IP Library › Granted Patent US 10,193,911
Granted Patent B2
US 10,193,911 · App. 15/913,879 · Granted Jan 29, 2019

Techniques for automatically mitigating denial of service attacks via attack pattern matching

Inventors: Yujie Zhao (Reston, VA); Suresh Bhogavilli (Gaithersburg, MD); Anupam Kulkarni (Aldie, VA); Sivasankar Subramanian (Herndon, VA)
Assignee: VERISIGN, INC.
H04L63/1416H04L63/1458H04L63/101H04L63/168H04L2463/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,193,911
App. No.
15/913,879
Granted
Jan 29, 2019
Kind
B2
Abstract

A method for mitigating a denial of service attack includes determining, for a client, a number of requests being transmitted to a server and determining, for the client, that the number of requests for a time period is greater than a top talker threshold. The method includes classifying the client as a top talker based on the number of requests being greater than the top talker threshold and identifying, for the client, additional requests being transmitted to the server. The method also includes determining whether a number of the additional requests matches one or more attack patterns and preventing one or more of the additional requests from being transmitted to the server if the number of additional requests that matches one or more attack patterns is greater than a first threshold.

Claims (66)

1. A method for mitigating a denial of service attack, the method comprising:

determining that a number of requests transmitted by a first client to a server during a first time period is greater than a first threshold;

in response, classifying the first client as a top talker;

generating one or more first attack patterns based on the requests transmitted by the first client to the server;

determining, at least partially in parallel with generating the one or more first attack patterns, that a number of requests transmitted by a second client to a server during a second time period is greater than the first threshold;

identifying additional requests being transmitted by at least one of the first client and the second client to the server;

determining that a number of the additional requests transmitted by the at least one of the first client and the second client to the server matches the one or more first attack patterns; and

in response, performing one or more operations to address the additional requests being transmitted to the server.

2. The method of claim 1 , the method further comprising:

blacklisting at least one of the first client and the second client for a predetermined time if the number of additional requests transmitted by the first client or the second client that matches the one or more first attack patterns is greater than a second threshold.

3. The method of claim 2 , the method further comprising:

determining, for the server, that a latency of processing queued requests exceeds a first limit.

4. The method of claim 3 , the method further comprising:

determining one or more additional attack patterns based on one or more of the queued requests.

5. The method of claim 3 , the method further comprising:

adjusting the first threshold and the second threshold in response to the determination that the latency of processing queued requests exceeds the first limit.

6. The method of claim 3 , the method further comprising:

determining, for the server, that the latency for processing queued requests falls below a second limit; and

ceasing any mitigation of the denial of service attack in response to the latency falling below the second limit.

7. The method of claim 3 , further comprising:

determining that the number of the additional requests transmitted by the first client to the server match one or more additional attack patterns; and

preventing one or more of the additional requests from being transmitted to the server if the number of additional requests that matches the one or more attack patterns is greater than the second threshold.

8. The method of claim 1 , further comprising:

generating, at least partially in parallel with performing the one or more operations, one or more second attack patterns based on the one or more additional requests transmitted by the second client to the server.

9. The method of claim 1 , further comprising:

determining, at least partially in parallel with performing the one or more operations, that a number of additional requests transmitted by a third client to the server during a third time period is greater than the first threshold.

10. A system for mitigating a denial of service attack, the system comprising:

at least one memory that includes instructions; and

a processor that is coupled to the memory, wherein, when the processor executes the instructions, the processor is configured to:

determine that a number of requests transmitted by a first client to a server during a first time period is greater than a first threshold;

in response, classify the first client as a top talker;

generate one or more first attack patterns based on the requests transmitted by the first client to the server;

determine, at least partially in parallel with generating the one or more first attack patterns, that a number of requests transmitted by a second client to a server during a second time period is greater than the first threshold;

identify additional requests being transmitted by at least one of the first client and the second client to the server;

determine that a number of the additional requests transmitted by the at least one of the first client and the second client to the server matches the one or more first attack patterns; and

in response, perform one or more operations to address the additional requests being transmitted to the server.

11. The system of claim 10 , wherein the processor is further configured to:

blacklist at least one of the first client and the second client for a predetermined time if the number of additional requests transmitted by the first client or the second client that matches the one or more first attack patterns is greater than a second threshold.

12. The system of claim 11 , wherein the processor is further configured to:

determine, for the server, that a latency of processing queued requests exceeds a first limit.

13. The system of claim 12 , wherein the processor is further configured to:

determine one or more additional attack patterns based on one or more of the queued requests.

14. The system of claim 12 , wherein the processor is further configured to:

adjust the first threshold and the second threshold in response to the determination that the latency of processing queued requests exceeds the first limit.

15. The system of claim 12 , wherein the processor is further configured to:

determine, for the server, that the latency for processing queued requests falls below a second limit; and

cease any mitigation of the denial of service attack in response to the latency falling below the second limit.

16. A non-transitory computer readable storage medium including instructions that, when executed by a processor, cause the processor to perform the steps of:

determining that a number of requests transmitted by a first client to a server during a first time period is greater than a first threshold;

in response, classifying the first client as a top talker;

generating one or more first attack patterns based on the requests transmitted by the first client to the server;

determining, at least partially in parallel with generating the one or more first attack patterns, that a number of requests transmitted by a second client to a server during a second time period is greater than the first threshold;

identifying additional requests being transmitted by at least one of the first client and the second client to the server;

determining that a number of the additional requests transmitted by the at least one of the first client and the second client to the server matches the one or more first attack patterns; and

in response, performing one or more operations to address the additional requests being transmitted to the server.

17. The non-transitory computer readable storage medium of claim 16 , further comprising:

blacklisting at least one of the first client and the second client for a predetermined time if the number of additional requests transmitted by the first client or the second client that matches the one or more first attack patterns is greater than a second threshold.

18. The non-transitory computer readable storage medium of claim 17 , further comprising:

determining, for the server, that a latency of processing queued requests exceeds a first limit.

19. The non-transitory computer readable storage medium of claim 18 , further comprising:

determining one or more additional attack patterns based on one or more of the queued requests.

20. The non-transitory computer readable storage medium of claim 18 , further comprising:

adjusting the first threshold and the second threshold in response to the determination that the latency of processing queued requests exceeds the first limit.

21. The non-transitory computer readable storage medium of claim 18 , further comprising:

determining, for the server, that the latency for processing queued requests falls below a second limit; and

ceasing any mitigation of the denial of service attack in response to the latency falling below the second limit.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2018
From: ZHAO, YUJIE; BHOGAVILLI, SURESH; KULKARNI, ANUPAM; SUBRAMANIAN, SIVASANKAR
To: VERISIGN, INC.
Reel/Frame 045126/0183 →
Continuity (2)
Continuation 14748571 · Jun 24, 2015
Related Publication 20180198808A1 · Jul 12, 2018