CA2963544C

Techniques for protecting against denial of service attacks near the source

Abstract

A computer-implemented method involves detecting, by a computing device, a network condition indicative of a distributed denial of service attack directed to a victim executing within a first network. In response to detecting the network condition, the method also involves identify an internet protocol address associated with the victim, and selecting, based at least in part on the network condition, a remotely deployed network point of presence of a second network. The remotely deployed network point of presence is geographically proximate to an origin of the distributed denial of service attack. The remotely deployed network point of presence comprises a device that participates in a private channel communicatively coupled to the first network and that is located at a geographically remote location with respect to the victim. The method also involves taking one or more actions that cause the selected remotely deployed network point of presence to, at least announce, utilizing a border gateway protocol, the internet protocol address of the victim at the selected remotely deployed network point of present. Announcing the internet protocol address causes the network traffic addressed to the victim to be redirected through the remotely deployed network point of presence configured to receive network traffic addressed to the victim and block a first portion of the network traffic addressed to the victim. The first portion is identified based at least in part on a first set of mitigations techniques, and send, utilizing the private channel, a first unblocked portion of the network traffic toward the victim. The method also involves receiving the first unblocked portion of the network traffic, and blocking a second portion of the network traffic to determine a second unblocked portion of the network traffic addressed to the victim, the second portion being identified based at least in part on a second set of mitigation techniques. The second set of mitigation techniques provides a finer level of network filtering than the first set of mitigation techniques. The method also involves forwarding the second unblocked portion of the network traffic toward the victim.

CA2963544C, drawing sheet 1
Sheet 1 of 10

Term

5.2 yearsleft in the term

Expires 19 December 2031.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

20 claims: 3 independent, 17 dependent

  1. 1
    CA 2963544 2017-04-05 THE EMBODIMENTS OF THE INVENTION IN WHICH AN EXCLUSIVE PROPERTY OR PRIVILEGE IS CLAIMED ARE DEFINED AS FOLLOWS:1. A computer-implemented method, comprising: detecting, by a computing device, a network condition indicative of a distributed denial of service attack directed to a victim executing within a first network;in response to detecting the network condition, identify an internet protocol address associated with the victim;selecting, based at least in part on the network condition, a remotely deployed network point of presence of a second network, the remotely deployed network point of presence being geographically proximate to an origin of the distributed denial of service attack, wherein the remotely deployed network point of presence comprises a device that participates in a private channel communicatively coupled to the first network and that is located at a geographically remote location with respect to the victim;taking one or more actions that cause the selected remotely deployed network point of presence to, at least: announce, utilizing a border gateway protocol, the internet protocol address of the victim at the selected remotely deployed network point of present, wherein announcing the internet protocol address causes the network traffic addressed to the victim to be redirected through the remotely deployed network point of presence configured to: receive network traffic addressed to the victim;block a first portion of the network traffic addressed to the victim, the first portion being identified based at least in part on a first set of mitigations techniques;and send, utilizing the private channel, a first unblocked portion of the network traffic toward the victim;receiving the first unblocked portion of the network traffic;blocking a second portion of the network traffic to determine a second unblocked portion of the network traffic addressed to the victim, the second portion being identified based at least in part on a second set of mitigation techniques, the second set of mitigation CA 2963544 2017-04-05 techniques providing a finer level of network filtering than the first set of mitigation techniques;and forwarding the second unblocked portion of the network traffic toward the victim.
  2. 2
    A computer system, comprising:one or more processors;and memory including executable instructions that, when executed by the one or more processors, cause the computer system to, at least: receive information indicating a distributed denial of service attack directed to a network destination;select a remotely deployed network point of presence of a network that is a geographical distance from an origin of the distributed denial of service attack, wherein the remotely deployed network point of presence is connected to the network destination via a private channel and wherein the remotely deployed network point of presence is located at a geographically remote location with respect to the network destination;take one or more actions that cause the selected remotely deployed network point of presence to, at least: announce, utilizing a border gateway protocol, an addressing route associated with the network destination at the selected remotely deployed network point of presence, wherein announcing the internet protocol address causes the network traffic addressed to the network desitnation to be redirected through the remotely deployed network point of presence;and redirect network traffic addressed to the network destination based on the announcement.
  3. 10
    One or more non-transitory computer-readable storage media having stored thereon instructions executable by one or more processors of a computer system that, when executed with the one or more processors, cause the computer system to at least:detect attack traffic indicative of a distributed denial of service attack directed to a network destination;CA 2963544 2017-04-05 in response to detecting the attack traffic, identify an Internet protocol address associated with the network destination;select a remotely deployed network point of presence of a network based on an origin of the distributed denial of service attack, wherein the remotely deployed network point of presence comprises a device that is connected to the network destination via a private channel and wherein the remotely deployed network point of presence is located at a geographically remote location with respect to the network destination;take one or more actions that cause the selected remotely deployed network point of presence to, at least: announce, utilizing a border gateway protocol, the Internet protocol address at the selected remotely deployed network point of present, wherein announcing the Internet protocol address causes the network traffic addressed to the network destination to be redirected through the remotely deployed network point of presence configured to: discard network traffic indicative of the distributed denial of service attack at the remotely deployed network point of presence;and forward, utilizing the private channel, non-discarded network traffic addressed toward the network destination.