Method and system for characterization and mitigation of encrypted distributed denial of service (DDoS) attacks
Assignee
Radware Ltd.
Inventors
Avi Chesla, Guy Perez
Abstract
A method and system for mitigating encrypted distributed denial of service (DDOS) attacks comprising: receiving a detection of an encrypted DDOS attack from an encrypted transaction related traffic, wherein the encrypted DDOS attack is associated with a plurality of transport layer security (TLS) fingerprints (FPs); classifying each of the plurality of TLS FPs as a type of FP based on a comparison of rate-invariant values to a native FP baseline, wherein the rate-invariant values are associated with the plurality of TLS FPs; selecting anomalous FPs as a subset of the plurality of TLS FPs; generating a real time signature (RTS), for the encrypted DDOS attack, having at least one unknown type of FP of the subset of anomalous FPs; and mitigating the encrypted DDOS attack based on the generated RTS.
CPC Classifications
Filing Date
2024-08-29
Application No.
18819308
Claims
20