-
公开(公告)号:US12155690B1
公开(公告)日:2024-11-26
申请号:US17643762
申请日:2021-12-10
Applicant: Amazon Technologies, Inc.
Inventor: Kelly Anne Rooker , Thomas Bradley Scholl , Kushal Mall , Darshan Narayana Reddy , Lewis Iain McLean , Andrew Robert Hassall , Grace Marie Hatamyar , Bradford Sachin Chatterjee , Sidath Manawadu , Bobby Brown , John Shields , Karthik Chandrashekar
IPC: H04L29/06 , H04L9/40 , H04L41/0816 , H04L41/28
Abstract: The present disclosure generally relates to systems and methods for utilization of network mitigation techniques in the form of null address routing to mitigate coordinated DDOS attacks. A monitoring and mitigation service can characterize a command and control node as compromised or otherwise manipulated for purposes of generating distributed attacks. The monitoring and mitigation service can then identify network mitigation information in the form of null routing addresses that will cause network communications associated with the identified command and control node to be terminated or otherwise not delivered to the intended network-based resources. The monitoring and mitigation service can propagate the null routing address to routing components. The network mitigation information can be associated with expiration criteria for the routing components that receive and implement the network mitigation technique.
-
公开(公告)号:US11552876B1
公开(公告)日:2023-01-10
申请号:US17094657
申请日:2020-11-10
Applicant: Amazon Technologies, Inc.
Inventor: Jinbing Zhang , Ali Khayam , Kushal Mall , Sammit Kulkarni , Michael Wan
Abstract: Systems and methods are disclosed for monitoring routing data and issuing alarms for route anomalies detected based on the monitored routing data. Routing data, including Border Gateway Protocol (BGP) announcement and/or withdraw messages for a targeted prefix of an Autonomous System (AS), is collected and analyzed to detect route anomalies. The analysis may include a comparison of the BGP messages to internal routing data. An alarm is selectively output corresponding to the detected route anomalies. The detected route anomalies may be correlated with monitored network traffic data to classify the route anomalies, where the output of the alarm is based on the classification of the route anomalies.
-