IP Library Granted Patent US 11,252,182
Granted Patent B2
US 11,252,182 · App. 16/417,367 · Granted Feb 15, 2022

Identifying malicious client network applications based on network request characteristics

Inventors: Maciej Bilas (Warsaw, PL); John Graham-Cumming (London, GB); Marek Majkowski (Warsaw, PL)
Assignee: CLOUDFLARE, INC.
H04L63/145H04L9/3271H04L43/04H04L63/1458H04L67/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,252,182
App. No.
16/417,367
Granted
Feb 15, 2022
Kind
B2
Abstract

An edge server receives a plurality of requests from a client network application for actions to be performed on a resource that is hosted at an origin server. The edge server determines request attributes of the requests and associates the request attributes with a session identifying the client network application. The edge server generates a confidence value for the client network application based at least on the determined request attributes of the plurality of requests and computed session metrics of the session. When the confidence value indicates that the client network application is malicious, the edge server performs one or more mitigation actions.

Claims (59)

1. A method, comprising:

receiving a plurality of requests from a client network application, each request in the plurality of requests for an action to be performed on a resource that is hosted at an origin server;

for the each request in the plurality of requests, determining one or more request attributes of the request and associating the one or more determined request attributes of the request with a session that identifies the client network application;

computing one or more session metrics of the session;

generating a confidence value for the client network application based at least on the determined request attributes of the plurality of requests and the computed session metrics of the session;

determining that the confidence value indicates that the client network application is malicious;

in response to determining that the confidence value indicates that the client network application is malicious, performing one or more mitigation actions.

2. The method of claim 1 , wherein generating the confidence value for the client network application comprises:

retrieving historical request data from a data structure, the historical request data including previous request attributes of previous requests from the client network application; and

analyzing the previous request attributes of the previous requests to identify patterns between the previous requests and the plurality of requests.

3. The method of claim 1 , wherein performing the one or more mitigation actions comprises:

modifying a reputation score associated with the client network application; and

initiating a challenge process in response to a subsequent request from the client network application.

4. The method of claim 1 , wherein performing the one or more mitigation actions comprises:

blocking the request from transmittal to the origin server.

5. The method of claim 1 , further comprising:

storing the one or more determined request attributes of the request and the session metrics in a data structure;

comparing request attributes of subsequent requests to the determined request attributes of the requests in the data structure; and

preventing one or more of the subsequent requests from being sent to the origin server when the request attributes of the one or more of the subsequent requests are similar to the determined request attributes of the requests in the data structure.

6. A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor, cause said processor to perform operations comprising:

receiving a plurality of requests from a client network application, each request in the plurality of requests for an action to be performed on a resource that is hosted at an origin server;

for the each request in the plurality of requests, determining one or more request attributes of the request and associating the one or more determined request attributes of the request with a session that identifies the client network application;

computing one or more session metrics of the session;

generating a confidence value for the client network application based at least on the determined request attributes of the plurality of requests and the computed session metrics of the session;

determining that the confidence value indicates that the client network application is malicious;

in response to determining that the confidence value indicates that the client network application is malicious, performing one or more mitigation actions.

7. The non-transitory machine-readable storage medium of claim 6 , wherein generating the confidence value for the client network application comprises:

retrieving historical request data from a data structure, the historical request data including previous request attributes of previous requests from the client network application; and

analyzing the previous request attributes of the previous requests to identify patterns between the previous requests and the plurality of requests.

8. The non-transitory machine-readable storage medium of claim 6 , wherein performing the one or more mitigation actions comprises:

modifying a reputation score associated with the client network application; and

initiating a challenge process in response to a subsequent request from the client network application.

9. The non-transitory machine-readable storage medium of claim 6 , wherein performing the one or more mitigation actions comprises:

blocking the request from transmittal to the origin server.

10. The non-transitory machine-readable storage medium of claim 6 that provides instructions that, when executed by the processor, cause said processor to further perform operations comprising:

storing the one or more determined request attributes of the request and the session metrics in a data structure;

comparing request attributes of subsequent requests to the determined request attributes of the requests in the data structure; and

preventing one or more of the subsequent requests from being sent to the origin server when the request attributes of the one or more of the subsequent requests are similar to the determined request attributes of the requests in the data structure.

11. An apparatus, comprising:

a processor;

a non-transitory machine-readable storage medium coupled with the processor that stores instructions that, when executed by the processor, cause said processor to perform the following:

receive a plurality of requests from a client network application, each request in the plurality of requests for an action to be performed on a resource that is hosted at an origin server;

for the each request in the plurality of requests, determine one or more request attributes of the request and associating the one or more determined request attributes of the request with a session that identifies the client network application;

compute one or more session metrics of the session;

generate a confidence value for the client network application based at least on the determined request attributes of the plurality of requests and the computed session metrics of the session;

determine that the confidence value indicates that the client network application is malicious;

in response to determining that the confidence value indicates that the client network application is malicious, perform one or more mitigation actions.

12. The apparatus of claim 11 , wherein generating the confidence value for the client network application comprises:

retrieving historical request data from a data structure, the historical request data including previous request attributes of previous requests from the client network application; and

analyzing the previous request attributes of the previous requests to identify patterns between the previous requests and the plurality of requests.

13. The apparatus of claim 11 , wherein performing the one or more mitigation actions comprises:

modifying a reputation score associated with the client network application; and

initiating a challenge process in response to a subsequent request from the client network application.

14. The apparatus of claim 11 , wherein performing the one or more mitigation actions comprises:

blocking the request from transmittal to the origin server.

15. The apparatus of claim 11 , wherein the instructions further cause said processor to perform the following:

store the one or more determined request attributes of the request and the session metrics in a data structure;

compare request attributes of subsequent requests to the determined request attributes of the requests in the data structure; and

prevent one or more of the subsequent requests from being sent to the origin server when the request attributes of the one or more of the subsequent requests are similar to the determined request attributes of the requests in the data structure.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2019
From: BILAS, MACIEJ; GRAHAM-CUMMING, JOHN; MAJKOWSKI, MAREK
To: CLOUDFLARE, INC.
Reel/Frame 049234/0455 →
Continuity (1)
Related Publication 20200374297A1 · Nov 26, 2020