Patent · US Active

Identifying sources of network attacks

US9794281B1 · kind B1 · utility

110Cited by
443References
21Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 24, 2015
Grant dateOct 17, 2017
Priority date
Expiry dateJan 6, 2036

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L61/4511
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Systems and methods are described to enable identification of computing devices associated with network attacks, such as denial of service attacks. Data packets used to execute a network attack often include forged source address information, such that the address of an attacker is difficult or impossible to determine based on those data packets. However, attackers generally provide legitimate address information when resolving an identifier, such as a universal resource identifier (URI), of an attack target into corresponding destination addresses. The application enables individual client computing devices to be provided with different combinations of destination addresses, such that when an attack is detected on a given combination of destination address, the client computing device to which that combination of destination addresses was provided can be identified as a source of the attack.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.