-
公开(公告)号:US12155690B1
公开(公告)日:2024-11-26
申请号:US17643762
申请日:2021-12-10
Applicant: Amazon Technologies, Inc.
Inventor: Kelly Anne Rooker , Thomas Bradley Scholl , Kushal Mall , Darshan Narayana Reddy , Lewis Iain McLean , Andrew Robert Hassall , Grace Marie Hatamyar , Bradford Sachin Chatterjee , Sidath Manawadu , Bobby Brown , John Shields , Karthik Chandrashekar
IPC: H04L29/06 , H04L9/40 , H04L41/0816 , H04L41/28
Abstract: The present disclosure generally relates to systems and methods for utilization of network mitigation techniques in the form of null address routing to mitigate coordinated DDOS attacks. A monitoring and mitigation service can characterize a command and control node as compromised or otherwise manipulated for purposes of generating distributed attacks. The monitoring and mitigation service can then identify network mitigation information in the form of null routing addresses that will cause network communications associated with the identified command and control node to be terminated or otherwise not delivered to the intended network-based resources. The monitoring and mitigation service can propagate the null routing address to routing components. The network mitigation information can be associated with expiration criteria for the routing components that receive and implement the network mitigation technique.
-
公开(公告)号:US20230246943A1
公开(公告)日:2023-08-03
申请号:US17590285
申请日:2022-02-01
Applicant: Amazon Technologies, Inc.
Inventor: Bradford Sachin Chatterjee , Thomas Bradley Scholl , Michael W. Palladino , Cheng-Jia Lai , Christopher Jason Brown , Yao Liu , Sasha Robbins , Blake Hoelzel , Eric Charles Briffa , Madhura Kale , Dennis Marinus , Matt Chung , Ibn Wendell Archer
Abstract: A system can determine by which path/tunnel an Internet destination can be best reached for a user with an IP address from a static BGP range. The system looks up the destination address in an egress map. This map can either specify a tunnel that should be used for encapsulation for static BGP, or (when tunnel is not present) cause the system to send out unencapsulated traffic, in which the traffic follows normal BGP routing on a border network.
-