×

Dynamic defense of network attacks

  • US 8,006,285 B1
  • Filed: 06/13/2005
  • Issued: 08/23/2011
  • Est. Priority Date: 06/13/2005
  • Status: Active Grant
First Claim
Patent Images

1. An intermediate network element comprising a processor programmed to control network traffic to a target network element from a plurality of sources, and further programmed to:

  • in response to determining that the target network element is under network attack, reserve a portion of bandwidth to the target resource for serving only trusted ones of the sources;

    in response to receiving messages from untrusted ones of the sources, administering respective challenges to the untrusted ones of the sources, wherein each challenge comprises a Turing test that requires a source-specific sentient response, wherein the challenges use stateless cookies such that the challenges are administered without recording associations between the challenges and answers to the challenges, wherein responses to the challenges are verified according to a function of a secret known to the intermediate network element and of respective network addresses of the sources; and

    in response to receiving a correct sentient response to one of the administered challenges from one of the untrusted sources, designating the one of the untrusted sources as trusted.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×