Network overload detection and mitigation system and method
Abstract
Systems and methods are provided for detecting and mitigating overload conditions affecting one or more computers attached to a network, such as overloads resulting from distributed denial of service (DDoS) attacks, for example. According to some described embodiments, an attempted overload condition is detected, e.g., by a system, through following a method, or both, within a data cleaning center. Detection may be achieved, e.g., by analyzing data packets traveling over the network to identify packets that bear characteristics that may be associated with DDoS attacks, and this analysis may include examination of the packets' data payloads. Mitigation, in turn, may include discarding some data packets, redirecting network traffic, or some combination thereof.
Claims
exact text as granted — not AI-modified1 . A system for detecting and mitigating an attempted overload condition targeting a domain name server, comprising:
a network connection for receiving a plurality of DNS requests from one or more client computers located on a network, the plurality of DNS requests directed to a DNS server; and a processor for providing a response to the plurality of DNS requests to the one or more client computers, instead of the DNS server, if the processor detects that a threshold number of the plurality of DNS requests received over a time period are substantially duplicate.
2 . The system of claim 1 , wherein the processor discards any of the DNS requests that are not directed to port 53 .
3 . The system of claim 1 , wherein the processor discards any DNS request that does not pass a DNS sanity check.
4 . The system of claim 1 , wherein the processor discards each request containing a domain name that is not on a list as a valid domain name.
5 . The system of claim 1 , wherein the processor detects whether a threshold number of DNS requests are duplicate by storing the received requests in a database, counting the number of requests for a domain name from the same source to produce a hit count over a period of time, and comparing the hit count against a threshold value.
6 . The system of claim 5 , wherein the processor detects whether a threshold number of DNS requests are duplicate for two or more domain names to produce a hit count over a period of time for each of the two or more domain names.
7 . A system for detecting an attempted overload condition targeting a networked computer system, comprising:
a network connection for receiving a data packet having an HTTP header; and an attack detection module to determine whether a user agent header entry in the HTTP header contains a non-alphabetical character.
8 . The system of claim 7 , further comprising an attack mitigation module to discard the data packet if the user agent header entry contains a non-alphabetical character.
9 . A system for detecting an attempted overload condition targeting a networked computer system, comprising:
a network connection for receiving a data packet having an HTTP header; and an attack detection module to determine whether a host value header entry exists in the HTTP header.
10 . The system of claim 9 , wherein the attack mitigation module discards the data packet if the host value header entry does not exist in the HTTP header.
11 . A system for detecting an attempted overload condition targeting a networked computer system, comprising:
a network connection for receiving a data packet; and an attack detection module to determine whether the contents of the data packet include a valid line break indicator.
12 . The system of claim 11 , further comprising an attack mitigation module to discard the data packet if the contents of the data packet do not include a valid line break indicator.
13 . A system for mitigating an overload condition targeting a networked computer system, comprising:
a network connection for receiving a plurality of data packets from one or more first computers located on a network, the data packets including a plurality of GET commands directed toward one or more second computers located on the network; and an attack mitigation module to determine whether a number of duplicate GET commands that have been received-exceeds a threshold value.
14 . The system of claim 13 , wherein the attack mitigation module blocks the duplicate GET commands if the threshold value is exceeded.
15 . The system of claim 13 , wherein the attack mitigation module performs a hash function on the received GET commands to determine if the GET commands are duplicates.
16 . A system for preventing an attempted overload condition targeting a networked computer system, comprising:
a network connection for receiving one or more initial data packets from one or more first computers for processing by a second computer; a redirection module to redirect the first computer to send the one or more initial data packets to a third computer; an attack detection module to determine whether the one or more initial data packets are a part of an attempted overload condition; and wherein the redirection module redirects the one or more first computers to send one or more subsequent data packets directly to the second computer if the attack detection module determines that the initial data packets are not a part of an attempted overload condition.
17 . The system of claim 16 , wherein the domain name of the third computer has a different prefix than the domain name of the second computer.
18 . The system of claim 17 , wherein the domain name of the second computer has a prefix of www, and the domain name of the third computer has a prefix of wwwn, wherein n is a numeric value.
19 . The system of claim 16 , wherein the attack detection module determines whether the one or more initial data packets are a part of the attempted overload condition by determining whether the network connection has received the one or more initial data packets from one or more browsers executing on the one or more first computers.
20 . The system of claim 19 , wherein the attack detection module determines whether the network connection has received the one or more initial data packets from one or more browsers executing on the one or more first computers by attempting to write one or more cookies to the one or more first computers.
21 . The system of claim 19 , wherein the attack detection module determines whether the network connection has received the one or more initial data packets from one or more browsers executing on the one or more first computers by providing a representation of text, in a non-machine readable format, to be typed into the one or more browsers by one or more users.
22 . A system for preventing an attempted overload condition targeting a networked computer system, comprising:
a network connection for receiving one or more initial data packets from one or more first computers for processing by one or more second computers; a redirection module to redirect the one or more first computers to send the one or more initial data packets to one or more third computers; an attack detection module to determine whether the one or more initial data packets are a part of an attempted overload condition; and wherein the redirection module redirects the one or more first computers to send one or more subsequent data packets directly to the one or more second computers if the attack detection module determines that the initial data packets are not a part of an attempted overload condition.Join the waitlist — get patent alerts
Track US2009037592A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.