IP Library Granted Patent US 8,321,955
Granted Patent B2
US 8,321,955 · App. 12/148,786 · Granted Nov 27, 2012

Systems and methods for protecting against denial of service attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,321,955
App. No.
12/148,786
Granted
Nov 27, 2012
Kind
B2
Abstract

Systems and methods utilizing the network layer and/or application layer to provide security in distributed computing systems in order to thwart denial of service attacks. The systems and methods of the present invention utilize puzzles placed at the network layer level and/or application layer level to protect against denial of service attacks. Further, the systems and methods of the present invention advantageously provide a robust and flexible solution to support puzzle issuance at arbitrary points in the network, including end hosts, firewalls, and routers and thereby a defense against denial of service attacks.

Claims (23)

1. A method of prioritizing a service request in a network system, comprising:

sending a first request from the client to the server to access a server resource;

creating by the server a proof-of-work challenge, wherein the server issues the proof-of-work challenge at an arbitrary location in the network system, the arbitrary location including the server, an end host, a firewall, and a router;

embedding the proof-of-work challenge within a uniform resource locator at an application layer in the network system, the proof-of-work challenge including an instruction to obtain a solution using Hyper-Text Markup Language to reference a scripting language file;

transmitting the embedded proof-of-work challenge from the arbitrary location to the client;

solving by the client the proof-of-work challenge to obtain a solution to the proof-of-work challenge;

forwarding a second request from the client to the server, wherein the second request includes the proof-of-work challenge and the solution;

establishing by the server a solution value based on the accuracy of the proof-of-work challenge and the solution;

comparing the solution value to a threshold value;

assigning a priority value to the second request based on said comparing step; and

processing by the server the second request.

2. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said processing step further comprises the step of allowing the request to proceed.

3. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said processing step further comprises the step of denying the request.

4. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said forwarding step further comprises the step of utilizing a network layer of the network system.

5. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said forwarding step further comprises the step of accepting by the server the second request from the client.

6. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said transmitting step further comprises the step of utilizing a network layer of the network system.

7. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said sending step further comprises the step of receiving by the server the first request from the client.

8. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said supplying step further comprises the step of embedding the instruction within the uniform resource locator.

9. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said supplying step further comprises the step of aborting the connection between the client and the server.

10. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said solving step further comprises the step of using the scripting language file.

11. A method of prioritizing a service request in a network system at the application layer according to claim 10 wherein the scripting language file is a JavaScript file.

12. A method of prioritizing a service request in a network system at the application layer according to claim 1 wherein said creating step further comprises the step of determining the current load and the historical load of the client.

13. A method of prioritizing a service request in a network system at the application layer according to claim 12 wherein said determining step further comprises the step of evaluating the current load and the historical load of the client to a threshold value.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2012
From: FENG, WU-CHANG
To: THE OREGON STATE BOARD OF HIGHER EDUCATION ON BEHALF OF PORTLAND STATE UNIVERSITY
Reel/Frame 029323/0160 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2012
From: KAISER, ED
To: THE OREGON STATE BOARD OF HIGHER EDUCATION ON BEHALF OF PORTLAND STATE UNIVERSITY
Reel/Frame 029323/0456 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2012
From: FENG, WU-CHANG
To: OREGON HEALTH & SCIENCE UNIVERSITY
Reel/Frame 029149/0736 →
CONFIRMATORY LICENSE Recorded Jul 29, 2009
From: OREGON HEALTH AND SCIENCE UNIVERSITY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 023019/0285 →
Continuity (3)
Continuation In Part 10926487 · Aug 26, 2004
Provisional Application 60498204 · Aug 26, 2003
Related Publication 20100031315A1 · Feb 4, 2010