US2023308476A1PendingUtilityA1

Automatic Detection and Mitigation of Denial-of-Service Attacks

Assignee: GOOGLE LLCPriority: Dec 11, 2020Filed: May 9, 2023Published: Sep 28, 2023
Est. expiryDec 11, 2040(~14.4 yrs left)· nominal 20-yr term from priority
H04L 63/1458H04L 41/142H04L 63/0263H04L 63/1416H04L 63/1425H04L 41/16G06N 20/00H04L 63/029G06N 3/04
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for mitigating network abuse includes obtaining a first set of network traffic messages of network traffic currently received by a network service and determining, via a first model, whether network abuse is occurring based on the first set of network traffic messages. When the network abuse is occurring, the method includes obtaining a second set of current network traffic messages. The method also includes, for each network traffic message in the second set of network traffic messages, labeling, via a second model, the network traffic message as an abusing network traffic message or a non-abusing network traffic message. The method also includes generating, via a third model, at least one network traffic rule. Each network traffic rule, when implemented, reduces an effect of the abusing network traffic messages.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method when executed by data processing hardware causes the data processing hardware to perform operations comprising:
 obtaining a set of network traffic messages representative of network traffic currently received by a network service, the set of network traffic messages comprising a plurality of network traffic windows, each of the plurality of network traffic windows comprising a subset of network traffic messages of the set of network traffic messages associated with a different discrete portion of time;   for each of the plurality of network traffic windows, storing, in a data structure, characteristics of the subset of network traffic messages;   determining, via a model, that network abuse is occurring based on the characteristics of the subset of network traffic messages; and   transmitting an abuse determination indicating that the network abuse is detected.   
     
     
         2 . The method of  claim 1 , wherein the operations further comprise:
 after transmitting the abuse determination indicating that the network abuse is detected, obtaining a second set of network traffic messages representative of network traffic currently received by the network service; and   for each network traffic message in the second set of network traffic messages, labeling, via a second model, the network traffic message as:
 an abusing network traffic message participating in the network abuse; or 
 a non-abusing network traffic message not participating in the network abuse. 
   
     
     
         3 . The method of  claim 2 , wherein the operations further comprise generating, via a third model, at least one network traffic rule, each network traffic rule configured to be implemented by a firewall and, when implemented, reduce an effect of the abusing network traffic messages. 
     
     
         4 . The method of  claim 1 , wherein the operations further comprise, for each of the plurality of network traffic windows, sampling a set of sampled network traffic messages from the subset of network traffic messages, the set of sampled network traffic messages representative of an entirety of the subset of network traffic messages. 
     
     
         5 . The method of  claim 1 , wherein determining that the network abuse is occurring comprises:
 generating, by the model, an abuse probability score; and   determining that the abuse probability score satisfies an abuse probability threshold.   
     
     
         6 . The method of  claim 1 , wherein the model comprises a neural network trained on sets of labeled network traffic messages. 
     
     
         7 . The method of  claim 1 , wherein the operations further comprise, after determining that the network abuse is occurring:
 receiving feedback corresponding to the determination that the network abuse was occurring; and   updating the model based on the feedback.   
     
     
         8 . The method of  claim 7 , wherein the feedback indicates that the determination that the network abuse was occurring was a false positive. 
     
     
         9 . The method of  claim 7 , wherein the feedback indicates that the determination that the network abuse was occurring was correct. 
     
     
         10 . The method of  claim 1 , wherein the network abuse comprises a denial-of-service attack. 
     
     
         11 . A system comprising:
 data processing hardware; and   memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:
 obtaining a set of network traffic messages representative of network traffic currently received by a network service, the set of network traffic messages comprising a plurality of network traffic windows, each of the plurality of network traffic windows comprising a subset of network traffic messages of the set of network traffic messages associated with a different discrete portion of time; 
 for each of the plurality of network traffic windows, storing, in a data structure, characteristics of the subset of network traffic messages; 
 determining, via a model, that network abuse is occurring based on the characteristics of the subset of network traffic messages; and 
 transmitting an abuse determination indicating that the network abuse is detected. 
   
     
     
         12 . The system of  claim 11 , wherein the operations further comprise:
 after transmitting the abuse determination indicating that the network abuse is detected, obtaining a second set of network traffic messages representative of network traffic currently received by the network service; and   for each network traffic message in the second set of network traffic messages, labeling, via a second model, the network traffic message as:
 an abusing network traffic message participating in the network abuse; or 
 a non-abusing network traffic message not participating in the network abuse. 
   
     
     
         13 . The system of  claim 12 , wherein the operations further comprise generating, via a third model, at least one network traffic rule, each network traffic rule configured to be implemented by a firewall and, when implemented, reduce an effect of the abusing network traffic messages. 
     
     
         14 . The system of  claim 11 , wherein the operations further comprise, for each of the plurality of network traffic windows, sampling a set of sampled network traffic messages from the subset of network traffic messages, the set of sampled network traffic messages representative of an entirety of the subset of network traffic messages. 
     
     
         15 . The system of  claim 11 , wherein determining that the network abuse is occurring comprises:
 generating, by the model, an abuse probability score; and   determining that the abuse probability score satisfies an abuse probability threshold.   
     
     
         16 . The system of  claim 11 , wherein the model comprises a neural network trained on sets of labeled network traffic messages. 
     
     
         17 . The system of  claim 11 , wherein the operations further comprise, after determining that the network abuse is occurring:
 receiving feedback corresponding to the determination that the network abuse was occurring; and   updating the model based on the feedback.   
     
     
         18 . The system of  claim 17 , wherein the feedback indicates that the determination that the network abuse was occurring was a false positive. 
     
     
         19 . The system of  claim 17 , wherein the feedback indicates that the determination that the network abuse was occurring was correct. 
     
     
         20 . The system of  claim 11 , wherein the network abuse comprises a denial-of-service attack.

Join the waitlist — get patent alerts

Track US2023308476A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.