US2022076209A1PendingUtilityA1

Process for Abuse Mitigation

Assignee: COMCAST CABLE COMM LLCPriority: Nov 16, 2006Filed: Aug 16, 2021Published: Mar 10, 2022
Est. expiryNov 16, 2026(~0.3 yrs left)· nominal 20-yr term from priority
H04L 51/212H04L 51/48H04L 2463/141H04L 63/1458G06Q 10/107H04L 2463/144H04L 51/28H04L 51/12
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Method of limiting offending messages communicated over a network, such as but not limited to messages associated with Spam and DoS attacks. The message limiting optionally including limiting bandwidth or other communication capabilities associated with an entity communicating or facilitating communication of the messages.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving, by one or more first computing devices and from a second computing device, a first message addressed to a destination device; and   based on determining that the first message is malicious:
 preventing sending of the first message to the destination device; and 
 sending, to the second computing device, a second message comprising an invalid network address and configured to prevent the second computing device from sending one or more additional messages. 
   
     
     
         2 . The method of  claim 1 , wherein determining that the first message is malicious comprises one or more of:
 monitoring messages received from the second computing device;   analyzing content of the first message;   determining that a quantity messages received from the second computing device satisfies a maximum threshold quantity of messages; or determining that the first message has been sent via a port of the second computing device, wherein messages, previously sent by the second computing device via the port of the second computing device, indicate malicious messaging by the second computing device.   
     
     
         3 . The method of  claim 1 , wherein the second computing device is associated with a first network, and
 wherein preventing sending of the first message to the destination device comprises preventing sending of the first message to a destination device associated with a second network different than the first network.   
     
     
         4 . The method of  claim 1 , wherein determining that the first message is malicious comprises:
 determining that messages, of at least one message type and sent by the second computing device, indicate malicious messaging by the second computing device; and   determining, based on the first message being of that at least one message type, that the first message is malicious.   
     
     
         5 . The method of  claim 1 , wherein the first message is of at least one message type, and
 wherein the second message is configured to prevent the second computing device from sending additional messages of the at least one message type.   
     
     
         6 . The method of  claim 1 , wherein the second message comprises an acknowledgement that provides a false indication of a successful receipt of the first message by the destination device. 
     
     
         7 . The method of  claim 1 , further comprising:
 determining that the second computing device sent the first message via a port of the second computing device; and   sending additional messages, received via the port of the second computing device, to a sink-hole device.   
     
     
         8 . The method of  claim 1 , wherein the second message is configured to limit a quantity of subsequent messages that will be sent by the second computing device. 
     
     
         9 . A first computing device comprising:
 one or more processors; and   memory storing instructions that, when executed by the one or more processors, cause the first computing device to:
 receive, from a second computing device, a first message addressed to a destination device; and 
 based on determining that the first message is malicious:
 prevent sending of the first message to the destination device; and 
 send, to the second computing device, a second message comprising an invalid network address and configured to prevent the second computing device from sending one or more additional messages. 
 
   
     
     
         10 . The first computing device of  claim 9 , wherein the instructions, when executed by the one or more processors, cause the first computing device to determine that the first message is malicious by causing one or more of:
 monitoring messages received from the second computing device;   analyzing content of the first message;   determining that a quantity messages received from the second computing device satisfies a maximum threshold quantity of messages; or   determining that the first message has been sent via a port of the second computing device, wherein messages, previously sent by the second computing device via the port of the second computing device, indicate malicious messaging by the second computing device.   
     
     
         11 . The first computing device of  claim 9 , wherein the second computing device is associated with a first network, and
 wherein the instructions, when executed by the one or more processors, cause the first computing device to prevent the sending of the first message to the destination device by preventing sending of the first message to a destination device associated with a second network different than the first network.   
     
     
         12 . The first computing device of  claim 9 , wherein the instructions, when executed by the one or more processors, cause the first computing device to determine that the first message is malicious by causing the first computing device to:
 determine that messages, of at least one message type and sent by the second computing device, indicate malicious messaging by the second computing device; and   determine based on the first message being of that at least one message type, that the first message is malicious.   
     
     
         13 . The first computing device of  claim 9 , wherein the first message is of at least one message type, and
 wherein the second message is configured to prevent the second computing device from sending additional messages of the at least one message type.   
     
     
         14 . The first computing device of  claim 9 , wherein the second message comprises an acknowledgement that provides a false indication of a successful receipt of the first message by the destination device. 
     
     
         15 . The first computing device of  claim 9 , wherein the instructions, when executed by the one or more processors, further cause the first computing device to:
 determine that the second computing device sent the first message via a port of the second computing device; and   send additional messages, received via the port of the second computing device, to a sink-hole device.   
     
     
         16 . The first computing device of  claim 9 , wherein the second message is configured to limit a quantity of subsequent messages that will be sent by the second computing device. 
     
     
         17 . A non-transitory computer readable medium storing instructions that, when executed, cause:
 receiving, from a computing device, a first message addressed to a destination device; and   based on determining that the first message is malicious:
 preventing sending of the first message to the destination device; and 
 sending, to the computing device, a second message comprising an invalid network address and configured to prevent the computing device from sending one or more additional messages. 
   
     
     
         18 . The non-transitory computer readable medium of  claim 17 , wherein the instructions, when executed, cause determining that the first message is malicious by causing one or more of:
 monitoring messages received from the computing device;   analyzing content of the first message;   determining that a quantity messages received from the computing device satisfies a maximum threshold quantity of messages; or   determining that the first message has been sent via a port of the computing device, wherein messages, previously sent by the computing device via the port of the computing device, indicate malicious messaging by the computing device.   
     
     
         19 . The non-transitory computer readable medium of  claim 17 , wherein the computing device is associated with a first network, and
 wherein the instructions, when executed, cause preventing sending of the first message to the destination device by causing preventing sending of the first message to a destination device associated with a second network different than the first network.   
     
     
         20 . The non-transitory computer readable medium of  claim 17 , wherein the instructions, when executed, cause determining that the first message is malicious by causing:
 determining that messages, of at least one message type and sent by the computing device, indicate malicious messaging by the computing device; and   determining, based on the first message being of that at least one message type, that the first message is malicious.   
     
     
         21 . The non-transitory computer readable medium of  claim 17 , wherein the first message is of at least one message type, and
 wherein the second message is configured to prevent the computing device from sending additional messages of the at least one message type.   
     
     
         22 . The non-transitory computer readable medium of  claim 17 , wherein the second message comprises an acknowledgement that provides a false indication of a successful receipt of the first message by the destination device. 
     
     
         23 . The non-transitory computer readable medium of  claim 17 , wherein the instructions, when executed, further cause:
 determining that the computing device sent the first message via a port of the computing device; and   sending additional messages, received via the port of the computing device, to a sink-hole device.   
     
     
         24 . The non-transitory computer readable medium of  claim 17 , wherein the second message is configured to limit a quantity of subsequent messages that will be sent by the computing device.

Join the waitlist — get patent alerts

Track US2022076209A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.