US 11,757,930 B2
Cooperative mitigation of distributed denial of service attacks originating in local networks
Tirumaleswar Reddy Konda, Bangalore (IN); Harsha R. Joshi, Bangalore (IN); Himanshu Srivastava, Bangalore (IN); Srikanth Nalluri, Bellandur (IN); and Dattatraya Kulkarni, Bangalore (IN)
Assigned to McAfee, LLC, San Jose, CA (US)
Filed by McAfee, LLC, San Jose, CA (US)
Filed on Jun. 28, 2021, as Appl. No. 17/360,810.
Application 17/360,810 is a continuation of application No. 16/154,473, filed on Oct. 8, 2018, granted, now 11,050,785.
Claims priority of application No. 201841031876 (IN), filed on Aug. 25, 2018.
Prior Publication US 2021/0329028 A1, Oct. 21, 2021
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 29/06 (2006.01); H04L 12/24 (2006.01); H04L 12/741 (2013.01); H04L 9/40 (2022.01); H04L 41/14 (2022.01); H04L 45/745 (2022.01); H04L 41/12 (2022.01)
CPC H04L 63/1458 (2013.01) [H04L 41/12 (2013.01); H04L 41/145 (2013.01); H04L 45/745 (2013.01); H04L 63/0263 (2013.01); H04L 63/1416 (2013.01); H04L 63/20 (2013.01)] 15 Claims
OG exemplary drawing
 
1. A network element to perform cooperative mitigation of distributed denial of service attacks associated with network traffic received by an Internet service provider network, the network element comprising:
at least one memory;
computer readable instructions; and
at least one processor to execute the computer readable instructions to at least:
detect a first distributed denial of service attack associated with first network traffic received by the Internet service provider network, the first network traffic originating from a first device connected to a local network; and
implement a threat signaling client to:
transmit first information describing the first distributed denial of service attack to a first threat signaling server implemented by a local network router of the local network;
receive second information from the first threat signaling server of the local network, the second information to provide a notification when the first network traffic associated with the first distributed denial of service attack has been mitigated;
prior to transmission of the first information, emulate a second threat signaling server, the second threat signaling server to receive a request from the first threat signaling server of the local network to establish a secure connection; and
after receipt of the request, switch from emulating the second threat signaling server to operating as the threat signaling client to (i) transmit messages to the first threat signaling server of the local network conveying information describing distributed denial of service attacks and (ii) receive corresponding notifications from the first threat signaling server of the local network concerning the distributed denial of service attacks.