×

Identifying a denial-of-service attack in a cloud-based proxy service

  • US 9,628,509 B2
  • Filed: 12/17/2013
  • Issued: 04/18/2017
  • Est. Priority Date: 08/07/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method in a cloud-based proxy service for identifying a target of a denial-of-service (DoS) attack, the method comprising:

  • determining that there is traffic indicative of the DoS attack directed to an IP address of the cloud-based proxy service;

    responsive to determining that there are a plurality of domains that resolve to that same IP address, identifying the one of the plurality of domains that is the target of the DoS attack, wherein the step of identifying includes performing the following;

    causing each of the plurality of domains to resolve to a respectively different IP address,determining that the traffic indicative of the DoS attack is directed to a single one of the different IP addresses, andidentifying the target of the DoS attack as the one of the plurality of domains that resolves to the single one of the different IP addresses in which the traffic indicative of the DoS attack is directed; and

    after identifying the target of the DoS attack, isolating the target of the DoS attack to a set of one or more data centers, wherein a set of one or more other domains that are not the target of the DoS attack initially belong to the set of data centers; and

    moving that set of other domains to a different set of one or more data centers after identifying the target of the DoS attack.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×