EP1535176A1

Method and system for protecting web sites from public internet threats

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 9 July 2023, 3.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

14 claims: 14 independent, 0 dependent

  1. 1
    Claims of equivalent WO 2004006113 A1 CLAIMS 1. A method operative in a content delivery network (CDN) having a set of content servers organized into regions and that provide content delivery on behalf of participating content providers, wherein a given content provider operates an origin server, comprising:shielding the given content provider's origin server from Internet Protocol (IP) traffic routable over the public Internet;and delivering content published at the given content provider's origin server from a CDN region.
  2. 2
    The method as described in Claim 1 wherein the step of shielding the given content provider's origin server includes the step of restricting access to the origin server except via a private IP address space.
  3. 3
    The method as described in Claim 2 further including the step of restricting IP spoofing for addresses within the private IP address space.
  4. 4
    The method as described in Claim 1 wherein the shielding step further includes the steps of:restricting access to the origin server except via a private IP address space;and restricting IP spoofing for addresses within the private IP address space
  5. 5
    The method as described in Claim 3 wherein the restricting step is implemented using an access control.
  6. 6
    The method as described in Claim 5 wherein the access control is implemented at a firewall.
  7. 7
    The method as described in Claim 1 further including the step of:if a given object request cannot be serviced from a CDN region, forwarding the given object request back to the origin server.
  8. 8
    In a Web site comprising an origin server, a firewall and router connectable to the publicly-routable Internet, the improvement comprising:apparatus associated with a private IP address space and being positioned upstream of the firewall and downstream of the router for shielding the origin server from Internet Protocol (IP) traffic routable over the public Internet;and a security mechanism comprising (a) a first access control implemented in the firewall for restricting access to the origin server except via the private IP address space, and (b) a second access control implemented in the router for restricting IP spoofing for addresses within the private IP address space.
  9. 9
    In the Web site infrastructure as described in Claim 8 wherein the apparatus comprises at least one server.
  10. 10
    In the Web site infrastructure as described in Claim 8 wherein the apparatus comprises at least first and second redundant servers.
  11. 11
    In the Web site infrastructure as described in Claim 8 wherein the first access control is an access control list.
  12. 12
    A method of protecting a Web site from attack, the Web site comprising an origin server, a firewall and router connectable to the publicly- routable Internet, comprising:restricting access to the origin server except from a private IP address space located between the firewall and the router;and serving content published at the origin server from a content delivery network.
  13. 13
    The method as described in Claim 12 wherein the step of serving content includes delivering content from a set of content servers.
  14. 14
    The method as described in Claim 13 wherein the set of content servers includes at least one CDN distribution node intermediate the origin server and a subset of content servers located at an Internet Point Of Presence (PoP).