IP Library › Granted Patent US 12,513,186
Granted Patent B2
US 12,513,186 · App. 18/626,273 · Granted Dec 30, 2025

Systems and methods for mitigating DDoS attacks on internet protocol networks

Inventor: Tracey Bernath (Castle Rock, CO)
Assignee: Inception Security Solutions LLC
H04L63/1458H04L63/0236H04L63/0281H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,186
App. No.
18/626,273
Granted
Dec 30, 2025
Kind
B2
Abstract

A system and method to protect resource servers from DDOS attacks is disclosed. A proxy gateway hides resource server using IP subnet addressing and receives authenticated IP packets. A cryptographic hash is generated, and destination IP packets address/ports are encrypted using a secret, algorithm, client IP address, resource server IP address, and port. The cryptographic hash and destination server are mapped into existing IP packet addresses, ports, or payload bits. The IP packets are routed to a redirect node in the public IP subnet of the proxy gateway. At the redirected node, the cryptographic hash is validated, and the resource server IP address and the port are extracted from mapping. Redirect node maps the clients public IP/port to an internal IP address and port associated with resource server and tunnels the IP packets from the redirect node to the resource server using the internal IP address and port.

Claims (39)

1 . A system to protect resource servers, the system comprising:

a proxy gateway between a client device and a resource server, the proxy gateway comprising a memory, a processor, and a plurality of programming instructions, the plurality of programming instructions stored in the memory and when executed by the processor, cause the processor to:

receive IP packets from a CDN server, wherein the IP packets are associated with the client device authenticated by the CDN server, and the IP packets are redirected towards the proxy gateway, wherein the proxy gateway provides access to the resource server using IP subnet addressing;

generate a cryptographic hash by encrypting the IP packets using a secret, client IP address, resource server IP address, and port, wherein the cryptographic hash is mapped into existing IP packet address, port, or payload bits;

determine if the mapping is stateless; and

responsive to determining that the mapping is stateless, route the IP packets to redirect node among a plurality of redirect nodes in the IP subnet of the proxy gateway,

wherein the redirect node is configured to map clients public IP/port to an internal IP address and port associated with the resource server, and tunnel the IP packets from the redirect node to the resource server using the internal IP address and port.

2 . The system of claim 1 , wherein the programming instruction executed when executed by the processor causes the processor to:

decrypt, at the redirect node the IP packets to validate the client device based on the cryptographic hash; and

responsive to validation of client device, determine the resource server IP address and the port.

3 . The system of claim 2 , wherein the programming instructions when executed by the processor cause the processor to:

responsive to detection of an attack at the proxy gateway, terminate the tunneling of IP traffic between the redirected server and the resource server; and

reauthenticating the client device and creating new mapping using a new secret for the client device.

4 . The system of claim 1 , wherein the proxy gateway creates, modifies, and deletes mapping using a secured API and distributes the mapping to the plurality of redirected nodes.

5 . The system of claim 1 , wherein the mapping supported by the redirect nodes comprises stateful and/or stateless.

6 . The system of claim 1 , wherein the secret and algorithm used in the mappings are rotated or changed to invalidate attackers.

7 . The system of claim 1 , wherein the programming instruction executed when executed by the processor causes the processor to:

determine if the mapping is stateful;

responsive to determining that the mapping is stateful, tunnel the IP packets to a stateful server; and

route the IP packets to the resource server IP and port from the stateful server.

8 . A method for protecting resource servers, the method comprising:

receiving, at a proxy gateway between a client device and a resource server, IP packets from a CDN server, wherein the IP packets are associated with the client device authenticated by the CDN server and the IP packets are redirected towards the proxy gateway, wherein the proxy gateway provides access to the resource server using public IP subnet addressing;

generating a cryptographic hash by encrypting the IP packets using a secret, client IP address, resource server IP address, and port, wherein the cryptographic hash is mapped into available bits in existing IP packet address, port, or payload bits;

determining if the mapping is stateless; and

responsive to determining that the mapping is stateless, routing the IP packets to redirect node among a plurality of redirect nodes in the public IP subnet of the proxy gateway,

wherein the redirect node is configured to map clients public IP/port to an internal IP address and port associated with the resource server, and tunnel the IP packets from the redirect node to the resource server using the internal IP address and port.

9 . The method of claim 8 , wherein the method further comprises:

decrypting, at the redirect node, the IP packets to validate the client device based on decrypted cryptographic hash; and

responsive to validation of the client device, determining the resource server IP address and the port.

10 . The method of claim 9 , wherein the method further comprises:

responsive to detection of an attack at the proxy gateway, terminating the tunneling of IP traffic between the redirected server and the resource server; and

reauthenticating the client device and creating new mapping using a new secret for the client device.

11 . The method of claim 8 , wherein the proxy gateway creates, modifies, and deletes mapping using a secured API and distributes the mapping to the plurality of redirected nodes.

12 . The method of claim 8 , wherein the mapping supported by the redirect nodes comprises stateful and/or stateless.

13 . The method of claim 8 , wherein the secret and algorithm used in the mappings are rotated or changed to invalidate attackers.

14 . The method of claim 8 , wherein the method further comprises:

determining if the mapping is stateful;

responsive to determining that the mapping is stateful, tunneling the IP packets to a stateful server; and

routing the IP packets to the resource server IP and port from the stateful server.

Continuity (2)
Provisional Application 63456533 · Apr 3, 2023
Related Publication 20240333758A1 · Oct 3, 2024
References Cited (7)
US 10819682B1 · Deepak · 2020 [cited by examiner]
US 20040019781A1 · Chari · 2004 [cited by examiner]
US 20060004782A1 · Eldar · 2006 [cited by examiner]
US 20130046883A1 · Lientz · 2013 [cited by examiner]
US 20130247197A1 · O'Brien · 2013 [cited by examiner]
US 20150358285A1 · Ellard · 2015 [cited by examiner]
US 20210377294A1 · Gupta · 2021 [cited by examiner]
Cited By (1)
US 12,621,342