US2016234230A1PendingUtilityA1

System and method for preventing dos attacks utilizing invalid transaction statistics

Assignee: F5 NETWORKS INCPriority: Sep 27, 2012Filed: Oct 5, 2015Published: Aug 11, 2016
Est. expirySep 27, 2032(~6.2 yrs left)· nominal 20-yr term from priority
H04L 43/0852H04L 67/42H04L 63/1458H04L 63/1416H04L 67/01H04L 2463/141H04L 2463/142H04L 43/16
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and network traffic management device to protect a network from network based attacks is disclosed. The method comprises receiving, at a network traffic management device, a plurality of requests from a plurality of client devices for one or more resources from one or more servers. The method comprises monitoring a number of server responses including an invalid transaction message for a particular client device or a particular requested resource. The method comprises comparing a ratio of invalid transactions to valid transactions for the particular client device or requested resource to a preestablished ratio threshold value. The method comprises marking the particular client device or requested resource as suspicious when the ratio exceeds the ratio threshold value. The method comprises preventing the suspicious particular client device or requested resource from being transmitted to the one or more servers when the network traffic management device detects a network attack.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for protecting a network from network based attacks, the method comprising:
 receiving, by a network traffic management device, a plurality of requests from a plurality of client devices for one or more resources from one or more servers;   monitoring, by the network traffic management device, response codes in a number of server responses for at least one of the client devices or at least one of the requested resources;   comparing, by the network traffic management device, a ratio of invalid ones of the server responses to valid ones of the server responses for the client device or requested resource to a preestablished ratio threshold value, wherein the invalid ones of the server responses each comprise an invalid one of the response codes;   marking, by the network traffic management device, the client device or requested resource as suspicious when the ratio exceeds the ratio threshold value and without restricting any network traffic when not in a prevention mode; and   preventing, by the network traffic management device, the suspicious client device from transmitting at least one additional request to one or more of the servers, or the suspicious requested resource from being transmitted to one or more of the client devices, when in the prevention mode.   
     
     
         2 . The method of  claim 1 , further comprising entering, by the network traffic management device, into the prevention mode upon detecting a network attack. 
     
     
         3 . The method of  claim 2 , further comprising:
 monitoring, by the network traffic management device, an average transactions per second value or an average latency value over a short set period of time; and   determining, by the network traffic management device, that the network attack has ended based on the monitoring; and   returning, by the network traffic management device, to a detection mode when the determining indicates that the network attack has ended.   
     
     
         4 . The method of  claim 1 , further comprising:
 monitoring, by the network traffic management device, current transactions per second for one or more established connections with one or more of the client devices and generating a current average transactions per second value based on the monitoring;   comparing, by the network traffic management device, the current average transactions per second value to an average transactions per second value over a short set period of time or an average transactions per second value over a long set period of time; and   entering, by the network traffic management device, the prevention mode when the current average transactions per second value exceeds the average transactions per second value for the short set period of time of the average transactions per second value for the long set period of time.   
     
     
         5 . The method of  claim 1 , further comprising:
 monitoring, by the network traffic management device, current latency values for one or more established connections with one of more of the client devices and generating a current average latency value based on the monitoring;   comparing, by the network traffic management device, the current average latency value to an average latency value over a short set period of time or an average latency value over a long set period of time; and   entering, by the network traffic management device, the prevention mode when the current average latency value exceeds the average latency value for the short set period of time or the average latency value for the long set period of time.   
     
     
         6 . A non-transitory computer-readable medium having stored thereon executable instructions for protecting a network from network based attacks, which when executed by at least one processor, cause the processor to perform steps comprising:
 receiving a plurality of requests from a plurality of client devices for one or more resources from one or more servers;   monitoring response codes in a number of server responses for at least one of the client devices or at least one of the requested resources;   comparing a ratio of invalid ones of the server responses to valid ones of the server responses for the client device or requested resource to a preestablished ratio threshold value, wherein the invalid ones of the server responses each comprise an invalid one of the response codes;   marking the client device or requested resource as suspicious when the ratio exceeds the ratio threshold value without restricting any network traffic when not in a prevention mode; and   preventing the suspicious client device from transmitting at least one additional request to one or more of the servers, or the suspicious requested resource from being transmitted to one or more of the client devices, when in the prevention mode.   
     
     
         7 . The non-transitory computer-readable medium of  claim 6 , further having stored thereon executable instructions which when executed by the processor further cause the processor to perform at least one additional step comprising entering into the prevention mode upon detecting a network attack. 
     
     
         8 . The non-transitory computer-readable medium of  claim 7 , further having stored thereon executable instructions which when executed by the processor further cause the processor to perform at least one additional step comprising:
 monitoring an average transactions per second value or an average latency value over a short set period of time; and   determining that the network attack has ended based on the monitoring; and   returning to a detection mode when the determining indicates that the network attack has ended.   
     
     
         9 . The non-transitory computer-readable medium of  claim 6 , further having stored thereon executable instructions which when executed by the processor further cause the processor to perform at least one additional step comprising:
 monitoring current transactions per second for one or more established connections with one or more of the client devices and generating a current average transactions per second value based on the monitoring;   comparing the current average transactions per second value to an average transactions per second value over a short set period of time or an average transactions per second value over a long set period of time; and   entering the prevention mode when the current average transactions per second value exceeds the average transactions per second value for the short set period of time of the average transactions per second value for the long set period of time.   
     
     
         10 . The non-transitory computer-readable medium of  claim 6 , further having stored thereon executable instructions which when executed by the processor further cause the processor to perform at least one additional step comprising:
 monitoring current latency values for one or more established connections with one of more of the client devices and generating a current average latency value based on the monitoring;   comparing the current average latency value to an average latency value over a short set period of time or an average latency value over a long set period of time; and   entering the prevention mode when the current average latency value exceeds the average latency value for the short set period of time or the average latency value for the long set period of time.   
     
     
         11 . A network traffic management device comprising at least one processor and a memory coupled to the processor which is configured to be capable of executing programmed instructions comprising and stored in the memory to:
 receive a plurality of requests from a plurality of client devices for one or more resources from one or more servers;   monitor response codes in a number of server responses for at least one of the client devices or at least one of the requested resources;   compare a ratio of invalid ones of the server responses to valid ones of the server responses for the client device or requested resource to a preestablished ratio threshold value, wherein the invalid ones of the server responses each comprise an invalid one of the response codes;   mark the client device or requested resource as suspicious when the ratio exceeds the ratio threshold value without restricting any network traffic when not in a prevention mode; and   prevent the suspicious client device from transmitting at least one additional request to one or more of the servers, or the suspicious requested resource from being transmitted to one or more of the client devices, when in the prevention mode.   
     
     
         12 . The network traffic management device of  claim 11 , wherein the processor coupled to the memory is further configured to be capable of executing at least one additional programmed instruction to enter into the prevention mode upon detecting a network attack. 
     
     
         13 . The network traffic management device of  claim 12 , wherein the processor coupled to the memory is further configured to be capable of executing at least one additional programmed instruction to:
 monitor an average transactions per second value or an average latency value over a short set period of time; and   determine that the network attack has ended based on the monitoring; and   return to a detection mode when the determining indicates that the network attack has ended.   
     
     
         14 . The network traffic management device of  claim 11 , wherein the processor coupled to the memory is further configured to be capable of executing at least one additional programmed instruction to:
 monitor current transactions per second for one or more established connections with one or more of the client devices and generating a current average transactions per second value based on the monitoring;   compare the current average transactions per second value to an average transactions per second value over a short set period of time or an average transactions per second value over a long set period of time; and   enter the prevention mode when the current average transactions per second value exceeds the average transactions per second value for the short set period of time of the average transactions per second value for the long set period of time.   
     
     
         15 . The network traffic management device of  claim 11 , wherein the processor coupled to the memory is further configured to be capable of executing at least one additional programmed instruction to:
 monitor current latency values for one or more established connections with one of more of the client devices and generating a current average latency value based on the monitoring;   compare the current average latency value to an average latency value over a short set period of time or an average latency value over a long set period of time; and   enter the prevention mode when the current average latency value exceeds the average latency value for the short set period of time or the average latency value for the long set period of time.

Join the waitlist — get patent alerts

Track US2016234230A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.