发明名称 CLIENT-SIDE ACTIVE VALIDATION FOR MITIGATING DDOS ATTACKS
摘要 Methods and systems for mitigating denial-of-service attacks include a proxy server that monitors a set of application servers configured to receive and service requests from clients. The proxy server intercepts the requests, and in response, provides the clients with customized client-side scripts embedded in markup language. The client-side scripts may include random strings to generate follow-through random uniform resource identifier redirection requests expected by the proxy server. The client-side scripts, upon execution, may challenge the clients by demanding user interaction within a specified period of time, requesting a delay before responding, and/or attempting to set a challenge cookie multiple times. If a client provides the demanded user interaction within the specified time, honors the delay, and/or sets the challenge cookie with the correct value, then the client-side scripts may generate a redirection request expected by the proxy server for that client and the proxy servers may whitelist that client for a configurable duration and forward that client's subsequent requests to the application servers without challenge.
申请公布号 US2014096194(A1) 申请公布日期 2014.04.03
申请号 US201314095712 申请日期 2013.12.03
申请人 VERISIGN, INC. 发明人 BHOGAVILLI SURESH;GUIMARAES ROBERTO;ZHAO YUJIE
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址