IP Library Granted Patent US 11,496,513
Granted Patent B2
US 11,496,513 · App. 17/138,723 · Granted Nov 8, 2022

Method and apparatus for distributed emulation of behavior of a malicious domain

Inventor: Justin Matthew Paine (Berkeley, CA)
Assignee: CLOUDFLARE, INC.
H04L63/1483H04L63/1425H04L63/1466H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,513
App. No.
17/138,723
Granted
Nov 8, 2022
Kind
B2
Abstract

A method and apparatus that provide a malicious domain emulator in a distributed cloud computing network are described. A malicious node emulator is executed as a third-party code in a compute server of the cloud computing platform to enable emulation of behavior of a malicious node. The malicious node emulator receives requests from one or multiple network devices addressed to the malicious domain and automatically emulates the behavior of the malicious domain to respond to these requests. The malicious node emulator logs information related to the requests and the network devices transmitting the requests.

Claims (37)

1. A method comprising:

receiving, at a first compute server of a plurality of compute servers, a first request from a first client device; and

responsive to determining that the first request is destined to a malicious domain, running a malicious node emulator in one of a plurality of isolated execution environments of a single process in the first compute server, wherein the malicious node emulator emulates an expected behavior of a server that hosts the malicious domain, wherein the one of a plurality of isolated execution environments is not a container or a virtual machine, wherein the plurality of isolated execution environments are managed in user space and not by an operating system and run at a same time within the single process, and wherein the single process switches between the plurality of isolated execution environments in which a first code in a first isolated execution environment of the plurality of isolated execution environments does not interfere with a second code running in a second isolated execution environment of the plurality of isolated execution environments despite being in a same process; and

transmitting by the first compute server to the first client device a first response that is consistent with the expected behavior of the server that hosts the malicious domain.

2. The method of claim 1 , wherein the malicious domain is registered with a proxy service causing requests for the malicious domain to be received to compute servers from the plurality of compute servers instead of the server that hosts the malicious domain.

3. The method of claim 1 , wherein the first request from the first client device is received at the first compute server of the plurality of compute servers as a result of a domain name service (DNS) request for the malicious domain.

4. The method of claim 1 further comprising:

receiving, at the first compute server of the plurality of compute servers, a second request from a second client device; and

responsive to determining that second request is not destined to a malicious domain, fulfilling the second request.

5. The method of claim 4 , wherein the fulfilling the second request includes transmitting the second request to an origin server.

6. The method of claim 1 further comprising:

analyzing the behavior of the server that hosts the malicious domain based at least in part on information related to the first request.

7. A non-transitory machine-readable storage medium of a first-compute server of a plurality of compute servers, that provides instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving, at a first compute server of a plurality of compute servers, a first request from a first client device; and

responsive to determining that the first request is destined to a malicious domain, running a malicious node emulator in one of a plurality of isolated execution environments of a single process in the first compute server, wherein the malicious node emulator emulates an expected behavior of a server that hosts the malicious domain, wherein the one of a plurality of isolated execution environments is not a container or a virtual machine, wherein the plurality of isolated execution environments are managed in user space and not by an operating system and run at a same time within the single process, and wherein the single process switches between the plurality of isolated execution environments in which a first code in a first isolated execution environment of the plurality of isolated execution environments does not interfere with a second code running in a second isolated execution environment of the plurality of isolated execution environments despite being in a same process; and

transmitting by the first compute server to the first client device a first response that is consistent with the expected behavior of the server that hosts the malicious domain.

8. The non-transitory machine-readable storage medium of claim 7 , wherein the malicious domain is registered with a proxy service causing requests for the malicious domain to be received to compute servers from the plurality of compute servers instead of the server that hosts the malicious domain.

9. The non-transitory machine-readable storage medium of claim 7 , wherein the first request from the first client device is received at the first compute server of the plurality of compute servers as a result of a domain name service (DNS) request for the malicious domain.

10. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise:

receiving, at the first compute server of the plurality of compute servers, a second request from a second client device; and

responsive to determining that second request is not destined to a malicious domain, fulfilling the second request.

11. The non-transitory machine-readable storage medium of claim 10 , wherein the fulfilling the second request includes transmitting the second request to an origin server.

12. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise:

analyzing the behavior of the server that hosts the malicious domain based at least in part on information related to the first request.

13. A first compute server comprising:

a set of one or more processors; and

a non-transitory machine-readable storage medium that provides instructions that, when executed by the set of one or more processors, cause the set of one or more processors to perform operations comprising:

receiving, at the first compute server of a plurality of compute servers, a first request from a first client device; and

responsive to determining that the first request is destined to a malicious domain, running a malicious node emulator in one of a plurality of isolated execution environments of a single process in the first compute server, wherein the malicious node emulator emulates an expected behavior of a server that hosts the malicious domain, wherein the one of a plurality of isolated execution environments is not a container or a virtual machine, wherein the plurality of isolated execution environments are managed in user space and not by an operating system and run at a same time within the single process, and wherein the single process switches between the plurality of isolated execution environments in which a first code in a first isolated execution environment of the plurality of isolated execution environments does not interfere with a second code running in a second isolated execution environment of the plurality of isolated execution environments despite being in a same process; and

transmitting by the first compute server to the first client device a first response that is consistent with the expected behavior of the server that hosts the malicious domain.

14. The first compute server of claim 13 , wherein the malicious domain is registered with a proxy service causing requests for the malicious domain to be received to compute servers from the plurality of compute servers instead of the server that hosts the malicious domain.

15. The first compute server of claim 13 , wherein the first request from the first client device is received at the first compute server of the plurality of compute servers as a result of a domain name service (DNS) request for the malicious domain.

16. The first compute server of claim 13 , wherein the operations further comprise:

receiving, at the first compute server of the plurality of compute servers, a second request from a second client device; and

responsive to determining that second request is not destined to a malicious domain, fulfilling the second request.

17. The first compute server of claim 16 , wherein the fulfilling the second request includes transmitting the second request to an origin server.

18. The first compute server of claim 13 , wherein the operations further comprise: analyzing the behavior of the server that hosts the malicious domain based at least in part on information related to the first request.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2020
From: PAINE, JUSTIN MATTHEW
To: CLOUDFLARE, INC.
Reel/Frame 054781/0844 →
Continuity (2)
Continuation 16553105 · Aug 27, 2019
Related Publication 20210120036A1 · Apr 22, 2021