EP2854366B1

Limiting the efficacy of a denial of service attack by increasing client resource demands

Abstract

This record has no abstract on file.

EP2854366B1, drawing sheet 1
Sheet 1 of 9

Term

8 yearsleft in the term

Expires 29 September 2034.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

13 claims: 5 independent, 8 dependent

  1. 1
    A device (230), comprising:one or more processors (320) to: detect a denial-of-service attack;receive a request, for access to a resource, from a client device (210);determine, based on the request and further based on detecting the denial-of-service attack, a computationally expensive problem to be provided to the client device wherein the one or more processors are further to determine a profile associated with the client device, the profile indicating a probability that the request is associated with the denial-of-service attack;and determine the computationally expensive problem based on the profile;provide the computationally expensive problem to the client device, the computationally expensive problem being provided to cause the client device to solve the computationally expensive problem;receive, from the client device, a solution to the computationally expensive problem;and grant or deny the client device access to the resource based on the solution.
  2. 4
    The device of any preceding claim, where the one or more processors, when granting or denying access to the resource, are further to:grant access to the resource;and where the one or more processors are further to: provide a verification indicator to the client device based on granting access to the resource;receive an additional request from the client device, the additional request including the verification indicator;verify the verification indicator;and provide a response to the additional request based on verifying the verification indicator, the response not including the computationally expensive problem or another computationally expensive problem.
  3. 5
    The device of any preceding claim, where the one or more processors, when granting or denying access to the resource, are further to:deny access to the resource;and where the one or more processors are further to: provide an additional computationally expensive problem to the client device based on denying access to the resource, the additional computationally expensive problem requiring more processing power or memory space to solve than the computationally expensive problem.
  4. 6
    The device of any preceding claim, where the one or more processors, when granting or denying access to the resource, are further to:grant access to the resource;and where the one or more processors are further to: provide a verification indicator to the client device based on granting access to the resource;receive an additional request from the client device, the additional request including the verification indicator;determine that the verification indicator has expired;and provide an additional computationally expensive problem to the client device based on determining that the verification indicator has expired.
  5. 7
    A method, comprising:detecting (410), by a security device, a denial-of-service attack;receiving (420), by the security device and from a client device, a request;determining (430), by the security device and based on detecting the denial-of-service attack, a computationally expensive problem to be provided to the client device, wherein the method further comprises determining a profile associated with the client device, the profile indicating a probability that the request is associated with the denial-of-service attack;and wherein the determining of the computationally expensive problem is further based on the profile;determining, by the security device, code that causes the client device to solve the computationally expensive problem;instructing, by the security device, the client device to execute the code, the code causing the client device to generate a solution to the computationally expensive problem;receiving (450), by the security device and from the client device, the solution;and providing, by the security device and to the client device, a response to the request based on the solution.
  6. 10
    The method of any of claims 7 to 9, where determining the computationally expensive problem further comprises:determining a metric associated with the denial-of-service attack;and determining the computationally expensive problem based on the metric.
  7. 11
    The method of any of claims 7 to 10, further comprising:determining that the solution is incorrect;denying access to a resource requested in the request based on determining that the solution is incorrect;and where providing the response further comprises: providing an additional computationally expensive problem to the client device based on denying access to the resource, the additional computationally expensive problem requiring more computing resources to solve than the computationally expensive problem.
  8. 12
    The method of any of claims 7 to 11, further comprising:determining that the solution is correct;granting access to a resource requested in the request based on determining that the solution is correct;where providing the response further comprises: providing a verification indicator to the client device based on determining that the solution is correct;and where the method further comprises: receiving an additional request from the client device, the additional request including the verification indicator;determining that the verification indicator is invalid;determining a metric associated with the denial-of-service attack;and providing an additional computationally expensive problem to the client device based on determining that the verification indicator is invalid and further based on the metric.
  9. 13
    A computer-readable medium storing instructions that, when executed by a device, cause the device perform the method of claims 7-12.