Techniques for targeted botnet protection
Abstract
A botnet identification module identifies members of one or more botnets based upon network traffic destined to one or more servers over time, and provides sets of botnet sources to a traffic monitoring module. Each set of botnet sources includes a plurality of source identifiers of end stations acting as part of a corresponding botnet. A traffic monitoring module receives the sets of botnet sources from the botnet identification module, and upon a receipt of traffic identified as malicious that was sent by a source identified within one of the sets of botnet sources, activates a protection mechanism with regard to all traffic from all of the sources identified by the one of the sets of botnet sources for an amount of time.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method in a traffic monitoring module (TMM) that is implemented by an electronic device and that is for providing targeted botnet protection for one or more servers, wherein the TMM is deployed in front of the one or more servers in that the TMM receives network traffic sent by a plurality of end stations that is destined for the one or more servers, the method comprising:
receiving, at the TMM, a message including a first plurality of identifiers that have been determined by a botnet identification module to be used by a subset of the plurality of end stations collectively acting as a first suspected botnet; receiving, at the TMM from a first of the plurality of end stations, a first request message that is destined for one of the one or more servers and that includes at least a first identifier of the first plurality of identifiers; allowing the first request message to be sent to its destination despite the first identifier existing within the first plurality of identifiers; receiving, at the TMM from a second of the plurality of end stations, a second request message that is destined for one of the one or more servers and that includes at least a second identifier that exists within the first plurality of identifiers; blocking, at the TMM, the second request message from being sent to its destination responsive to a determination that the second request message is malicious; and responsive to the determination that the second request message is malicious and a different determination that the second identifier included in the second request message exists within the first plurality of identifiers, activating, by the TMM for an amount of time, a protection mechanism that applies to all traffic that has any of the first plurality of identifiers including the first identifier and the second identifier, wherein the first identifier and the second identifier are IP addresses having different subnets.
2 . The method of claim 1 , wherein the first request message includes one or more of the first plurality of identifiers in at least a set of one or more locations in the first request message, and wherein the set of one or more locations includes one or more of:
a source Internet Protocol (IP) address header field; a User-Agent header field; and an X-Forwarded-For header field.
3 . The method of claim 1 , wherein the protection mechanism that applies to all traffic that has any of the first plurality of identifiers comprises dropping all traffic that has any of the first plurality of identifiers regardless of whether it is separately determined to be malicious.
4 . The method of claim 3 , further comprising:
receiving, at the TMM from the first of the plurality of end stations, a third request message that is destined for one of the one or more servers; and allowing the third request message to be sent to its destination despite the third request message including at least one of the first plurality of identifiers due to the protection mechanism no longer being activated for the first suspected botnet.
5 . The method of claim 1 , wherein the protection mechanism that applies to all traffic that has any of the first plurality of identifiers comprises increasing an amount of security analysis performed on the traffic that has any of the first plurality of identifiers.
6 . The method of claim 1 , wherein the amount of time is specific to the first suspected botnet.
7 . The method of claim 6 , wherein the amount of time is based upon an average or maximum attack length of time determined based upon previous activity of the first suspected botnet.
8 . The method of claim 1 , wherein the amount of time is indefinite in that it continues until a condition is satisfied.
9 . The method of claim 8 , wherein the condition is satisfied upon a determination, by the TMM, that no request messages have been received at the TMM that include any of the first plurality of identifiers for a threshold amount of time.
10 . The method of claim 1 , further comprising:
receiving, at the TMM from a third of the plurality of end stations, a third request message that is destined for one of the one or more servers and that includes at least one of the first plurality of identifiers; and blocking, at the TMM as part of the protection mechanism before an end of the amount of time, the third request message from being sent to its destination due to the protection mechanism being activated.
11 . The method of claim 1 , wherein:
the received message that includes the first plurality of identifiers further includes a second plurality of identifiers that have been determined to be used by a subset of the plurality of end stations collectively acting as a second suspected botnet; the second identifier exists within both the first plurality of identifiers and the second plurality of identifiers; and the activated protection mechanism further applies to all traffic that has any of the second plurality of identifiers due to the second identifier also existing within the second plurality of identifiers.
12 . A non-transitory computer readable storage medium having instructions which, when executed by one or more processors of an electronic device, causes the electronic device to implement a traffic monitoring module (TMM) that is to perform operations for providing targeted botnet protection for one or more servers, wherein the TMM is to be deployed in front of the one or more servers in that the TMM receives network traffic sent by a plurality of end stations that is destined for the one or more servers, the operations comprising:
receiving, at the TMM, a message including a first plurality of identifiers that have been determined by a botnet identification module to be used by a subset of the plurality of end stations collectively acting as a first suspected botnet; receiving, at the TMM from a first of the plurality of end stations, a first request message that is destined for one of the one or more servers and that includes at least a first identifier of the first plurality of identifiers; allowing the first request message to be sent to its destination despite the first identifier existing within the first plurality of identifiers; receiving, at the TMM from a second of the plurality of end stations, a second request message that is destined for one of the one or more servers and that includes at least a second identifier that exists within the first plurality of identifiers; blocking, at the TMM, the second request message from being sent to its destination responsive to a determination that the second request message is malicious; and responsive to the determination that the second request message is malicious and a different determination that the second identifier included in the second request message exists within the first plurality of identifiers, activating, by the TMM for an amount of time, a protection mechanism that applies to all traffic that has any of the first plurality of identifiers including the first identifier and the second identifier, wherein the first identifier and the second identifier are IP addresses having different subnets.
13 . The non-transitory computer readable storage medium of claim 12 , wherein the first request message includes one or more of the first plurality of identifiers in at least a set of one or more locations in the first request message, and wherein the set of one or more locations includes one or more of:
a source Internet Protocol (IP) address header field; a User-Agent header field; and an X-Forwarded-For header field.
14 . The non-transitory computer readable storage medium of claim 12 , wherein the protection mechanism that applies to all traffic that has any of the first plurality of identifiers comprises dropping all traffic that has any of the first plurality of identifiers regardless of whether it is separately determined to be malicious.
15 . The non-transitory computer readable storage medium of claim 14 , wherein the operations further comprise:
receiving, at the TMM from the first of the plurality of end stations, a third request message that is destined for one of the one or more servers; and allowing the third request message to be sent to its destination despite the third request message including at least one of the first plurality of identifiers due to the protection mechanism no longer being activated for the first suspected botnet.
16 . The non-transitory computer readable storage medium of claim 12 , wherein the protection mechanism that applies to all traffic that has any of the first plurality of identifiers comprises increasing an amount of security analysis performed on the traffic that has any of the first plurality of identifiers.
17 . The non-transitory computer readable storage medium of claim 12 , wherein the amount of time is specific to the first suspected botnet, wherein the amount of time is based upon an average or maximum attack length of time determined based upon previous activity of the first suspected botnet.
18 . The non-transitory computer readable storage medium of claim 12 , wherein the amount of time is indefinite in that it continues until a condition is satisfied, wherein the condition is satisfied upon a determination, by the TMM, that no request messages have been received at the TMM that include any of the first plurality of identifiers for a threshold amount of time.
19 . The non-transitory computer readable storage medium of claim 12 , wherein the operations further comprise:
receiving, at the TMM from a third of the plurality of end stations, a third request message that is destined for one of the one or more servers and that includes at least one of the first plurality of identifiers; and blocking, at the TMM as part of the protection mechanism before an end of the amount of time, the third request message from being sent to its destination due to the protection mechanism being activated.
20 . The non-transitory computer readable storage medium of claim 12 , wherein:
the received message that includes the first plurality of identifiers further includes a second plurality of identifiers that have been determined to be used by a subset of the plurality of end stations collectively acting as a second suspected botnet; the second identifier exists within both the first plurality of identifiers and the second plurality of identifiers; and the activated protection mechanism further applies to all traffic that has any of the second plurality of identifiers due to the second identifier also existing within the second plurality of identifiers.Join the waitlist — get patent alerts
Track US2021092142A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.