×

Determining the likelihood of traffic being legitimately received at a proxy server in a cloud-based proxy service

  • US 9,641,549 B2
  • Filed: 02/04/2014
  • Issued: 05/02/2017
  • Est. Priority Date: 08/07/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method in a first one of a plurality of proxy servers that are anycasted to a same IP address, the method comprising:

  • receiving, at the first one of the plurality of proxy servers, a first packet that has a first source IP address, wherein the first packet is received at the first proxy server as a result of an anycast protocol implementation selecting that first proxy server as the closest out of the plurality of proxy servers in terms of routing protocol metric used to route traffic to the plurality of proxy servers, and wherein the first proxy server is in a different geographic location than other ones of the plurality of proxy servers;

    determining, using a data structure that indicates a plurality of source IP addresses from which packets are not likely to be legitimately received at that first proxy server, whether the received first packet is likely to be legitimately received at the first proxy server, wherein the data structure is built based on historical analysis of source IP addresses of packets received at the plurality of proxy servers when there is not currently a denial of service (DoS) attack associated with the plurality of proxy servers that are anycasted, and wherein the received first packet is likely to be legitimately received at the first proxy server when a probability determined using the historical analysis is above a threshold value, the probability retrieved from a probability map; and

    blocking the received first packet responsive to a determination that the received first packet is not likely to be legitimately received at the first proxy server, wherein determining using the data structure that the received first packet is not likely to be legitimately received at the first proxy server is an indication that a legitimate packet having that first source IP address should be received at a different one of the plurality of proxy servers.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×