Automatic Detection and Mitigation of Denial-of-Service Attacks
Abstract
A method for mitigating network abuse includes obtaining a first set of network traffic messages of network traffic currently received by a network service and determining, via a first model, whether network abuse is occurring based on the first set of network traffic messages. When the network abuse is occurring, the method includes obtaining a second set of current network traffic messages. The method also includes, for each network traffic message in the second set of network traffic messages, labeling, via a second model, the network traffic message as an abusing network traffic message or a non-abusing network traffic message. The method also includes generating, via a third model, at least one network traffic rule. Each network traffic rule, when implemented, reduces an effect of the abusing network traffic messages.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method when executed by data processing hardware causes the data processing hardware to perform operations comprising:
obtaining a set of network traffic messages representative of network traffic currently received by a network service, the set of network traffic messages comprising a plurality of network traffic windows, each of the plurality of network traffic windows comprising a subset of network traffic messages of the set of network traffic messages associated with a different discrete portion of time; for each of the plurality of network traffic windows, storing, in a data structure, characteristics of the subset of network traffic messages; determining, via a model, that network abuse is occurring based on the characteristics of the subset of network traffic messages; and transmitting an abuse determination indicating that the network abuse is detected.
2 . The method of claim 1 , wherein the operations further comprise:
after transmitting the abuse determination indicating that the network abuse is detected, obtaining a second set of network traffic messages representative of network traffic currently received by the network service; and for each network traffic message in the second set of network traffic messages, labeling, via a second model, the network traffic message as:
an abusing network traffic message participating in the network abuse; or
a non-abusing network traffic message not participating in the network abuse.
3 . The method of claim 2 , wherein the operations further comprise generating, via a third model, at least one network traffic rule, each network traffic rule configured to be implemented by a firewall and, when implemented, reduce an effect of the abusing network traffic messages.
4 . The method of claim 1 , wherein the operations further comprise, for each of the plurality of network traffic windows, sampling a set of sampled network traffic messages from the subset of network traffic messages, the set of sampled network traffic messages representative of an entirety of the subset of network traffic messages.
5 . The method of claim 1 , wherein determining that the network abuse is occurring comprises:
generating, by the model, an abuse probability score; and determining that the abuse probability score satisfies an abuse probability threshold.
6 . The method of claim 1 , wherein the model comprises a neural network trained on sets of labeled network traffic messages.
7 . The method of claim 1 , wherein the operations further comprise, after determining that the network abuse is occurring:
receiving feedback corresponding to the determination that the network abuse was occurring; and updating the model based on the feedback.
8 . The method of claim 7 , wherein the feedback indicates that the determination that the network abuse was occurring was a false positive.
9 . The method of claim 7 , wherein the feedback indicates that the determination that the network abuse was occurring was correct.
10 . The method of claim 1 , wherein the network abuse comprises a denial-of-service attack.
11 . A system comprising:
data processing hardware; and memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:
obtaining a set of network traffic messages representative of network traffic currently received by a network service, the set of network traffic messages comprising a plurality of network traffic windows, each of the plurality of network traffic windows comprising a subset of network traffic messages of the set of network traffic messages associated with a different discrete portion of time;
for each of the plurality of network traffic windows, storing, in a data structure, characteristics of the subset of network traffic messages;
determining, via a model, that network abuse is occurring based on the characteristics of the subset of network traffic messages; and
transmitting an abuse determination indicating that the network abuse is detected.
12 . The system of claim 11 , wherein the operations further comprise:
after transmitting the abuse determination indicating that the network abuse is detected, obtaining a second set of network traffic messages representative of network traffic currently received by the network service; and for each network traffic message in the second set of network traffic messages, labeling, via a second model, the network traffic message as:
an abusing network traffic message participating in the network abuse; or
a non-abusing network traffic message not participating in the network abuse.
13 . The system of claim 12 , wherein the operations further comprise generating, via a third model, at least one network traffic rule, each network traffic rule configured to be implemented by a firewall and, when implemented, reduce an effect of the abusing network traffic messages.
14 . The system of claim 11 , wherein the operations further comprise, for each of the plurality of network traffic windows, sampling a set of sampled network traffic messages from the subset of network traffic messages, the set of sampled network traffic messages representative of an entirety of the subset of network traffic messages.
15 . The system of claim 11 , wherein determining that the network abuse is occurring comprises:
generating, by the model, an abuse probability score; and determining that the abuse probability score satisfies an abuse probability threshold.
16 . The system of claim 11 , wherein the model comprises a neural network trained on sets of labeled network traffic messages.
17 . The system of claim 11 , wherein the operations further comprise, after determining that the network abuse is occurring:
receiving feedback corresponding to the determination that the network abuse was occurring; and updating the model based on the feedback.
18 . The system of claim 17 , wherein the feedback indicates that the determination that the network abuse was occurring was a false positive.
19 . The system of claim 17 , wherein the feedback indicates that the determination that the network abuse was occurring was correct.
20 . The system of claim 11 , wherein the network abuse comprises a denial-of-service attack.Join the waitlist — get patent alerts
Track US2023308476A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.