US2015200960A1PendingUtilityA1

Techniques for protecting against denial of service attacks near the source

Assignee: AMAZON TECH INCPriority: Dec 29, 2010Filed: Feb 23, 2015Published: Jul 16, 2015
Est. expiryDec 29, 2030(~4.4 yrs left)· nominal 20-yr term from priority
H04L 63/1458H04L 63/1416
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods protect against denial of service attacks. Remotely originated network traffic addressed to one or more network destinations is routed through one or more locations. One or more of the locations may be geographically proximate to a source of a denial of service attack. One or more denial of service attack mitigation strategies is applied to portions of the network traffic received at the one or more locations. Network traffic not blocked pursuant to the one or more denial of service attack mitigation strategies is dispatched to its intended recipient. Dispatching the unblocked network traffic to its intended recipient may include the use of one or more private channels and/or one or more additional denial of service attack mitigation strategies.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A computer-implemented method, comprising:
 detecting, by a computing device included in a network, a network condition indicative of a distributed denial of service attack directed to a victim;   in response to detecting the network condition, identify an internet protocol address associated with the victim;   selecting, based at least in part on the network condition, a remotely deployed network point of presence of the network that is geographically proximate to an origin of the distributed denial of service attack;   taking one or more actions that cause the selected remotely deployed network point of presence to, at least:
 announce, utilizing a border gateway protocol, the internet protocol address of the victim to servers external to the network; 
 receive network traffic addressed to the victim; 
 block a first portion of the network traffic addressed to the victim; and 
 send, a first unblocked portion of the network traffic toward the victim; 
   receiving the first unblocked portion of the network traffic;   blocking, by the computing device, a second portion of the network traffic to determine a second unblocked portion of the network traffic addressed to the victim; and   forwarding the second unblocked portion of the network traffic toward the victim.   
     
     
         3 . The computer-implemented method of  claim 2 , where the remotely deployed network point of presence is communicatively coupled with the victim via a private channel. 
     
     
         4 . The computer-implemented method of  claim 2 , wherein blocking the first portion of the network traffic and blocking the second portion of the network traffic includes applying a set of mitigation techniques to the network traffic. 
     
     
         5 . A computer system, comprising:
 one or more processors; and   memory including executable instructions that, when executed by the one or more processors, cause the computer system to, at least:
 receive information indicating a distributed denial of service attack directed to a network destination; 
 select a remotely deployed network point of presence of the network that is a geographical distance from an origin of the distributed denial of service attack; 
 take one or more actions that cause the selected remotely deployed network point of presence to, at least:
 announce an addressing route associated with the network destination to servers external with respect to the network, the announcement utilizing a border gateway protocol; and 
 redirect network traffic addressed to the victim based on the announcement. 
 
   
     
     
         6 . The computer system of  claim 5 , wherein the one or more actions further cause the selected remotely deployed network point of presence to, at least:
 block a first portion of the network traffic addressed to the network destination; and   send an unblocked portion of the network traffic toward the network destination.   
     
     
         7 . The computer system of  claim 6 , further comprising:
 blocking a second portion of the network traffic addressed to the victim; and   sending a second unblocked portion of the network traffic toward the victim.   
     
     
         8 . The computer system of  claim 5 , wherein the addressing route includes an Internet protocol address used on a public network. 
     
     
         9 . The computer system of  claim 5 , wherein announcement of the addressing route causes the remotely deployed network point of presence to receive network traffic addressed to the network destination. 
     
     
         10 . The computer system of  claim 5 , wherein the network traffic was routed to a destination other than the remotely deployed network point of presence prior to the announcement of the addressing route. 
     
     
         11 . The computer system of  claim 5 , wherein the geographical distance of the selected remotely deployed network point of presence to the origin is less than geographical distances of other remotely deployed network points of presence of the network. 
     
     
         12 . The computer system of  claim 5 , wherein the selected remotely deployed network point of presence is located in a first country that is different than a second country associated with the network destination. 
     
     
         13 . One or more computer-readable storage media having stored thereon instructions executable by one or more processors of a computer system that, when executed with the one or more processors, cause the computer system to at least:
 detect attack traffic indicative of a distributed denial of service attack directed to a network destination;   in response to detecting the attack traffic, identify an Internet protocol address associated with the network destination;   select a remotely deployed network point of presence of the network based on an origin of the distributed denial of service attack;   take one or more actions that cause the selected remotely deployed network point of presence to, at least:
 announce the Internet protocol address to an entity external to the network utilizing a border gateway protocol; 
 discard network traffic indicative of the distributed denial of service attack at the remotely deployed network point of presence; and 
 forward non-discarded network traffic addressed toward the network destination. 
   
     
     
         14 . The one or more computer-readable storage media of  claim 13 , wherein the one or more actions further causes the selected remotely deployed network point of presence to, at least:
 receive a first portion of network traffic addressed to the network destination;   apply a set of mitigation techniques, wherein the set of mitigation techniques identify network traffic to be discarded.   
     
     
         15 . The one or more computer-readable storage media of  claim 14 , including further instructions that, when executed with the one or more processors, cause the computer system to at least:
 receive a second portion of network traffic addressed to the network destination at a computing device located closer to the network destination than the selected remotely deployed network point of presence.   
     
     
         16 . The one or more computer-readable storage media of  claim 15 , wherein the second portion of network traffic includes less traffic than the first portion of network traffic. 
     
     
         17 . The one or more computer-readable storage media of  claim 15 , including further instructions that, when executed with the one or more processors, cause the computer system to at least:
 apply an additional set of mitigation techniques; and   discard additional network traffic based at least in part on the additional set of mitigation techniques.   
     
     
         18 . The one or more computer-readable storage media of  claim 17 , wherein the additional set of mitigation techniques are computationally more expensive than the set of mitigation techniques applied by the remotely deployed network point of presence. 
     
     
         19 . The one or more computer-readable storage media of  claim 13 , wherein the selected remotely deployed network point of presence is geographically closer to the origin of the distributed denial of service attack than all other computing devices in the network. 
     
     
         20 . The one or more computer-readable storage media of  claim 13 , wherein the selected remotely deployed network point of presence is located in a same country as the origin of the distributed denial of service attack. 
     
     
         21 . The one or more computer-readable storage media of  claim 13 , wherein the network destination corresponds to a virtual machine instance.

Join the waitlist — get patent alerts

Track US2015200960A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.