The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 31, 2022

Filed:

Mar. 31, 2020
Applicant:

Fortinet, Inc., Sunnyvale, CA (US);

Inventors:

Zhi Guo, San Jose, CA (US);

Peixue Li, Cupertino, CA (US);

Xu Zhou, San Jose, CA (US);

Assignee:

Fortinet, Inc., Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04L 69/329 (2022.01); H04L 43/16 (2022.01); H04L 49/90 (2022.01); H04L 45/748 (2022.01); H04L 67/02 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1458 (2013.01); H04L 43/16 (2013.01); H04L 45/748 (2013.01); H04L 49/9068 (2013.01); H04L 63/1433 (2013.01); H04L 67/02 (2013.01); H04L 69/329 (2013.01);
Abstract

Systems and methods for providing an integrated or Smart NIC-based hardware accelerator for a network security device to facilitate identification and mitigation of DoS attacks is provided. According to one embodiment, a processor of a network security device receives an application layer protocol request from a client, directed to a domain hosted by various servers and protected by the network security device. The application layer protocol request is parsed to extract a domain name and a path string. The hardware acceleration sub-system updates rate-based counters based on the application layer protocol request by performing a longest prefix match on the domain name and the path string. When a rate threshold associated with the rate-based counters is exceeded, a challenge message is created and transmitted to the client, having embedded therein the application layer protocol request; otherwise the application layer protocol request is allowed to pass through the network security device.


Find Patent Forward Citations

Loading…