a first network traffic management module, wherein the first network traffic management module executes after an allocation of resources for establishing the first network connection;

determine, using the first network traffic management module, that the first request is from a potential bad actor;

generate, using the first network traffic management module, an identifier using the first request, wherein the identifier comprises a source network address of the first request and an additional identifier based on contents of the first request;

store, using the first network traffic management module, the identifier in a list of potential bad actor identifiers;

receive a second request to establish a second network connection using second a network traffic management module, wherein the second network traffic management module executes before an allocation of resources for establishing the second network connection;

generate, using the second network traffic management module, the identifier using the second request;

determine, using the second network traffic management module, that the identifier is in the list of potential bad actor identifiers; and

based on the determining:

drop the second request, and

prevent the resources for establishing the second network connection from being allocated.

7 . The system of claim 6 , wherein the one or more processors are further configured to be capable of executing the stored programmed instructions to:

transmit, using the first network traffic management module, a challenge in a response to the potential bad actor;

receive, using the first network traffic management module, an answer to the challenge that indicates that the potential bad actor is not a bad actor; and

remove, using the first network traffic management module, the identifier from the list of potential bad actor identifiers.

8 . The system of claim 6 , wherein the one or more processors are further configured to be capable of executing the stored programmed instructions to:

store, using the first network traffic management module, a timestamp in association with the identifier; and

wherein dropping the second request and preventing the resources for establishing the second connection from being allocated are further based on a determining, using the second network traffic management module, that the timestamp associated with the identifier is older than a specified time threshold time.

9 . The system of claim 6 , wherein:

the additional identifier comprises a hash based on transport layer security (TLS) handshake information.

10 . The system of claim 6 , wherein:

the network traffic management module comprises an extended Berkeley Packet Filter (eBPF) express data path (XDP) program.

11 . A non-transitory computer readable medium having stored thereon instructions comprising executable code that, when executed by one or more processors, causes the processors to:

receive a first request to establish a first network connection using a first network traffic management module, wherein the first network traffic management module executes after an allocation of resources for establishing the first network connection;

determine, using the first network traffic management module, that the first request is from a potential bad actor;

generate, using the first network traffic management module, an identifier using the first request, wherein the identifier comprises a source network address of the first request and an additional identifier based on contents of the first request;

store, using the first network traffic management module, the identifier in a list of potential bad actor identifiers;

receive a second request to establish a second network connection using a second network traffic management module, wherein the second network traffic management module executes before an allocation of resources for establishing the second network connection;

generate, using the second network traffic management module, the identifier using the second request;

determine, using the second network traffic management module, that the identifier is in the list of potential bad actor identifiers; and

based on the determining:

drop the second request, and

prevent the resources for establishing the second network connection from being allocated.

12 . The non-transitory computer readable medium of claim 11 , wherein the instructions further comprise executable code that, when executed by one or more processors, causes the processors to:

transmit, using the first network traffic management module, a challenge in a response to the potential bad actor;

receive, using the first network traffic management module, an answer to the challenge that indicates that the potential bad actor is not a bad actor; and

remove, using the first network traffic management module, the identifier from the list of potential bad actor identifiers.

13 . The non-transitory computer readable medium of claim 11 , wherein the instructions further comprise executable code that, when executed by one or more processors, causes the processors to:

store, using the first network traffic management module, a timestamp in association with the identifier; and

wherein dropping the second request and preventing the resources for establishing the second connection from being allocated are further based on a determining, using the second network traffic management module, that the timestamp associated with the identifier is older than a specified time threshold time.

14 . The non-transitory computer readable medium of claim 11 , wherein:

the additional identifier comprises a hash based on transport layer security (TLS) handshake information.

15 . The non-transitory computer readable medium of claim 11 , wherein:

the network traffic management module comprises an extended Berkeley Packet Filter (eBPF) express data path (XDP) program.

16 . A network traffic management apparatus, comprising memory comprising programmed instructions stored thereon and one or more processors configured to be capable of executing the stored programmed instructions to:

receive a first request to establish a first network connection using a first network traffic management module, wherein the first network traffic management module executes after an allocation of resources for establishing the first network connection;

determine, using the first network traffic management module, that the first request is from a potential bad actor;

generate, using the first network traffic management module, an identifier using the first request, wherein the identifier comprises a source network address of the first request and an additional identifier based on contents of the first request;

store, using the first network traffic management module, the identifier generated using the first request in a list of potential bad actor identifiers;

receive a second request to establish a second network connection using a second network traffic management module, wherein the second network traffic management module executes before an allocation of resources for establishing the second network connection;

generate the identifier, using the second network traffic management module, using the second request;

determine, using the second network traffic management module, that the identifier is in the list of potential bad actor identifiers; and

based on the determining:

drop the second request, and

prevent the resources for establishing the second network connection from being allocated.

17 . The network traffic management apparatus of claim 16 , wherein:

the second network traffic management module comprises an extended Berkeley Packet Filter (eBPF) express data path (XDP) program.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2023
From: KRISHTAL, VADIM; PASMAN, TOMER; PERY, EYAL
To: F5, INC.
Reel/Frame 065940/0870 →
Continuity (1)
Related Publication 20250294052A1 · Sep 18, 2025
References Cited (173)
US 4783828A · Sadjadi · 1988 [cited by applicant]
US 6118893A · Li · 2000 [cited by applicant]
US 6537488B1 · Okumura et al. · 2003 [cited by applicant]
US 6748056B1 · Bapriotti · 2004 [cited by applicant]
US 6769066B1 · Botros · 2004 [cited by applicant]
US 7228412B2 · Freed · 2007 [cited by applicant]
US 7406606B2 · Chawla · 2008 [cited by applicant]
US 7441429B1 · Nucci · 2008 [cited by applicant]
US 7519834B1 · Dondeti · 2009 [cited by applicant]
US 7568224B1 · Jennings · 2009 [cited by applicant]
US 7624447B1 · Horowitz · 2009 [cited by applicant]
US 7743415B2 · Poletto et al. · 2010 [cited by applicant]
US 8572733B1 · Rockwood · 2013 [cited by applicant]
US 8578482B1 · Yang · 2013 [cited by applicant]
US 8756684B2 · Frantz · 2014 [cited by applicant]
US 8886620B1 · Mukerji · 2014 [cited by applicant]
US 8943588B1 · Speegle · 2015 [cited by applicant]
US 9032519B1 · Maher · 2015 [cited by applicant]
US 9077709B1 · Dall · 2015 [cited by applicant]
US 9203837B2 · Pierson · 2015 [cited by applicant]
US 9578055B1 · Khanal · 2017 [cited by applicant]
US 9628499B1 · Yu · 2017 [cited by applicant]
US 9654485B1 · Neumann · 2017 [cited by applicant]
US 9900344B2 · Smith · 2018 [cited by applicant]
US 9942250B2 · Stiansen · 2018 [cited by applicant]
US 9948629B2 · Eisen · 2018 [cited by applicant]
US 9967250B2 · Johansson · 2018 [cited by applicant]
US 10050792B1 · Johnson · 2018 [cited by applicant]
US 10237298B1 · Nguyen · 2019 [cited by applicant]
US 10397250B1 · Shemesh · 2019 [cited by applicant]
US 10693901B1 · Chan · 2020 [cited by applicant]
US 11228609B1 · Finkelshtein · 2022 [cited by applicant]
US 11336575B1 · Milley et al. · 2022 [cited by applicant]
US 11574316B1 · Hoskins · 2023 [cited by examiner]
US 11888870B2 · Garyani · 2024 [cited by examiner]
US 11968226B1 · Chychi · 2024 [cited by applicant]
US 12095747B2 · Stuntebeck · 2024 [cited by examiner]
US 12483617B2 · Shastri · 2025 [cited by examiner]
US 20020116615A1 · Nguyen · 2002 [cited by applicant]
US 20030042439A1 · Rusu · 2003 [cited by applicant]
US 20030073091A1 · Krylov · 2003 [cited by applicant]
US 20030145232A1 · Poletto · 2003 [cited by applicant]
US 20030199762A1 · Fritz · 2003 [cited by applicant]
US 20040037326A1 · D'souza · 2004 [cited by applicant]
US 20040103283A1 · Hornak · 2004 [cited by applicant]
US 20040170123A1 · Carpenter · 2004 [cited by applicant]
US 20050027846A1 · Nolfe · 2005 [cited by applicant]
US 20050111367A1 · Jonathan Chao · 2005 [cited by applicant]
US 20050195840A1 · Krapp · 2005 [cited by applicant]
US 20050198519A1 · Tamura · 2005 [cited by applicant]
US 20060031483A1 · Lund · 2006 [cited by applicant]
US 20060031928A1 · Conley · 2006 [cited by applicant]
US 20070014276A1 · Bettink · 2007 [cited by applicant]
US 20070118894A1 · Bhatia · 2007 [cited by applicant]
US 20070280114A1 · Chao · 2007 [cited by applicant]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080028467A1 · Kommareddy · 2008 [cited by applicant]
US 20080263215A1 · Schnellbaecher · 2008 [cited by applicant]
US 20080320567A1 · Shulman · 2008 [cited by applicant]
US 20090199297A1 · Jarrett · 2009 [cited by applicant]
US 20100031315A1 · Feng · 2010 [cited by applicant]
US 20100070451A1 · Hugues · 2010 [cited by applicant]
US 20100284282A1 · Solie · 2010 [cited by applicant]
US 20100325418A1 · Kanekar · 2010 [cited by applicant]
US 20110012586A1 · Montanar · 2011 [cited by applicant]
US 20110072516A1 · Cohen · 2011 [cited by applicant]
US 20110154026A1 · Edstrom · 2011 [cited by applicant]
US 20110264905A1 · Ovvsiannikov · 2011 [cited by applicant]
US 20120051236A1 · Hegde · 2012 [cited by applicant]
US 20120079592A1 · Pandrangi · 2012 [cited by applicant]
US 20120117239A1 · Holloway · 2012 [cited by applicant]
US 20120144487A1 · Kim · 2012 [cited by applicant]
US 20120167210A1 · Oro Garcia et al. · 2012 [cited by applicant]
US 20120173710A1 · Rodriguez · 2012 [cited by applicant]
US 20120227106A1 · Shulman · 2012 [cited by applicant]
US 20120323700A1 · Aleksandrovich · 2012 [cited by applicant]
US 20130080407A1 · Levow · 2013 [cited by applicant]
US 20130263268A1 · Kim et al. · 2013 [cited by applicant]
US 20130276114A1 · Friedrichs · 2013 [cited by applicant]
US 20130305365A1 · Rubin · 2013 [cited by applicant]
US 20140095865A1 · Yerra · 2014 [cited by applicant]
US 20140289854A1 · Mahvi · 2014 [cited by applicant]
US 20140298419A1 · Boubez · 2014 [cited by applicant]
US 20140310805A1 · Kandekar · 2014 [cited by applicant]
US 20140317739A1 · Be'ery · 2014 [cited by applicant]
US 20150067328A1 · Yin · 2015 [cited by applicant]
US 20150088662A1 · Moller · 2015 [cited by applicant]
US 20150163234A1 · Tal · 2015 [cited by applicant]
US 20150215334A1 · Bingham · 2015 [cited by applicant]
US 20150271179A1 · Nang · 2015 [cited by applicant]
US 20150295945A1 · Canzanese · 2015 [cited by applicant]
US 20150310196A1 · Turgeman · 2015 [cited by applicant]
US 20160021084A1 · Eisen · 2016 [cited by applicant]
US 20160021117A1 · Harmon · 2016 [cited by applicant]
US 20160127406A1 · Smith · 2016 [cited by applicant]
US 20160182542A1 · Staniford · 2016 [cited by applicant]
US 20160337314A1 · Yu · 2016 [cited by applicant]
US 20170171231A1 · Reybok, Jr. · 2017 [cited by applicant]
US 20170249306A1 · Alien · 2017 [cited by applicant]
US 20170318053A1 · Singh · 2017 [cited by applicant]
US 20180124073A1 · Scherman · 2018 [cited by applicant]
US 20180124300A1 · Brook · 2018 [cited by applicant]
US 20180139228A1 · Kanakarajan · 2018 [cited by applicant]
US 20180165457A1 · Holz · 2018 [cited by applicant]
US 20200296125A1 · Alderson · 2020 [cited by applicant]
US 20200351244A1 · Moore · 2020 [cited by examiner]
US 20210075790A1 · Hebert · 2021 [cited by applicant]
US 20220121362A1 · Liu et al. · 2022 [cited by applicant]
US 20230006910A1 · Dewar · 2023 [cited by examiner]
US 20230080679A1 · Koral · 2023 [cited by examiner]
US 20230146962A1 · Reddy et al. · 2023 [cited by applicant]
US 20230362192A1 · Ballew · 2023 [cited by applicant]
US 20230379405A1 · Chhabra · 2023 [cited by applicant]
US 20230394138A1 · Noeth · 2023 [cited by applicant]
US 20230401332A1 · Vahidnia · 2023 [cited by examiner]
US 20230421478A1 · Chhabra · 2023 [cited by applicant]
US 20240073244A1 · Duan · 2024 [cited by applicant]
US 20240073249A1 · Cirello Filho · 2024 [cited by applicant]
US 20240121111A1 · Gomez · 2024 [cited by examiner]
US 20240163094A1 · Karas · 2024 [cited by applicant]
US 20240171484A1 · Munoz · 2024 [cited by applicant]
US 20240214416A1 · Tracy · 2024 [cited by applicant]
US 20240236002A1 · Huson · 2024 [cited by applicant]
US 20240265057A1 · Kol · 2024 [cited by applicant]
US 20240283674A1 · Kanda · 2024 [cited by applicant]
US 20240291744A1 · Chhabra · 2024 [cited by applicant]
US 20240291745A1 · Chhabra · 2024 [cited by applicant]
US 20240356625A1 · Walker · 2024 [cited by examiner]
US 20240356849A1 · Inbal · 2024 [cited by examiner]
US 20250007835A1 · Chhabra · 2025 [cited by applicant]
US 20250007937A1 · Mittal · 2025 [cited by applicant]
US 20250039143A1 · Parla · 2025 [cited by examiner]
US 20250077238A1 · Obando Chacon · 2025 [cited by examiner]
US 20250097100A1 · Raja · 2025 [cited by examiner]
US 20250106254A1 · Clark · 2025 [cited by examiner]
US 20250106634A1 · Sankar Mantha · 2025 [cited by examiner]
US 20250126141A1 · Uthaman · 2025 [cited by examiner]
US 20250148034A1 · Shribman · 2025 [cited by applicant]
US 20250159039A1 · Shribman · 2025 [cited by applicant]
US 20250168470A1 · Pansare · 2025 [cited by examiner]
US 20250175556A1 · Meredith · 2025 [cited by examiner]
US 20250181420A1 · Talavera · 2025 [cited by examiner]
US 20250193681A1 · Pandit · 2025 [cited by examiner]
US 20250203486A1 · Karampatsis · 2025 [cited by examiner]
CN 109391600A · 2019 [cited by applicant]
CN 110365712A · 2019 [cited by applicant]
WO WO0235860A1 · 2002 [cited by applicant]
BIG-1P® Analytics: Implementations, version 11.3, Nov. 15, 2012, F5 Networks, Inc., pp. 1-40. [cited by applicant]
F5 Networks, “BIG-1 P Local Traffic Manager: Concepts”, version 11.4, pp. 1-178, retrieved from https://support.f5.comkb/en-us/products/bigipltm/manuals/producl/ltm-concepts-11-4-0 .html on Feb. 12, 2015. [cited by applicant]
F5 Networks, “BIG-1P Local Traffic Manager: Implementations”, version 11.4, pp. 1-234, retrieved from https://support.5 .com/kb/en-us/products/bigipltm/manuals/producl/ltm-implementations-11-4-0 .html on Feb. 12, 2015. [cited by applicant]
F5 Networks, “BIG-1 P Local Traffic Manager: Monitors Reference”, version 11.4, pp. 1-106, retrieved from hllps://support. f5 .com/kb/en-us/products/big-ip ltm/manuals/producl/ltm-monitorsreference-11-4-0 .html on Feb. … [cited by applicant]
F5 Networks, “Operations Guide 1.0 F5 Local Traffic Manager and Global Traffic Manager”, pp. 1.144, retrieved from hllps://support. f5 .com/kb/en-us/products/bigipltm/manuals/product/f5-1 tm-gtm-operations-guide-1--0 .h… [cited by applicant]
F5 Networks, “Release Note: BIG-IP L TM and TMOS”, version 11.4.1, pp. 1-58, retrieved from hllps://support.f5.com/kb/en-us/products/bigipltm/releasenotes/product/relnote-ltm-11-4-1.html on Feb. 12, 2015. [cited by applicant]
F5 Networks, Inc., “BIG-IP Application Security Manager Operations Guide”, Manual, Feb. 5, 2016, pp. 1-181, F5 Networks, Inc. [cited by applicant]
F5 Networks, Inc., “BIG-IP ASM 11.5.0”, Release Notes, Apr. 12, 2016, Version 11.5.0. [cited by applicant]
F5 Networks, Inc., “BIG-IPASM”, Release Notes, Jun. 13, 2016, pp. 1-18, version 11.6.1 F5 Networks, Inc. [cited by applicant]
F5 Networks, Inc., “BIG-IP@Analytics: Implementations”, Manual, Jan. 31, 2014, pp. 1-50, Version 11.5. [cited by applicant]
F5 Networks, Inc., “BIG-IP®Analytics: Implementations”, Manual, Aug. 25, 2014, pp. 1-62, v11.6, F5 Networks, Inc. [cited by applicant]
F5 Networks, Inc., “BIG-IP@ Application Security Manager TM: Getting Started”, Manual, Aug. 25, 2014, pp. 1-78, version 11.6, F5 Networks, Inc. [cited by applicant]
F5 Networks, Inc., “BIG-IP® Application Security Manager TM: Implementations”, Manual, Aug. 25, 2014, pp. 1-420, version 11.6, F5 Networks, Inc. [cited by applicant]
F5 Networks, Inc., “BIG-IP@Application Security ManagerTM: Implementations”, Manual, Jan. 31, 2014, pp. 1-396, Version 11.5. [cited by applicant]
F5 Networks, Inc., “BIG-IP® Application Security ManagerTM:Implementations”, F5 Networks, Inc., Dec. 10, J014, version 11.6, pp. 1-420, Dec. 10, 2024. [cited by applicant]
F5 Networks, Inc., “BIG-IP® Local Traffic Management: Basics”, Manual, Aug. 25, 2014, pp. 1-74, version 11.6, F5 Networks, Inc. [cited by applicant]
F5 Networks, Inc., “BIG-IP® Network Firewall: Policies and Implementations”, Manual, Aug. 10, 2016, pp. 1-166, ,11.6, F5 Networks, Inc. [cited by applicant]
F5 Networks, Inc., “BIG-IP® Systems: DoS Protection and Protocol Firewall Implementations”, Manual, Aug. 25, 2014, pp. 1-108, v11.6, F5 Networks, Inc. [cited by applicant]
F5 Networks, Inc., “BIG-IP® TMOS®: Concepts”, Manual, Nov. 11, 2014, pp. 1-148, Version 11.5. [cited by applicant]
F5 Networks, Inc., “BIG-IP® TMOS®: Implementations”, Manual, Jan. 31, 2014, pp. 1-274, Version 11.5. [cited by applicant]
F5 Networks, Inc., “F5 BIG-IP TMOS: Operations Guide”, Manual, Mar. 5, 2015, pp. 1-276 version 11.6, F5 Networks, Inc. [cited by applicant]
F5 Networks, Inc., “BIG-IP Application Security Manager: Implementations”, F5 Networks, Inc., Dec. 10, 2014, version 11.6, pp. 1-420. [cited by applicant]
F5 Networks, Inc., “BIG-IP® Application Security Manager™: Implementations”, Manual, Nov. 10, 2017, pp. 1-348, version 13.0, F5 Networks, Inc. [cited by applicant]
International Search Report dated Mar. 25, 2024 issued in International Application No. PCT/US2023/083393. [cited by applicant]
European Search Report Date Dec. 18, 2024. European Patent Application No. 24193938.8. [cited by applicant]
European Search Report Dated Feb. 17, 2025. European Patent AppIn No. 24216113.1. [cited by applicant]