US 11,750,632 B2
Method and system for detecting and mitigating HTTPS flood attacks
Ehud Doron, Modiin (IL); Lev Medvedovsky, Netanya (IL); David Aviv, Tel Aviv (IL); Eyal Rundstein, Givataim (IL); Ronit Lubitch Greenberg, Tel Aviv (IL); and Avishay Balderman, Tel Aviv (IL)
Assigned to RADWARE, LTD., Tel Aviv (IL)
Filed by RADWARE LTD., Tel Aviv (IL)
Filed on May 31, 2022, as Appl. No. 17/804,725.
Application 17/804,725 is a continuation of application No. 16/453,035, filed on Jun. 26, 2019, granted, now 11,363,044.
Prior Publication US 2022/0294814 A1, Sep. 15, 2022
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1425 (2013.01) [H04L 63/1458 (2013.01)] 21 Claims
OG exemplary drawing
 
1. A method for detecting and mitigating denial-of-service (DoS) attacks that are using an encrypted communication protocol, comprising:
estimating traffic telemetries of packets of at least ingress traffic passing over an insecure network that is directed to a protected entity by analyzing transmission control protocol (TCP) headers of the packets, the packets of the at least ingress traffic being secured using an encrypted version of a non-encrypted communication protocol, the packets of the at least ingress traffic being intended for the protected entity;
providing at least one rate-based feature and at least one rate-invariant feature based on the estimated traffic telemetries, wherein the rate-based feature and the rate-invariant feature demonstrate a normal behavior of the traffic using the encrypted protocol intended for the protected entity; and
executing a mitigation action when a potential flood DoS attack using the encrypted communication protocol is detected by an evaluation of the at least one rate-based feature and the at least one rate-invariant feature to determine whether the behavior of the ingress traffic intended for the protected entity indicates a potential flood DoS attack using the encrypted communication protocol, wherein the evaluation of the at least one rate-based feature is with respect to at least a first baseline and the evaluation of the at least one rate-invariant feature is with respect to at least a second baseline.