IP Library Granted Patent US 7,721,091
Granted Patent B2
US 7,721,091 · App. 11/433,534 · Granted May 18, 2010

Method for protecting against denial of service attacks using trust, quality of service, personalization, and hide port messages

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,721,091
App. No.
11/433,534
Granted
May 18, 2010
Kind
B2
Abstract

According to an embodiment of the invention, a method for processing a plurality of service requests in a client-server system includes server steps of receiving at least one request for service from a client and providing a level of service based on a trust level provided in the at least one request. According to another embodiment, a method of authenticating messages includes steps of: embedding authentication information into a message at the application level; downloading a script from a computer for sending the message; running said script to send said message to a server; and checking said message by said server at the network level.

Claims (12)

1. A method for processing a plurality of requests in a client-server system, the method comprising steps of:

receiving at least one request from a client at a server;

computing a trust level score for the client based on the at least one request wherein said trust level score is based on an amount of resources expended by the server in handling the at least one request such that a higher trust level score is computed for requests consuming less system resources;

assigning the trust level score to the client based on the at least one request;

embedding the assigned trust level score in a hypertext transfer protocol trust cookie included in all responses sent from the server to the client, wherein the trust cookie comprises a client IP address, a server IP address, a time at which the trust cookie was issued, and the assigned trust level score;

serving the client presenting a valid trust cookie at a priority level associated with the assigned trust level score;

for the client with a low assigned trust level score, limiting a number of requests that said client can issue per unit of time; and

dropping any request from a client with no trust cookie or an invalid trust cookie.

2. The method of claim 1 , further comprising modifying the assigned trust level score provided to the client based on a subsequent request.

3. The method of claim 1 wherein the trust cookie further comprises a flag denoting a sentinel.

4. The method of claim 1 wherein the trust cookie further comprises a secret cryptographic key.

5. The method of claim 1 wherein the trust cookie further comprises a symmetric key encryption algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2006
From: IYENGAR, ARUN K.; SRIVATSA, MUDHAKAR; YIN, JIAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 017790/0632 →
Continuity (1)
Related Publication 20070266426A1 · Nov 15, 2007