Proactive network attack demand management
Abstract
Various embodiments described and illustrated herein provide one or more of systems, methods, software, and firmware to handle attack generated demand proactively using distributed virtualization. One goal of some such embodiments is to provide a time window of stable operational response within which an intrusion detection system may detect an attack and/or cause a countermeasure against the attacks to be activated. Demand excursions which are not caused by an attack are supported during the variability of demand providing transparent response to legitimate users of the system. These embodiments, and others, are described in greater detail below.
Claims
exact text as granted — not AI-modified1 - 15 . (canceled)
16 . At least one machine readable medium including instructions that, when executed by a machine, cause the machine to perform operations comprising:
receiving a network request that is suspected to be part of an attack on a network, the network request directed to a first resource available on the network; intercepting the network request in response to the network request being part of the attack and routing the request to a virtual local area network; and servicing the network request from a second resource available on the virtual local area network.
17 . The machine readable medium of claim 16 , wherein servicing the network request from the second resource includes instantiating a virtual machine on the virtual local area network to service the network request.
18 . The machine readable medium of claim 17 , wherein the virtual machine is instantiated in response to a first network request corresponding to the suspected attack, the network request being one of a plurality of network requests that correspond to the suspected attack.
19 . The machine readable medium of claim 16 , wherein the network request is one of a plurality of requests that correspond to the suspected network attack, the plurality of requests related via application of an attack detection rule.
20 . The machine readable medium of claim 19 , wherein the suspected attack begins with the first request of the plurality of requests and persists through a predetermined time period.
21 . The machine readable medium of claim 20 , comprising performing additional attack analysis during the predetermined time period on requests in the plurality of requests received during the predetermined time period.
22 . The machine readable medium of claim 21 , comprising denying requests of the plurality of requests when the additional attack analysis indicates that the suspected attack is an actual attack and allowing requests to the first resource otherwise.
23 . The machine readable medium of claim 16 , wherein the second resource includes a saturation constraint, and wherein additional requests beyond the saturation constraint are ignored.
24 . A system for serving suspect network requests, the system comprising:
a first network interface arranged to receive a network request that is suspected to be part of an attack on a network, the network request directed to a first resource available on the network; a classifier to intercept the network request in response to the network request being part of the attack and routing the request to a virtual local area network; and a second network interface to service the network request from a second resource available on the virtual local area network.
25 . The system of claim 24 , comprising partitionable hardware resources, wherein to service the network request from the second resource includes the classifier to instantiate a virtual machine on the virtual local area network by the partitionable hardware resources to service the network request.
26 . The system of claim 25 , wherein the virtual machine is instantiated in response to a first network request corresponding to the suspected attack, the network request being one of a plurality of network requests that correspond to the suspected attack.
27 . The system of claim 24 , wherein the network request is one of a plurality of requests that correspond to the suspected network attack, the plurality of requests related via application of an attack detection rule.
28 . The system of claim 27 , wherein the suspected attack begins with the first request of the plurality of requests and persists through a predetermined time period.
29 . The system of claim 28 , comprising an attack analytic processor to perform additional attack analysis during the predetermined time period on requests in the plurality of requests received during the predetermined time period.
30 . The system of claim 29 , wherein the classifier is to deny requests of the plurality of requests when the additional attack analysis indicates that the suspected attack is an actual attack and allowing requests to the first resource otherwise.
31 . The system of claim 24 , wherein the second resource includes a saturation constraint, and wherein additional requests beyond the saturation constraint are ignored.
32 . A method for serving suspect network requests, the method comprising:
receiving a network request that is suspected to be part of an attack on a network, the network request directed to a first resource available on the network; intercepting the network request in response to the network request being part of the attack and routing the request to a virtual local area network; and servicing the network request from a second resource available on the virtual local area network.
33 . The method of claim 32 , wherein servicing the network request from the second resource includes instantiating a virtual machine on the virtual local area network to service the network request.
34 . The method of claim 33 , wherein the virtual machine is instantiated in response to a first network request corresponding to the suspected attack, the network request being one of a plurality of network requests that correspond to the suspected attack.
35 . The method of claim 32 , wherein the network request is one of a plurality of requests that correspond to the suspected network attack, the plurality of requests related via application of an attack detection rule.
36 . The method of claim 35 , wherein the suspected attack begins with the first request of the plurality of requests and persists through a predetermined time period.
37 . The method of claim 36 , comprising performing additional attack analysis during the predetermined time period on requests in the plurality of requests received during the predetermined time period.
38 . The method of claim 37 , comprising denying requests of the plurality of requests when the additional attack analysis indicates that the suspected attack is an actual attack and allowing requests to the first resource otherwise.
39 . The method of claim 32 , wherein the second resource includes a saturation constraint, and wherein additional requests beyond the saturation constraint are ignored.Join the waitlist — get patent alerts
Track US2016021137A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.