US2022076209A1PendingUtilityA1
Process for Abuse Mitigation
Est. expiryNov 16, 2026(~0.3 yrs left)· nominal 20-yr term from priority
H04L 51/212H04L 51/48H04L 2463/141H04L 63/1458G06Q 10/107H04L 2463/144H04L 51/28H04L 51/12
51
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Method of limiting offending messages communicated over a network, such as but not limited to messages associated with Spam and DoS attacks. The message limiting optionally including limiting bandwidth or other communication capabilities associated with an entity communicating or facilitating communication of the messages.
Claims
exact text as granted — not AI-modified1 . A method comprising:
receiving, by one or more first computing devices and from a second computing device, a first message addressed to a destination device; and based on determining that the first message is malicious:
preventing sending of the first message to the destination device; and
sending, to the second computing device, a second message comprising an invalid network address and configured to prevent the second computing device from sending one or more additional messages.
2 . The method of claim 1 , wherein determining that the first message is malicious comprises one or more of:
monitoring messages received from the second computing device; analyzing content of the first message; determining that a quantity messages received from the second computing device satisfies a maximum threshold quantity of messages; or determining that the first message has been sent via a port of the second computing device, wherein messages, previously sent by the second computing device via the port of the second computing device, indicate malicious messaging by the second computing device.
3 . The method of claim 1 , wherein the second computing device is associated with a first network, and
wherein preventing sending of the first message to the destination device comprises preventing sending of the first message to a destination device associated with a second network different than the first network.
4 . The method of claim 1 , wherein determining that the first message is malicious comprises:
determining that messages, of at least one message type and sent by the second computing device, indicate malicious messaging by the second computing device; and determining, based on the first message being of that at least one message type, that the first message is malicious.
5 . The method of claim 1 , wherein the first message is of at least one message type, and
wherein the second message is configured to prevent the second computing device from sending additional messages of the at least one message type.
6 . The method of claim 1 , wherein the second message comprises an acknowledgement that provides a false indication of a successful receipt of the first message by the destination device.
7 . The method of claim 1 , further comprising:
determining that the second computing device sent the first message via a port of the second computing device; and sending additional messages, received via the port of the second computing device, to a sink-hole device.
8 . The method of claim 1 , wherein the second message is configured to limit a quantity of subsequent messages that will be sent by the second computing device.
9 . A first computing device comprising:
one or more processors; and memory storing instructions that, when executed by the one or more processors, cause the first computing device to:
receive, from a second computing device, a first message addressed to a destination device; and
based on determining that the first message is malicious:
prevent sending of the first message to the destination device; and
send, to the second computing device, a second message comprising an invalid network address and configured to prevent the second computing device from sending one or more additional messages.
10 . The first computing device of claim 9 , wherein the instructions, when executed by the one or more processors, cause the first computing device to determine that the first message is malicious by causing one or more of:
monitoring messages received from the second computing device; analyzing content of the first message; determining that a quantity messages received from the second computing device satisfies a maximum threshold quantity of messages; or determining that the first message has been sent via a port of the second computing device, wherein messages, previously sent by the second computing device via the port of the second computing device, indicate malicious messaging by the second computing device.
11 . The first computing device of claim 9 , wherein the second computing device is associated with a first network, and
wherein the instructions, when executed by the one or more processors, cause the first computing device to prevent the sending of the first message to the destination device by preventing sending of the first message to a destination device associated with a second network different than the first network.
12 . The first computing device of claim 9 , wherein the instructions, when executed by the one or more processors, cause the first computing device to determine that the first message is malicious by causing the first computing device to:
determine that messages, of at least one message type and sent by the second computing device, indicate malicious messaging by the second computing device; and determine based on the first message being of that at least one message type, that the first message is malicious.
13 . The first computing device of claim 9 , wherein the first message is of at least one message type, and
wherein the second message is configured to prevent the second computing device from sending additional messages of the at least one message type.
14 . The first computing device of claim 9 , wherein the second message comprises an acknowledgement that provides a false indication of a successful receipt of the first message by the destination device.
15 . The first computing device of claim 9 , wherein the instructions, when executed by the one or more processors, further cause the first computing device to:
determine that the second computing device sent the first message via a port of the second computing device; and send additional messages, received via the port of the second computing device, to a sink-hole device.
16 . The first computing device of claim 9 , wherein the second message is configured to limit a quantity of subsequent messages that will be sent by the second computing device.
17 . A non-transitory computer readable medium storing instructions that, when executed, cause:
receiving, from a computing device, a first message addressed to a destination device; and based on determining that the first message is malicious:
preventing sending of the first message to the destination device; and
sending, to the computing device, a second message comprising an invalid network address and configured to prevent the computing device from sending one or more additional messages.
18 . The non-transitory computer readable medium of claim 17 , wherein the instructions, when executed, cause determining that the first message is malicious by causing one or more of:
monitoring messages received from the computing device; analyzing content of the first message; determining that a quantity messages received from the computing device satisfies a maximum threshold quantity of messages; or determining that the first message has been sent via a port of the computing device, wherein messages, previously sent by the computing device via the port of the computing device, indicate malicious messaging by the computing device.
19 . The non-transitory computer readable medium of claim 17 , wherein the computing device is associated with a first network, and
wherein the instructions, when executed, cause preventing sending of the first message to the destination device by causing preventing sending of the first message to a destination device associated with a second network different than the first network.
20 . The non-transitory computer readable medium of claim 17 , wherein the instructions, when executed, cause determining that the first message is malicious by causing:
determining that messages, of at least one message type and sent by the computing device, indicate malicious messaging by the computing device; and determining, based on the first message being of that at least one message type, that the first message is malicious.
21 . The non-transitory computer readable medium of claim 17 , wherein the first message is of at least one message type, and
wherein the second message is configured to prevent the computing device from sending additional messages of the at least one message type.
22 . The non-transitory computer readable medium of claim 17 , wherein the second message comprises an acknowledgement that provides a false indication of a successful receipt of the first message by the destination device.
23 . The non-transitory computer readable medium of claim 17 , wherein the instructions, when executed, further cause:
determining that the computing device sent the first message via a port of the computing device; and sending additional messages, received via the port of the computing device, to a sink-hole device.
24 . The non-transitory computer readable medium of claim 17 , wherein the second message is configured to limit a quantity of subsequent messages that will be sent by the computing device.Join the waitlist — get patent alerts
Track US2022076209A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.