US2016330240A1PendingUtilityA1

Blocking via an unsolvable captcha

Assignee: JUNIPER NETWORKS INCPriority: Sep 30, 2013Filed: Jul 21, 2016Published: Nov 10, 2016
Est. expirySep 30, 2033(~7.2 yrs left)· nominal 20-yr term from priority
Inventors:Kyle Adams
G06F 21/554H04L 63/1491G06F 2221/2133H04L 63/1416
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A security device may receive a request from an attacker device and intended for a server device. The security device may identify the request as being associated with a malicious activity. The malicious activity may include one or more undesirable tasks directed to the server device. The security device may generate an unsolvable challenge-response test based on identifying the request as being associated with the malicious activity. The unsolvable challenge-response test may be generated using at least one construction technique and may be configured in an attempt to block the attacker device without making the attacker device aware that the attacker device is being blocked. The security device may provide the unsolvable challenge-response test to the attacker device, and may receive a solution associated with the unsolvable challenge-response test. The security device may notify the attacker device that the solution is incorrect regardless of whether the solution is actually correct.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A system comprising:
 one or more processors to:
 identify an attacker device; 
 select, based on identifying the attacker device, a construction technique associated with displaying an error; 
 generate an unsolvable challenge-response test using the construction technique,
 the unsolvable challenge-response test including information for causing the attacker device to display the error without making the attacker device aware that the attacker device is being blocked; and 
 
 provide the unsolvable challenge-response test to the attacker device. 
   
     
     
         22 . The system of  claim 21 ,
 where the one or more processors are further to:
 obtain information indicating multiple failed attempts to log into a user account from a particular device, and 
   where the one or more processors, when identifying the attacker device, are to:
 identify that the particular device is the attacker device based on the multiple failed attempts from the particular device. 
   
     
     
         23 . The system of  claim 21 ,
 where the one or more processors are further to:
 receive a request from the attacker device; and 
 determine that the request is associated with malicious activity, and 
   where the one or more processors, when identifying the attacker device, are further to:
 identify the attacker device based on determining that the request is associated with malicious activity. 
   
     
     
         24 . The system of  claim 21 , where the unsolvable challenge-response test comprises an unsolvable completely automated public Turing test to tell Computers and Humans Apart (CAPTCHA). 
     
     
         25 . The system of  claim 21 , where the one or more processors are further to:
 provide an initial challenge-response test to the attacker device before providing the unsolvable challenge-response test to the attacker device.   
     
     
         26 . The system of  claim 25 , where one or more processors are further to:
 generate the initial challenge-response test by distorting a character included in the unsolvable challenge-response test.   
     
     
         27 . The system of  claim 25 , where the initial challenge-response test requires the attacker device to submit a solution to the initial challenge-response test without a user of the attacker device being able to view the initial challenge-response test for a time necessary to submit the solution. 
     
     
         28 . A non-transitory computer-readable medium storing instructions, the instructions comprising:
 one or more instructions that, when executed by one or more processors, cause the one or more processors to:
 identify an attacker device; 
 select, based on identifying the attacker device, a construction technique; 
 generate an unsolvable challenge-response test using the construction technique,
 the unsolvable challenge-response test including information for causing the attacker device to prompt a user of the attacker device without making the attacker device aware that the attacker device is being blocked; and 
 
 provide the unsolvable challenge-response test to the attacker device. 
   
     
     
         29 . The non-transitory computer-readable medium of  claim 28 , where the one or more instructions to identify the attacker device comprise:
 one or more instructions that, when executed by the one or more processors, cause the one or more processors to:
 identify the attacker device based on information indicating multiple failed attempts from the attacker device. 
   
     
     
         30 . The non-transitory computer-readable medium of  claim 28 , where the one or more instructions to identify the attacker device comprise:
 one or more instructions that, when executed by the one or more processors, cause the one or more processors to:
 identify the attacker device based on a request, from the attacker device, associated with malicious activity. 
   
     
     
         31 . The non-transitory computer-readable medium of  claim 28 , where a correct solution, to the unsolvable challenge-response test, comprises a character that a user of the attacker device cannot input. 
     
     
         32 . The non-transitory computer-readable medium of  claim 28 ,
 where the unsolvable challenge-response test comprises an unsolvable completely automated public Turing test to tell Computers and Humans Apart (CAPTCHA), and   where the unsolvable CAPTCHA comprises a character that appears similar to another character.   
     
     
         33 . The non-transitory computer-readable medium of  claim 28 ,
 where the unsolvable challenge-response test comprises an unsolvable completely automated public Turing test to tell Computers and Humans Apart (CAPTCHA),   where the unsolvable CAPTCHA comprises a first quantity of characters to be displayed, and   where the unsolvable CAPTCHA requires a solution that includes a second quantity of characters that is different from the first quantity of characters.   
     
     
         34 . The non-transitory computer-readable medium of  claim 28 , where the unsolvable challenge-response test includes an error, to be displayed by the attacker device, that indicates that the attacker device is unable to display an image. 
     
     
         35 . A method comprising:
 identifying, by a device, an attacker device;   generating, by the device, a unsolvable challenge-response test for the attacker device,
 the unsolvable challenge-response test including information for causing the attacker device to display a user interface without making the attacker device aware that the attacker device is being blocked; and 
   providing, by the device, the unsolvable challenge-response test to the attacker device.   
     
     
         36 . The method of  claim 35 , further comprising:
 selecting, based on identifying the attacker device, a construction technique associated with displaying an error,
 where generating the unsolvable challenge-response test comprises:
 generating the unsolvable challenge-response test using the construction technique. 
 
   
     
     
         37 . The method of  claim 36 ,
 where the user interface includes the error, and   where the error indicates that the attacker device is unable to display an image.   
     
     
         38 . The method of  claim 35 , where the user interface includes an input field that does not allow the attacker device to input a solution into the input field. 
     
     
         39 . The method of  claim 35 , where the user interface includes information indicating that the unsolvable challenge-response test could not be generated. 
     
     
         40 . The method of  claim 35 , further comprising:
 notifying the attacker device that a first solution to the unsolvable challenge-response test is incorrect; and   permitting the attacker device to provide a second solution to the unsolvable challenge-response test.

Join the waitlist — get patent alerts

Track US2016330240A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.