发明名称 Internet-based proxy service to limit internet visitor connection speed
摘要 A proxy server for limiting Internet connection speed of visitors that pose a threat. The proxy server receives from a client device a request to perform an action on an identified resource that is hosted at an origin server for a domain. The proxy server receives the request as a result of a DNS request for the domain resolving to the proxy server. The origin server is one of multiple origin servers that belong to different domains that resolve to the proxy server and are owned by different entities. The proxy server analyzes the request to determine whether a visitor belonging to the request poses a threat. If the proxy server determines that the visitor poses a threat, the proxy server reduces the speed at which the proxy server processes the request while keeping a connection to the client device open.
申请公布号 US9009330(B2) 申请公布日期 2015.04.14
申请号 US201012939919 申请日期 2010.11.04
申请人 Cloudflare, Inc. 发明人 Holloway Lee Hahn;Prince Matthew Browning;Pye Ian Gerald
分类号 G06F15/16;G06F21/00;H04L29/06 主分类号 G06F15/16
代理机构 Blakely, Sokoloff, Taylor & Zafman LLP 代理人 Blakely, Sokoloff, Taylor & Zafman LLP
主权项 1. A method in a proxy server for limiting Internet connection speed of visitors that pose a threat, comprising: receiving, from a client device, a request to perform an action on an identified resource that is hosted at an origin server for a domain as a result of a DNS (Domain Name System) request for the domain resolving to the proxy server, wherein the origin server is one of a plurality of origin servers that belong to different domains that resolve to the proxy server and are owned by different entities; analyzing the request to determine whether a visitor belonging to the request poses a threat; responsive to a determination that the visitor belonging to the request poses a threat, reducing the speed at which the proxy server processes the request while keeping a connection to the client device open; determining whether the requested resource is available in cache; responsive to a determination that the requested resource is available in cache, transmitting, at a reduced speed to the client device, a response having the requested resource without transmitting the request to the origin server; responsive to a determination that the requested resource is not available in cache, performing the following: transmitting the request at a reduced speed to the origin server,receiving a response to the request from the origin server, andtransmitting the response to the client device at the reduced speed; and wherein the transmitted response includes a set of one or more false links to one or more false pages of one or more of the different domains of the origin servers such that if the visitor follows one of those false links, the corresponding request is received at the proxy server and processed at the reduced speed and will cause another response to be generated that includes another set of one or more false links to one or more false pages of one or more of the different domains that are processed at the reduced speed in an attempt to occupy that visitor and prevent the visitor from performing suspicious activity on any of the plurality of origin servers that resolve to the proxy server and other origin servers that do not resolve to the proxy server.
地址 San Francisco CA US