Systems and methods for identifying and addressing malicious network traffic based on network traffic lane activity
Disclosed herein are systems and methods for identifying and addressing malicious network traffic based on network traffic lane activity. An example method includes receiving data associated with a plurality of messages transmitted via a network, determining a first network traffic lane associated with a first set of messages of the plurality of messages and a second network traffic lane associated with a second set of messages of the plurality of messages, and determining that the first set of messages is associated with an increased probability of being involved in a distributed denial of service (DDoS) attack. In examples, the method includes causing at least one remedial action to be performed for at least a portion of messages associated with the first network traffic lane. Non-transitory machine-readable mediums are also disclosed.
1 . A method, comprising:
receiving, by at least one processor, data associated with a plurality of messages transmitted via a network;
determining, by the at least one processor, a first network traffic lane associated with a first set of messages of the plurality of messages, and a second network traffic lane associated with a second set of messages of the plurality of messages, wherein determining each of the first network traffic lane and the second network traffic lane comprises:
determining, by the at least one processor, a fingerprint for each message of the plurality of messages based on a plurality of attributes obtained from a data string associated with a transport layer security (TLS) handshake between a first device and a second device; and
assigning, by the at least one processor, each message to the first network traffic lane or the second network traffic lane based on the fingerprint;
determining, by the at least one processor, that the first set of messages is associated with an increased probability of being involved in a distributed denial of service (DDoS) attack; and
causing, by the at least one processor, at least one remedial action to be performed for at least a portion of messages associated with the first network traffic lane based on the fingerprint and the first set of messages being associated with the increased probability of being involved in a DDoS attack, wherein the at least one remedial action is performed on a per-lane basis to avoid interruption of network lanes determined to not be involved in the DDoS attack.
2 . The method of claim 1 , wherein determining the fingerprint for each message of the plurality of messages based on the plurality of attributes for each message comprises:
concatenating, for each message of the plurality of messages and by the at least one processor, identifiers for each attribute of the plurality of attributes to form the fingerprint.
3 . The method of claim 1 , wherein attributes of the set of attributes comprise one or more of:
a transport layer security (TLS) fingerprint associated with one or more messages exchanged during an initial handshake involving a client device and a server,
a header fingerprint associated with data packets exchanged between the client device and the server;
cookie fingerprints associated with one or more cookies stored by the client device; or
individual fingerprints associated with the client device.
4 . The method of claim 1 , wherein the first network traffic lane is associated with a first fingerprint type, and wherein the second network traffic lane is associated with a second fingerprint type,
wherein determining the first set of messages comprises: associating, by the at least one processor, each message of the plurality of messages having a fingerprint associated with the first fingerprint type with the first set of messages; and
wherein determining the second set of messages comprises: associating, by the at least one processor, each message of the plurality of messages having a fingerprint associated with the second fingerprint type with the second set of messages.
5 . The method of claim 1 , wherein determining that the first set of messages is associated with an increased probability of being involved in the DDoS attack comprises:
determining that an amount of messages associated with the first set of messages satisfies a threshold representing an unusual amount of network traffic for the first network traffic lane during a period of time.
6 . The method of claim 1 , wherein receiving the data associated with the plurality of messages transmitted via the network comprises:
receiving the data associated with the plurality of messages transmitted via the network by at least one reverse proxy server.
7 . The method of claim 1 , further comprising:
determining that one or more messages of the messages associated with the first network traffic lane include unique identifiers established for client devices that transmitted the one or more messages; and
forgoing the at least one remedial action to be performed for a subset of messages associated with the first network traffic lane based on the presence of the unique identifier in the messages.
8 . A system comprising:
a non-transitory machine-readable storage medium and one or more processors configured to:
receive data associated with a plurality of messages transmitted via a network;
determine a first network traffic lane associated with a first set of messages of the plurality of messages, and a second network traffic lane associated with a second set of messages of the plurality of messages, wherein determining each of the first network traffic lane and the second network traffic lane comprises:
determining, by the at least one processor, a fingerprint for each message of the plurality of messages based on a plurality of attributes obtained from a data string associated with a transport layer security (TLS) handshake between a first device and a second device; and
assigning, by the one or more processors, each message to the first network traffic lane or the second network traffic lane based on the fingerprint;
determine that the first set of messages is associated with an increased probability of being involved in a distributed denial of service (DDoS) attack; and
cause at least one remedial action to be performed for at least a portion of messages associated with the first network traffic lane based on the first set of messages being associated with the increased probability of being involved in a DDoS attack, wherein the at least one remedial action is performed on a per-lane basis to avoid interruption of network lanes determined to not be involved in the DDoS attack.
9 . The system of claim 8 , wherein the one or more processors configured to determine the fingerprint for each message of the plurality of messages based on the plurality of attributes for each message are configured to:
concatenating, for each message of the plurality of messages, identifiers for each attribute of the plurality of attributes to form the fingerprint.
10 . The system of claim 8 , wherein attributes of the set of attributes comprise one or more of:
a transport layer security (TLS) fingerprint associated with one or more messages exchanged during an initial handshake involving a client device and a server,
a header fingerprint associated with data packets exchanged between the client device and the server;
cookie fingerprints associated with one or more cookies stored by the client device; or
individual fingerprints associated with the client device.
11 . The system of claim 8 , wherein the first network traffic lane is associated with a first fingerprint type, wherein the second network traffic lane is associated with a second fingerprint type,
wherein the one or more processors configured to determine the first set of messages are configured to: associate each message of the plurality of messages having a fingerprint associated with the first fingerprint type with the first set of messages; and
wherein the one or more processors configured to determine the second set of messages are configured to: associate each message of the plurality of messages having a fingerprint associated with the second fingerprint type with the second set of messages.
12 . The system of claim 8 , wherein the one or more processors configured to determine that the first set of messages is associated with an increased probability of being involved in the DDoS attack are configured to:
determine that an amount of messages associated with the first set of messages satisfies a threshold representing an unusual amount of network traffic for the first network traffic lane during a period of time.
13 . The system of claim 8 , wherein the one or more processors configured to receive the data associated with the plurality of messages transmitted via the network are configured to:
receive the data associated with the plurality of messages transmitted via the network by at least one reverse proxy server.
14 . The system of claim 8 , wherein the one or more processors are further configured to:
determine that one or more messages of the messages associated with the first network traffic lane include unique identifiers established for client devices that transmitted the one or more messages; and
forgo the at least one remedial action to be performed for a subset of messages associated with the first network traffic lane based on the presence of the unique identifier in the messages.
15 . A non-transitory machine-readable storage medium having computer-executable instructions stored thereon that, when executed by one or more processors, cause the one or more processors to:
receive data associated with a plurality of messages transmitted via a network;
determine a first network traffic lane associated with a first set of messages of the plurality of messages, and a second network traffic lane associated with a second set of messages of the plurality of messages, wherein determining each of the first network traffic lane and the second network traffic lane comprises:
determining, by the at least one processor, a fingerprint for each message of the plurality of messages based on a plurality of attributes obtained from a data string associated with a transport layer security (TLS) handshake between a first device and a second device; and
assign each message to the first network traffic lane or the second network traffic lane based on the fingerprint;
determine that the first set of messages is associated with an increased probability of being involved in a distributed denial of service (DDoS) attack; and
cause at least one remedial action to be performed for at least a portion of messages associated with the first network traffic lane based on the first set of messages being associated with the increased probability of being involved in a DDoS attack, wherein the at least one remedial action is performed on a per-lane basis to avoid interruption of network lanes determined to not be involved in the DDoS attack.
16 . The non-transitory machine-readable storage medium of claim 15 , wherein the instructions that cause the one or more processors to determine the fingerprint for each message of the plurality of messages based on the plurality of attributes for each message cause the one or more processors to:
concatenate, for each message of the plurality of messages, identifiers for each attribute of the plurality of attributes to form the fingerprint.
17 . The non-transitory machine-readable storage medium of claim 15 , wherein attributes of the set of attributes comprise one or more of:
a transport layer security (TLS) fingerprint associated with one or more messages exchanged during an initial handshake involving a client device and a server,
a header fingerprint associated with data packets exchanged between the client device and the server;
cookie fingerprints associated with one or more cookies stored by the client device; or
individual fingerprints associated with the client device.