Early detection of dedicated denial of service attacks through metrics correlation
Abstract
A monitoring service obtains request data specifying entries corresponding to requests received by a Domain Name System service to obtain an Internet Protocol address for a resource and to requests received by a web service to access the resource. The monitoring service uses that request data to generate a request frequency value corresponding to the received requests and compares this value to a baseline request frequency value. If the request frequency value exceeds the baseline request frequency value by a maximum threshold value, the monitoring service performs an operation to redirect network traffic originally directed towards the web service.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method, comprising:
receiving first request data, the first request data specifying requests received by a Domain Name System service over a first period of time and requests received by a web service for providing a resource over the first period of time; determining, based at least in part on the first request data, a baseline ratio of the requests received by the web service to the requests received by the Domain Name System service; receiving second request data, the second request data specifying at least second requests received by the Domain Name System service over a second period of time having a duration of the first period of time and second requests received by the web service for providing the resource over the second period of time; determining, based at least in part on the second request data, a ratio of the second requests received by the web service relative to the second requests received by the Domain Name System service; determining, based at least in part on the ratio relative to the baseline, that the ratio is indicative of a Distributed Denial of Service attack; and redirecting network traffic directed towards the web service to another service.
2 . The computer-implemented method of claim 1 , further comprising:
identifying, based at least in part on the first request data and the second request data, an Internet Protocol address corresponding to an entity that causes the ratio to be indicative of the Distributed Denial of Service attack; and providing the Internet Protocol address corresponding to the entity to the other service to cause the other service to block network traffic originating from the Internet Protocol address corresponding to the entity.
3 . The computer-implemented method of claim 1 , wherein redirecting the network traffic directed towards the web service to the other service includes transmitting a request to the Domain Name System service to associate a domain name of the web service with an Internet Protocol of the other service.
4 . The computer-implemented method of claim 1 , further comprising transmitting a notification to indicate detection of the Dedicated Denial of Service attack directed towards the web service.
5 . A system, comprising at least one computing device configured to implement one or more services, wherein the one or more services:
obtaining request data generated as a result of requests received by a service that resolves an identifier to a set of network addresses for a resource over a period of time and requests received by a web service for providing the resource over the period of time; determine, based at least in part on the request data, a value corresponding to the request data; determine that the value satisfies a set of conditions; and perform an operation to cause a change in how future requests are processed.
6 . The system of claim 5 , wherein the one or more services further:
identify, based at least in part on the request data, requests generated by trusted entities; and remove, from the request data, the requests generated by the trusted entities such that the value corresponding to the request data is determined without the requests generated by the trusted entities.
7 . The system of claim 6 , wherein identifying the requests generated by the trusted entities includes:
determining Internet Protocol addresses corresponding to the trusted entities; and identifying, from the request data, entries having any of the Internet Protocol addresses corresponding to the trusted entities.
8 . The system of claim 6 , wherein identifying the requests generated by the trusted entities includes:
identifying, from the request data, entries specifying a shared secret provided to trusted entities; and verifying that the shared secret is valid.
9 . The system of claim 5 , wherein the operation includes transmitting a request to the service that resolves the identifier to the set of network addresses for the resource to associate the identifier of the resource with an Internet Protocol address of a Content Delivery Network service that is usable to mitigate a Denial of Service attack to cause the network traffic to be redirected to the Content Delivery Network service.
10 . The system of claim 5 , wherein the operation includes transmitting, to a proxy server of the web service, Internet Protocol addresses of entities identified as being responsible for submitting requests resulting in the value satisfying the set of conditions to cause the proxy server to block network traffic originating from the Internet Protocol addresses of the entities.
11 . The system of claim 5 , wherein the operation includes transmitting a notification specifying that a Denial of Service attack has been detected.
12 . The system of claim 5 , wherein the value corresponding to the request data is a ratio calculated by dividing a number of requests processed by the web service specified in the request data over the period of time by a number of requests processed by the service that resolves the identifier to the set of network addresses for the resource over the period of time.
13 . A non-transitory computer-readable storage medium having stored thereon executable instructions that, as a result of being executed by one or more processors of a computer system, cause the computer system to at least:
obtain request data comprising entries specifying requests received over a period of time by a service that resolves an identifier to a set of network addresses for a resource and requests received over the period of time by the web service for providing the resource; determine, based at least in part on request data and baseline request data, that a set of conditions have been satisfied; and perform an operation to cause a change in how future requests are processed.
14 . The non-transitory computer-readable storage medium of claim 13 , wherein the operation includes transmitting a request to the service that resolves the identifier to redirect network traffic directed at the resource to another service that can promulgate the change.
15 . The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further cause the computer system to:
determine a request frequency ratio of the requests received by the web service for providing the resource to the requests received by the service that resolves the identifier; and compare the request frequency ratio to the baseline request data to determine that the set of conditions have been satisfied.
16 . The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further cause the computer system to:
identify, based at least in part on the request data, requests generated by trusted entities; and disregard requests generated by the trusted entities such that whether the set of conditions is satisfied is determined without using the requests generated by the trusted entities.
17 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions that cause the computer cause the computer system to identify the requests generated by the trusted entities further cause the computer system to:
identify Internet Protocol addresses corresponding to the trusted entities; and identify entries in the request data that specify at least one of the Internet Protocol addresses corresponding to the trusted entities.
18 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions that cause the computer cause the computer system to identify the requests generated by the trusted entities further cause the computer system to:
identify, from the request data, entries specifying a cryptographic hash generated using a cryptographic key and a shared secret provided to trusted entities; generate a second cryptographic hash based at least in part on the cryptographic key and the shared secret; and determine that the shared secret is valid as a result of the cryptographic hash being identical to the second cryptographic hash.
19 . The non-transitory computer-readable storage medium of claim 13 , wherein the operation includes transmitting a notification to the web service to indicate that the set of conditions have been satisfied.
20 . The non-transitory computer-readable storage medium of claim 13 , wherein the operation includes:
identifying Internet Protocol addresses of entities that caused the set of conditions to be satisfied; and blocking network traffic from the Internet Protocol addresses of the entities that caused the set of conditions to be satisfied.Join the waitlist — get patent alerts
Track US2021144172A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.