IP Library Granted Patent US 10,270,794
Granted Patent B1
US 10,270,794 · App. 15/893,519 · Granted Apr 23, 2019

Detection of denial of service attacks

Inventors: Arindum Mukerji (Seattle, WA); Khurram Waheed (Melbourne, AU)
Assignee: ExtraHop Networks, Inc.
H04L63/1425H04L63/1458H04L2463/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,270,794
App. No.
15/893,519
Granted
Apr 23, 2019
Kind
B1
Abstract

Embodiments are directed to monitoring network traffic over a network using one or more network monitoring computers. A monitoring engine may be instantiated to perform actions, including: monitoring network traffic to identify client requests provided by clients and server responses provided by servers in response to the client requests; determining request metrics associated with the client requests; and determining response metrics associated with the server responses. An analysis engine may be instantiated that performs actions, including: comparing the request metrics with the response metrics; determining atypical behavior associated with the clients based on the comparison such that the atypical behavior includes an absence of adaption by the clients to changes in the server responses; and providing alerts that may identify the clients be associated with the atypical behavior.

Claims (116)

1. A method for monitoring network traffic between two or more network computers using one or more network monitoring computers, wherein execution of instructions by the one or more networking monitoring computers perform the method comprising:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic to identify one or more client requests provided by one or more clients and one or more server responses provided by one or more servers to the one or more client requests;

determining one or more request metrics that are associated with baseline behavior for the one or more client requests;

determining one or more response metrics that are associated with baseline behavior for the one or more server responses; and

instantiating an analysis engine that performs actions, comprising:

comparing the one or more request metrics for the identified one or more clients to previously determined one or more request metrics for a class of other clients;

determining atypical behavior associated with the one or more identified clients based on the comparison, wherein the atypical behavior includes an absence of adaption by the one or more identified clients to one or more synthetic modifications that increase one or more of an apparent latency or delay in the one or more server responses; and

providing one or more alerts that identify the one or more identified clients associated with the atypical behavior.

2. The method of claim 1 , wherein the comparison of the one or more request metrics and the one or more response metrics, further comprises:

comparing one or more transaction rates associated with the one or more identified clients and the one or more servers to one or more client request send rates;

determining one or more atypical behavior clients based on the comparison, wherein the one or more client request send rates associated with the one or more atypical behavior clients increases or remains constant as the one or more transaction rates decrease.

3. The method of claim 1 , wherein the analysis engine performs further actions, comprising:

comparing the one or more client requests to one or more expected client requests that are based on an application provided by the one or more servers; and

determining one or more atypical behavior clients based on the comparison, wherein the one or more atypical behavior clients send one or more of the one or more client requests that include atypical communication with the application.

4. The method of claim 1 , wherein the analysis engine performs further actions, comprising:

correlating the one or more client requests with the one or more server responses based on one or more characteristics of the one or more client requests and the one or more server responses;

comparing the one or more correlated client requests with the one or more correlated server responses;

determining one or more atypical behavior clients based on a result of the correlated comparison.

5. The method of claim 1 , wherein the analysis engine performs further actions, comprising:

assigning a weight value to the one or more client requests based on a payload size or a performance load associated with the one or more server responses; and

determining one or more atypical behavior clients based on the one or more weighted client requests, wherein the one or more atypical behavior clients send the one or more client requests that are weighted more than the one or more weighted client requests associated with one or more other clients that perform typical behavior.

6. The method of claim 1 , wherein the analysis engine performs further actions, including modifying one or more network characteristics of the one or more server responses to the one or more identified clients, wherein the modification increases the apparent latency or transaction rate of the one or more servers to reduce a rate of the one or more server responses.

7. The method of claim 1 , wherein the monitoring engine performs further actions, comprising:

monitoring network traffic that occurs inside a trusted network; and

collecting the one or more request metrics and the one or more response metrics based on the network traffic that occurs inside the trusted network.

8. A processor readable non-transitory storage media that includes instructions for monitoring network traffic between two or more network computers using one or more network monitoring computers, wherein execution of the instructions by the one or more networking monitoring computers perform the method comprising:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic to identify one or more client requests provided by one or more clients and one or more server responses provided by one or more servers to the one or more client requests;

determining one or more request metrics that are associated with baseline behavior for the one or more client requests;

determining one or more response metrics that are associated with baseline behavior for the one or more server responses; and

instantiating an analysis engine that performs actions, comprising:

comparing the one or more request metrics for the identified one or more clients to previously determined one or more request metrics for a class of other clients;

determining atypical behavior associated with the one or more identified clients based on the comparison, wherein the atypical behavior includes an absence of adaption by the one or more identified clients to one or more synthetic modifications that increase one or more of an apparent latency or delay in the one or more server responses; and

providing one or more alerts that identify the one or more identified clients associated with the atypical behavior.

9. The media of claim 8 , wherein the comparison of the one or more request metrics and the one or more response metrics, further comprises:

comparing one or more transaction rates associated with the one or more identified clients and the one or more servers to one or more client request sent rates;

determining one or more atypical behavior clients based on the comparison, wherein the one or more client request send rates associated with the one or more atypical behavior clients increases or remains constant as the one or more transaction rates decrease.

10. The media of claim 8 , wherein the analysis engine performs further actions, comprising:

comparing the one or more client requests to one or more expected client requests that are based on an application provided by the one or more servers; and

determining one or more atypical behavior clients based on the comparison, wherein the one or more atypical behavior clients send one or more of the one or more client requests that include atypical communication with the application.

11. The media of claim 8 , wherein the analysis engine performs further actions, comprising:

correlating the one or more client requests with the one or more server responses based on one or more characteristics of the one or more client requests and the one or more server responses;

comparing the one or more correlated client requests with the one or more correlated server responses;

determining one or more atypical behavior clients based on a result of the correlated comparison.

12. The media of claim 8 , wherein the analysis engine performs further actions, comprising:

assigning a weight value to the one or more client requests based on a payload size or a performance load associated with the one or more server responses; and

determining one or more atypical behavior clients based on the one or more weighted client requests, wherein the one or more atypical behavior clients send the one or more client requests that are weighted more than the one or more weighted client requests associated with one or more other clients that perform typical behavior.

13. The media of claim 8 , wherein the analysis engine performs further actions, including modifying one or more network characteristics of the one or more server responses to the one or more identified clients, wherein the modification increases the apparent latency or transaction rate of the one or more servers to reduce a rate of the one or more server responses.

14. The media of claim 8 , wherein the monitoring engine performs further actions, comprising:

monitoring network traffic that occurs inside a trusted network; and

collecting the one or more request metrics and the one or more response metrics based on the network traffic that occurs inside the trusted network.

15. A system for monitoring network traffic in a network:

one or more network monitoring computers (NMCs), comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic to identify one or more client requests provided by one or more clients and one or more server responses provided by one or more servers to the one or more client requests;

determining one or more request metrics that are associated with baseline behavior for the one or more client requests;

determining one or more response metrics that are associated with baseline behavior for the one or more server responses; and

instantiating an analysis engine that performs actions, comprising:

comparing the one or more request metrics for the identified one or more clients to previously determined one or more request metrics for a class of other clients;

determining atypical behavior associated with the one or more identified clients based on the comparison, wherein the atypical behavior includes an absence of adaption by the one or more identified clients to one or more synthetic modifications that increase one or more of an apparent latency or delay in the one or more server responses; and

providing one or more alerts that identify the one or more identified clients associated with the atypical behavior; and

one or more client computers, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more of the one or more client requests.

16. The system of claim 15 , wherein the comparison of the one or more request metrics and the one or more response metrics, further comprises:

comparing one or more transaction rates associated with the one or more identified clients and the one or more servers to one or more client request send rates;

determining one or more atypical behavior clients based on the comparison, wherein the one or more client request send rates associated with the one or more atypical behavior clients increases or remains constant as the one or more transaction rates decrease.

17. The system of claim 15 , wherein the analysis engine performs further actions, comprising:

comparing the one or more client requests to one or more expected client requests that are based on an application provided by the one or more servers; and

determining one or more atypical behavior clients based on the comparison, wherein the one or more atypical behavior clients send one or more of the one or more client requests that include atypical communication with the application.

18. The system of claim 15 , wherein the analysis engine performs further actions, comprising:

correlating the one or more client requests with the one or more server responses based on one or more characteristics of the one or more client requests and the one or more server responses;

comparing the one or more correlated client requests with the one or more correlated server responses;

determining one or more atypical behavior clients based on a result of the correlated comparison.

19. The system of claim 15 , wherein the analysis engine performs further actions, comprising:

assigning a weight value to the one or more client requests based on a payload size or a performance load associated with the one or more server responses; and

determining one or more atypical behavior clients based on the one or more weighted client requests, wherein the one or more atypical behavior clients send the one or more client requests that are weighted more than the one or more weighted client requests associated with one or more other clients that perform typical behavior.

20. The system of claim 15 , wherein the analysis engine performs further actions, including modifying one or more network characteristics of the one or more server responses to the one or more identified clients, wherein the modification increases the apparent latency or transaction rate of the one or more servers to reduce a rate of the one or more server responses.

21. The system of claim 15 , wherein the monitoring engine performs further actions, comprising:

monitoring network traffic that occurs inside a trusted network; and

collecting the one or more request metrics and the one or more response metrics based on the network traffic that occurs inside the trusted network.

22. A network monitoring computer (NMC) for monitoring communication over a network between one or more computers, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic to identify one or more client requests provided by one or more clients and one or more server responses provided by one or more servers to the one or more client requests;

determining one or more request metrics that are associated with baseline behavior for the one or more client requests;

determining one or more response metrics that are associated with baseline behavior for the one or more server responses; and

instantiating an analysis engine that performs actions, comprising:

comparing the one or more request metrics for the identified one or more clients to previously determined one or more request metrics for a class of other clients;

determining atypical behavior associated with the one or more identified clients based on the comparison, wherein the atypical behavior includes an absence of adaption by the one or more identified clients to one or more synthetic modifications that increase one or more of an apparent latency or delay in the one or more server responses; and

providing one or more alerts that identify the one or more identified clients associated with the atypical behavior.

23. The network monitoring computer of claim 22 , wherein the comparison of the one or more request metrics and the one or more response metrics, further comprises:

comparing one or more transaction rates associated with the one or more identified clients and the one or more servers to one or more client request send rates;

determining one or more atypical behavior clients based on the comparison, wherein the one or more client request send rates associated with the one or more atypical behavior clients increases or remains constant as the one or more transaction rates decrease.

24. The network monitoring computer of claim 22 , wherein the analysis engine performs further actions, comprising:

comparing the one or more client requests to one or more expected client requests that are based on an application provided by the one or more servers; and

determining one or more atypical behavior clients based on the comparison, wherein the one or more atypical behavior clients send one or more of the one or more client requests that include atypical communication with the application.

25. The network monitoring computer of claim 22 , wherein the analysis engine performs further actions, comprising:

correlating the one or more client requests with the one or more server responses based on one or more characteristics of the one or more client requests and the one or more server responses;

comparing the one or more correlated client requests with the one or more correlated server responses;

determining one or more atypical behavior clients based on a result of the correlated comparison.

26. The network monitoring computer of claim 22 , wherein the analysis engine performs further actions, comprising:

assigning a weight value to the one or more client requests based on a payload size or a performance load associated with the one or more server responses; and

determining one or more atypical behavior clients based on the one or more weighted client requests, wherein the one or more atypical behavior clients send the one or more client requests that are weighted more than the one or more weighted client requests associated with one or more other clients that perform typical behavior.

27. The network monitoring computer of claim 22 , wherein the analysis engine performs further actions, including, modifying one or more network characteristics of the one or more server responses to the one or more identified clients, wherein the modification increases the apparent latency or transaction rate of the one or more servers to reduce a rate of the one or more server responses.

28. The network monitoring computer of claim 22 , wherein the monitoring engine performs further actions, comprising:

monitoring network traffic that occurs inside a trusted network; and

collecting the one or more request metrics and the one or more response metrics based on the network traffic that occurs inside the trusted network.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2018
From: MUKERJI, ARINDUM; WAHEED, KHURRAM
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 044886/0859 →
Cited By (10)
US 12,212,581 US 12,225,030 US 12,309,192 US 12,355,816 US 12,418,563 US 12,423,315 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312