Invention Grant
- Patent Title: Client-side active validation for mitigating DDOS attacks
- Patent Title (中): 客户端主动验证以减轻DDOS攻击
-
Application No.: US14095712Application Date: 2013-12-03
-
Publication No.: US09473530B2Publication Date: 2016-10-18
- Inventor: Suresh Bhogavilli , Roberto Guimaraes , Yujie Zhao
- Applicant: VERISIGN, INC.
- Applicant Address: US VA Reston
- Assignee: VERISIGN, INC.
- Current Assignee: VERISIGN, INC.
- Current Assignee Address: US VA Reston
- Agency: Artegis Law Group, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55

Abstract:
Methods and systems for mitigating denial-of-service attacks include a proxy server that monitors a set of application servers configured to receive and service requests from clients. The proxy server intercepts the requests, and in response, provides the clients with customized client-side scripts embedded in markup language. The client-side scripts may include random strings to generate follow-through random uniform resource identifier redirection requests expected by the proxy server. The client-side scripts, upon execution, may challenge the clients by demanding user interaction within a specified period of time, requesting a delay before responding, and/or attempting to set a challenge cookie multiple times. If a client provides the demanded user interaction within the specified time, honors the delay, and/or sets the challenge cookie with the correct value, then the client-side scripts may generate a redirection request expected by the proxy server for that client and the proxy servers may whitelist that client for a configurable duration and forward that client's subsequent requests to the application servers without challenge.
Public/Granted literature
- US20140096194A1 CLIENT-SIDE ACTIVE VALIDATION FOR MITIGATING DDOS ATTACKS Public/Granted day:2014-04-03
Information query