IP Library Granted Patent US 12,495,068
Granted Patent B2
US 12,495,068 · App. 18/634,829 · Granted Dec 9, 2025

Protecting from denial of service attacks

Inventors: Gabi Liron (Yokneam Illit, IL); Moshe Shemesh (Tel Aviv, IL); Chen Gonen (Yeruham, IL)
Assignee: Mellanox Technologies, Ltd.
H04L63/1458G06F9/45558G06F2009/45575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,068
App. No.
18/634,829
Granted
Dec 9, 2025
Kind
B2
Abstract

Apparatuses, systems, and techniques to detect a Denial of Service (DoS) attack on a target device by an entity. In at least one embodiment, the detection is followed by an event message to prevent the entity from sending further communications to the target device.

Claims (42)

1 . A system comprising:

one or more circuits to:

determine a target is potentially under attack by an entity based at least in part on a number of communications sent to one or more memory addresses mapped by one or more registers associated with the target; and

send a notification to prevent the entity from sending additional communications to the one or more memory addresses in response to determining the target is potentially under attack, the target comprising at least one of hardware or firmware.

2 . The system of claim 1 , wherein the entity is a virtual function (“VF”) being performed by a virtual machine (“VM”) managed by a hypervisor.

3 . The system of claim 2 , wherein the notification is sent to the hypervisor, the notification being a notification to disconnect the VM.

4 . The system of claim 3 , wherein disconnecting the VM comprises disabling the VF to prevent the VF from sending additional communications to the to one or more memory addresses.

5 . The system of claim 3 , wherein disconnecting the VM comprises terminating the VM.

6 . The system of claim 1 , wherein determining the target is potentially under attack is based at least in part on the number of communications comprises determining a rate at which the communications are received, and comparing the rate to a threshold rate value.

7 . The system of claim 6 , wherein determining the rate comprises calculating the rate based only on any of the communications determined not to be valid communications.

8 . The system of claim 1 , wherein determining the target is potentially under attack by the entity is based at least in part on a number of communications sent to one or more memory addresses mapped by the one or more registers associated with the target.

9 . The system of claim 8 , wherein the one or more registers associated with the target comprise a plurality of base address registers.

10 . The system of claim 1 , wherein determining the target is potentially under attack by the entity is based at least in part on a number of communications sent to one or more memory addresses mapped to one or more registers that the entity is not authorized to access.

11 . The system of claim 1 , wherein a plurality of additional entities send an additional number of communications to one or more memory addresses mapped to one or more registers, and determining the target is potentially under attack by the entity is based at least in part on a number of communications sent by the entity to one or more memory addresses mapped to one or more registers compared to a number of additional communications sent to one or more memory addresses mapped to one or more registers by the plurality of additional entities.

12 . A method comprising:

determining a target is potentially under attack by an entity based at least in part on a number of communications sent to one or more memory addresses mapped to one or more registers associated with the target; and

sending a notification to prevent the entity from sending additional communications to the one or more memory addresses in response to determining the target is potentially under attack.

13 . The method of claim 12 , wherein the target comprises at least one of hardware or firmware.

14 . The method of claim 12 , wherein the entity is a virtual function (“VF”) being performed by a virtual machine (“VM”) managed by a hypervisor.

15 . The method of claim 14 , wherein sending the notification comprises sending the notification to the hypervisor, the notification being a notification to disconnect the VM.

16 . The method of claim 15 , wherein disconnecting the VM comprises disabling the VF to prevent the VF from sending additional communications to the to one or more memory addresses.

17 . The method of claim 15 , wherein disconnecting the VM comprises terminating the VM.

18 . The method of claim 12 , wherein determining a target is potentially under attack comprises determining a rate at which the communications are received, and comparing the rate to a threshold rate value.

19 . The method of claim 18 , wherein determining the rate comprises calculating the rate based only on any of the communications determined not to be valid communications.

20 . The method of claim 12 , wherein determining the target is potentially under attack by the entity comprises determining a number of communications sent to one or more memory addresses mapped to one or more registers associated with the target.

21 . The method of claim 20 , wherein the one or more registers associated with the target comprise a plurality of base address registers.

22 . The method of claim 12 , wherein determining the target is potentially under attack by the entity comprises determining a number of communications sent to one or more memory addresses mapped to one or more registers that the entity is not authorized to access.

23 . The method of claim 12 , wherein a plurality of additional entities send an additional number of communications to one or more memory addresses mapped to one or more registers, and determining the target is potentially under attack by the entity comprises determining a number of communications sent by the entity to one or more memory addresses mapped to one or more registers compared to a number of additional communications sent to one or more memory addresses mapped to one or more registers by the plurality of additional entities.

24 . A non-transitory machine-readable medium for use with a computer network, the non-transitory machine readable medium having stored thereon a set of instructions, which if performed by one or more processors, cause the one or more processors to at least:

determining a target is potentially under attack by an entity based at least in part on a number of communications sent to one or more memory addresses mapped to one or more registers associated with the target; and

sending a notification to prevent the entity from sending additional communications to the one or more memory addresses in response to determining the target is potentially under attack.

25 . The non-transitory machine-readable medium of claim 24 , wherein the target comprises at least one of hardware or firmware.

26 . The non-transitory machine-readable medium of claim 24 , wherein the entity is a virtual function (“VF”) being performed by a virtual machine (“VM”) managed by a hypervisor.

27 . The non-transitory machine-readable medium of claim 26 , wherein sending the notification comprises sending the notification to the hypervisor, the notification being a notification to disconnect the VM.

28 . The non-transitory machine-readable medium of claim 27 , wherein disconnecting the VM comprises disabling the VF to prevent the VF from sending additional communications to the to one or more memory addresses.

29 . The non-transitory machine-readable medium of claim 27 , wherein disconnecting the VM comprises terminating the VM.

30 . The non-transitory machine-readable medium of claim 24 , wherein the set of instructions, which if performed by the one or more processors, cause the one or more processors to at least determine a target is potentially under attack comprises determining a rate at which the communications are received, and comparing the rate to a threshold rate value.

31 . The non-transitory machine-readable medium of claim 30 , wherein determining the rate comprises calculating the rate based only on any of the communications determined not to be valid communications.

32 . The non-transitory machine-readable medium of claim 24 , wherein determining the target is potentially under attack by the entity comprises determining a number of communications sent to one or more memory addresses mapped to one or more registers associated with the target.

33 . The non-transitory machine-readable medium of claim 32 , wherein the one or more registers associated with the target comprise a plurality of base address registers.

34 . The non-transitory machine-readable medium of claim 24 , wherein the set of instructions, which if performed by the one or more processors, cause the one or more processors to at least determine the target is potentially under attack by the entity by determining a number of communications sent to one or more memory addresses mapped to one or more registers that the entity is not authorized to access.

35 . The non-transitory machine-readable medium of claim 24 , wherein a plurality of additional entities send an additional number of communications to one or more memory addresses mapped to one or more registers the set of instructions, which if performed by the one or more processors, cause the one or more processors to at least determine the target is potentially under attack by the entity by determining a number of communications sent by the entity to one or more memory addresses mapped to one or more registers compared to a number of additional communications sent to one or more memory addresses mapped to one or more registers by the plurality of additional entities.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2024
From: LIRON, GABI; SHEMESH, MOSHE; GONEN, CHEN
To: MELLANOX TECHNOLOGIES, LTD.
Reel/Frame 067094/0692 →
Continuity (1)
Related Publication 20250323937A1 · Oct 16, 2025
References Cited (14)
US 11595408B2 · Beddus et al. · 2023 [cited by applicant]
US 11700190B2 · Yadav et al. · 2023 [cited by applicant]
US 20120075314A1 · Malakapalli · 2012 [cited by examiner]
US 20120254993A1 · Sallam · 2012 [cited by examiner]
US 20140059688A1 · Margalit · 2014 [cited by examiner]
US 20160224383A1 · Bonzini · 2016 [cited by examiner]
US 20170277554A1 · Oehrlein · 2017 [cited by examiner]
US 20170286311A1 · Juenemann · 2017 [cited by examiner]
US 20230275906A1 · Zohar et al. · 2023 [cited by applicant]
CN 112015516A · 2020 [cited by examiner]
EP 2867811B1 · 2018 [cited by applicant]
EP 3633951B1 · 2024 [cited by examiner]
Extended European Search Report for Application No. 25169966.6, mailed Jun. 3, 2025, 13 pages. [cited by applicant]
Zhang et al., “DOS Attack on Your Memory in the Cloud,” retrieved from <https://dl.acm.org/doi/pdf/10.1145/3052973.3052978,> Apr. 2, 2017, 13 pages. [cited by applicant]