US2021144172A1PendingUtilityA1

Early detection of dedicated denial of service attacks through metrics correlation

Assignee: AMAZON TECH INCPriority: Mar 20, 2017Filed: Dec 15, 2020Published: May 13, 2021
Est. expiryMar 20, 2037(~10.6 yrs left)· nominal 20-yr term from priority
Inventors:Muhammad Wasiq
H04L 67/1097H04L 67/02H04L 63/1458H04L 9/0861H04L 9/40H04L 67/01H04L 61/4511H04L 67/60H04L 67/563H04L 61/5007H04L 67/51H04L 63/1425H04L 63/06H04L 2463/142H04L 63/126H04L 2463/141H04L 9/3236H04L 63/10H04L 63/08H04L 63/0281H04L 67/42H04L 67/32H04L 29/06H04L 61/1511H04L 67/16H04L 61/2007
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A monitoring service obtains request data specifying entries corresponding to requests received by a Domain Name System service to obtain an Internet Protocol address for a resource and to requests received by a web service to access the resource. The monitoring service uses that request data to generate a request frequency value corresponding to the received requests and compares this value to a baseline request frequency value. If the request frequency value exceeds the baseline request frequency value by a maximum threshold value, the monitoring service performs an operation to redirect network traffic originally directed towards the web service.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method, comprising:
 receiving first request data, the first request data specifying requests received by a Domain Name System service over a first period of time and requests received by a web service for providing a resource over the first period of time;   determining, based at least in part on the first request data, a baseline ratio of the requests received by the web service to the requests received by the Domain Name System service;   receiving second request data, the second request data specifying at least second requests received by the Domain Name System service over a second period of time having a duration of the first period of time and second requests received by the web service for providing the resource over the second period of time;   determining, based at least in part on the second request data, a ratio of the second requests received by the web service relative to the second requests received by the Domain Name System service;   determining, based at least in part on the ratio relative to the baseline, that the ratio is indicative of a Distributed Denial of Service attack; and   redirecting network traffic directed towards the web service to another service.   
     
     
         2 . The computer-implemented method of  claim 1 , further comprising:
 identifying, based at least in part on the first request data and the second request data, an Internet Protocol address corresponding to an entity that causes the ratio to be indicative of the Distributed Denial of Service attack; and   providing the Internet Protocol address corresponding to the entity to the other service to cause the other service to block network traffic originating from the Internet Protocol address corresponding to the entity.   
     
     
         3 . The computer-implemented method of  claim 1 , wherein redirecting the network traffic directed towards the web service to the other service includes transmitting a request to the Domain Name System service to associate a domain name of the web service with an Internet Protocol of the other service. 
     
     
         4 . The computer-implemented method of  claim 1 , further comprising transmitting a notification to indicate detection of the Dedicated Denial of Service attack directed towards the web service. 
     
     
         5 . A system, comprising at least one computing device configured to implement one or more services, wherein the one or more services:
 obtaining request data generated as a result of requests received by a service that resolves an identifier to a set of network addresses for a resource over a period of time and requests received by a web service for providing the resource over the period of time;   determine, based at least in part on the request data, a value corresponding to the request data;   determine that the value satisfies a set of conditions; and   perform an operation to cause a change in how future requests are processed.   
     
     
         6 . The system of  claim 5 , wherein the one or more services further:
 identify, based at least in part on the request data, requests generated by trusted entities; and   remove, from the request data, the requests generated by the trusted entities such that the value corresponding to the request data is determined without the requests generated by the trusted entities.   
     
     
         7 . The system of  claim 6 , wherein identifying the requests generated by the trusted entities includes:
 determining Internet Protocol addresses corresponding to the trusted entities; and   identifying, from the request data, entries having any of the Internet Protocol addresses corresponding to the trusted entities.   
     
     
         8 . The system of  claim 6 , wherein identifying the requests generated by the trusted entities includes:
 identifying, from the request data, entries specifying a shared secret provided to trusted entities; and   verifying that the shared secret is valid.   
     
     
         9 . The system of  claim 5 , wherein the operation includes transmitting a request to the service that resolves the identifier to the set of network addresses for the resource to associate the identifier of the resource with an Internet Protocol address of a Content Delivery Network service that is usable to mitigate a Denial of Service attack to cause the network traffic to be redirected to the Content Delivery Network service. 
     
     
         10 . The system of  claim 5 , wherein the operation includes transmitting, to a proxy server of the web service, Internet Protocol addresses of entities identified as being responsible for submitting requests resulting in the value satisfying the set of conditions to cause the proxy server to block network traffic originating from the Internet Protocol addresses of the entities. 
     
     
         11 . The system of  claim 5 , wherein the operation includes transmitting a notification specifying that a Denial of Service attack has been detected. 
     
     
         12 . The system of  claim 5 , wherein the value corresponding to the request data is a ratio calculated by dividing a number of requests processed by the web service specified in the request data over the period of time by a number of requests processed by the service that resolves the identifier to the set of network addresses for the resource over the period of time. 
     
     
         13 . A non-transitory computer-readable storage medium having stored thereon executable instructions that, as a result of being executed by one or more processors of a computer system, cause the computer system to at least:
 obtain request data comprising entries specifying requests received over a period of time by a service that resolves an identifier to a set of network addresses for a resource and requests received over the period of time by the web service for providing the resource;   determine, based at least in part on request data and baseline request data, that a set of conditions have been satisfied; and   perform an operation to cause a change in how future requests are processed.   
     
     
         14 . The non-transitory computer-readable storage medium of  claim 13 , wherein the operation includes transmitting a request to the service that resolves the identifier to redirect network traffic directed at the resource to another service that can promulgate the change. 
     
     
         15 . The non-transitory computer-readable storage medium of  claim 13 , wherein the instructions further cause the computer system to:
 determine a request frequency ratio of the requests received by the web service for providing the resource to the requests received by the service that resolves the identifier; and   compare the request frequency ratio to the baseline request data to determine that the set of conditions have been satisfied.   
     
     
         16 . The non-transitory computer-readable storage medium of  claim 13 , wherein the instructions further cause the computer system to:
 identify, based at least in part on the request data, requests generated by trusted entities; and   disregard requests generated by the trusted entities such that whether the set of conditions is satisfied is determined without using the requests generated by the trusted entities.   
     
     
         17 . The non-transitory computer-readable storage medium of  claim 16 , wherein the instructions that cause the computer cause the computer system to identify the requests generated by the trusted entities further cause the computer system to:
 identify Internet Protocol addresses corresponding to the trusted entities; and   identify entries in the request data that specify at least one of the Internet Protocol addresses corresponding to the trusted entities.   
     
     
         18 . The non-transitory computer-readable storage medium of  claim 16 , wherein the instructions that cause the computer cause the computer system to identify the requests generated by the trusted entities further cause the computer system to:
 identify, from the request data, entries specifying a cryptographic hash generated using a cryptographic key and a shared secret provided to trusted entities;   generate a second cryptographic hash based at least in part on the cryptographic key and the shared secret; and   determine that the shared secret is valid as a result of the cryptographic hash being identical to the second cryptographic hash.   
     
     
         19 . The non-transitory computer-readable storage medium of  claim 13 , wherein the operation includes transmitting a notification to the web service to indicate that the set of conditions have been satisfied. 
     
     
         20 . The non-transitory computer-readable storage medium of  claim 13 , wherein the operation includes:
 identifying Internet Protocol addresses of entities that caused the set of conditions to be satisfied; and   blocking network traffic from the Internet Protocol addresses of the entities that caused the set of conditions to be satisfied.

Join the waitlist — get patent alerts

Track US2021144172A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.