System and method of performing amplification attack mitigation in data communication network control protocols

A token-based mechanism at the receiver node controls response sizes in network control protocols, addressing the inefficiencies of existing amplification attack mitigation by ensuring predictable and proportional responses, enhancing network security and efficiency.

WO2026027062A1PCT designated stage Publication Date: 2026-02-05HUAWEI TECH CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/072029
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-02
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Existing methods for mitigating amplification attacks in network control protocols fail to provide predictable responses without truncation or length limitations, leading to network inefficiencies and vulnerabilities.

Method used

Implementing a token-based mechanism where a receiver node updates a token counter based on received messages, bounding the response size by the number of tokens, and generating responses proportional to the tokens received, thereby preventing disproportionately large responses.

Benefits of technology

This approach enhances network security and efficiency by preventing amplification attacks, ensuring controlled and proportional responses, reducing the risk of network congestion and overload, and adapting to real-time network conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024072029_05022026_PF_FP_ABST
    Figure EP2024072029_05022026_PF_FP_ABST
Patent Text Reader

Abstract

A method of performing amplification attack mitigation in a data communications network implementing network control protocols, comprising steps, carried out at a receiver node of the network, of receiving a set of one or more token messages from a sender node of the network, updating a token counter based on the received set of one or more token messages, receiving a packet from the sender node, generating a set of one or more response packets such that the size of the response is bounded by the number of tokens specified in the token counter and sending the one or more response packets to the sender node.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEM AND METHOD OF PERFORMING AMPLIFICATION ATTACK MITIGATION IN DATA COMMUNICATION NETWORK CONTROL PROTOCOLS

[0002] TECHNICAL FIELD

[0003] The present disclosure relates generally to the field of wireless communication systems and, more specifically, to a system, and a method of performing amplification attack mitigation in a data communications network implementing network control protocols, such as by providing an amplification attack mitigation in network control protocols.

[0004] BACKGROUND

[0005] Amplification is a well-known property of certain network control protocols where the response to a request is larger than the request itself, either in terms of the number of packets or the amount of data (bytes) that leads to inefficiencies and vulnerabilities in network operations. Certain protocols, such as the Internet Control Message Protocol (ICMP) use request-response mechanisms where an error in a packet triggers a longer response message containing the original message and additional error information. Moreover, such request-response mechanisms inherently create amplification, as seen in widely used utilities, such as traceroute. Additionally, other protocols, such as In-situ Operations Administration and Maintenance (IOAM) protocol include extensive reporting by network nodes. For example, the loopback feature of the IOAM causes intermediate nodes to send performance-related responses back to source, potentially leading to the amplification. Similarly, other protocols may also exhibit similar behaviour where a single request triggers multiple responses from receiver. For example, certain protocols allow a sender node to receive multiple response messages from a responder node, which can exacerbate amplification issues.

[0006] An amplification attack is an attack in which an attacker sends a relatively small amount of data to the receiver, triggering the transmission of a large amount of data from the receiver to one or more destinations. Therefore, the attacker uses low resources in order to create a large impact. Specifically, the amplification attack can be combined with spoofing that is the attacker can send one or more packets with a source address that represents the desired victim of the attack, causing the receiver to transmit a large amount of data to the victim. This approach may, in extreme cases, allow the attacker to create a Denial-of-Service or a Distributed-Denial-of- Service attack. Therefore, certain attempts have been taken to mitigate the risk of the amplification attack but fail due to many reasons. However, such attempts often failed due to various reasons, such as by limiting the rate responses, by using a symmetric request-response to limit the protocol, and the like. Specifically, the drawback of rate limiting is that some requests are sent without receiving a response, and often it is not predictable whether a response will be received. The drawback of the symmetric approach is that in some cases the response needs to be truncated in order to be the same length as the request, and thus the response does not necessarily include all the desired information. Thus, there exists a technical problem of how to mitigate amplification attacks while allowing predictable responses that do not need to be truncated or limited in length.

[0007] Therefore, in light of the foregoing discussion, there exists a need to overcome the aforementioned drawbacks associated with the conventional systems and the conventional methods of performing amplification attack mitigation in a data communications network implementing network control protocols.

[0008] SUMMARY

[0009] The present disclosure provides a system and a method of performing amplification attack mitigation in a data communications network implementing network control protocols. The present disclosure provides a solution to the existing problem of how to mitigate amplification attacks while allowing predictable responses that do not need to be truncated or limited in length. An objective of the present disclosure is to provide a solution that overcomes at least partially the problems encountered in the prior art and provides an improved system and an improved method of performing amplification attack mitigation in a data communications network implementing network control protocols.

[0010] One or more objectives of the present disclosure are achieved by the solutions provided in the enclosed independent claims. Advantageous implementations of the present disclosure are further defined in the dependent claims.

[0011] In one aspect, the present disclosure provides a method of performing amplification attack mitigation in a data communications network implementing network control protocols, comprising steps, carried out at a receiver node of the network, of receiving a set of one or more token messages from a sender node of the network, updating a token counter based on the received set of one or more token messages, receiving a packet from the sender node, generating a set of one or more response packets such that the size of the response is bounded by the number of tokens specified in the token counter, and sending the one or more response packets to the sender node.

[0012] Advantageously, by bounding the response size to the number of tokens received, the method is used to prevent the receiver node from sending disproportionately large responses, which could be exploited in the amplification attacks. Moreover, the token counter can be configured to aggregate tokens based on either the number of packets or the total number of bytes in order to provide flexibility for managing the responses and to ensure efficient network management, such as by preventing unnecessary data transmission with reduced risk of network congestion or overload. The method is used to adapt to network conditions by adjusting the token aggregation and response generation processes based on real-time network metrics that enhance overall network performance and network security. In addition, the method provides a robust defence against amplification attacks by aligning the number and size of response packets with the tokens received from the sender, which reduces the likelihood of amplification attacks that could disrupt network services. Therefore, the method is used to ensure a secure, efficient, and adaptable network control protocol that mitigates the risks associated with the amplification attacks.

[0013] In a second aspect, the present disclosure provides a method of performing amplification attack mitigation in a data communications network implementing network control protocols, comprising steps, carried out at a sender node of the network, of: sending a set of one or more token messages to a receiver node of the network and the receiver node updates a token counter based on the received set of one or more token messages, sending a packet to the receiver node and the receiver node generates a set of one or more response packets such that the size of the response is bounded by the number of tokens specified in the token counter, and receiving the one or more response packets from the receiver node.

[0014] Advantageously, the method of performing amplification attack mitigation is used to prevent the receiver node from sending disproportionately large responses, effectively mitigating the risk of amplification attacks through a flexible token aggregation mechanism that can be configured to count either the number of packets or the total bytes received, allowing for tailored management of response sizes by bounding the response size to the number of tokens received. The method is also used to enhance network efficiency by preventing unnecessary data transmission, thus reducing the risk of network congestion or overload. Additionally, the method can dynamically adapt to network conditions by adjusting token aggregation and response generation processes based on real-time network metrics, that enhances overall network performance and security. Furthermore, by aligning the number and size of response packets with the tokens received from the sender, the method provides a robust defence against amplification attacks, significantly reducing the likelihood of such attacks disrupting network services. Therefore, the method is used to ensure a secure, efficient, and adaptable network control protocol that mitigates the risks associated with the amplification attacks.

[0015] In a third aspect, the present disclosure provides a system comprising means adapted for carrying out all the steps of the method according to any preceding method claim.

[0016] The system achieves all the advantages and technical effects of the data communication network of the present disclosure.

[0017] It is to be appreciated that all the aforementioned implementation forms can be combined.

[0018] It has to be noted that all devices, elements, circuitry, units, and means described in the present application could be implemented in the software or hardware elements or any kind of combination thereof. All steps which are performed by the various entities described in the present application as well as the functionalities described to be performed by the various entities are intended to mean that the respective entity is adapted to or configured to perform the respective steps and functionalities. Even if, in the following description of specific embodiments, a specific functionality or step to be performed by external entities is not reflected in the description of a specific detailed element of that entity which performs that specific step or functionality, it should be clear for a skilled person that these methods and functionalities can be implemented in respective software or hardware elements, or any kind of combination thereof. It will be appreciated that features of the present disclosure are susceptible to being combined in various combinations without departing from the scope of the present disclosure as defined by the appended claims.

[0019] Additional aspects, advantages, features, and objects of the present disclosure would be made apparent from the drawings and the detailed description of the illustrative implementations construed in conjunction with the appended claims that follow. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The summary above, as well as the following detailed description of illustrative embodiments, is better understood when read in conjunction with the appended drawings. For the purpose of illustrating the present disclosure, exemplary constructions of the disclosure are shown in the drawings. However, the present disclosure is not limited to specific methods and instrumentalities disclosed herein. Moreover, those in the art will understand that the drawings are not to scale. Wherever possible, like elements have been indicated by identical numbers.

[0021] Embodiments of the present disclosure will now be described, by way of example only, with reference to the following diagrams wherein:

[0022] FIG. 1 is a block diagram that depicts a system configured for performing amplification attack mitigation in a data communication network control protocols, in accordance with an embodiment of the present disclosure;

[0023] FIG. 2 is a flowchart depicting a method for performing amplification attack mitigation in a data communication network control protocols comprising steps carried out at a receiver node of the network, in accordance with an embodiment of the present disclosure;

[0024] FIG. 3 is a flowchart depicting a method for comprising steps carried out at a sender node of a network, in accordance with an embodiment of the present disclosure;

[0025] FIG. 4 is a diagram that depicts mitigation of the amplification attack by using token messages with a single receiver node, in accordance with an embodiment of the present disclosure; and

[0026] FIG. 5 is a diagram that depicts mitigation of the amplification attack by using token messages with multiple intermediate nodes and the receiver node, in accordance with an embodiment of the present disclosure.

[0027] In the accompanying drawings, an underlined number is employed to represent an item over which the underlined number is positioned or an item to which the underlined number is adjacent. A non-underlined number relates to an item identified by a line linking the nonunderlined number to the item. When a number is non-underlined and accompanied by an associated arrow, the non-underlined number is used to identify a general item at which the arrow is pointing. DETAILED DESCRIPTION OF EMBODIMENTS

[0028] The following detailed description illustrates embodiments of the present disclosure and ways in which they can be implemented. Although some modes of carrying out the present disclosure have been disclosed, those skilled in the art would recognize that other embodiments for carrying out or practicing the present disclosure are also possible.

[0029] FIG. l is a block diagram that depicts a system configured for performing amplification attack mitigation in a data communication network control protocols, in accordance with an embodiment of the present disclosure. With reference to FIG.l, there is shown a block diagram that includes a system 100. The system 100 includes a sender node 102, a receiver node 112, and a communication channel 110. Moreover, the sender node 102 includes a first controller 104, a first memory 106, and a first network interface 108. Similarly, the receiver node 112 includes a second controller 114, a second memory 116, and a second network interface 118.

[0030] The sender node 102 refers to a component within the data communication network responsible for transmitting data packets. Similarly, the receiver node 112 refers to a component in the data communication network responsible for accepting and processing the data packets transmitted by the sender node 102. In an example, the sender node 102 may include but are not limited to, a transmitter, a sender, a transceiver, an encoder, a user terminal of a cellular network, a customized hardware for wireless telecommunication, or any other portable or non-portable electronic device, client device, user equipment, and the like.

[0031] In accordance with an embodiment, the receiver node 112 is an intermediate node in the network. For example, the sender node 102 sends a request to the receiver node 112, with intermediate nodes, such as a first intermediate node and a second intermediate node in the data communication network. In such a case, the sender node 102 is configured to first send token messages to the first intermediate node, then to the second intermediate node, and finally to the receiver node 112. Therefore, the receiver node 112, which is the intermediate node is used in packet transmission from the sender node 102 to the receiver node 112 within the data communication network.

[0032] The first controller 104 refers to a processing unit configured to send, coordinate and manage the transmission of the data packets in the data communication network. Similarly, the second controller 114 refers to a processing unit configured to receive and process the data packets in the data communication network. Examples of implementation of the first controller 104 and the second controller 114 may include but are not limited to a central data processing device, a microprocessor, a microcontroller, a complex instruction set computing (CISC) processor, an application-specific integrated circuit (ASIC) processor, a reduced instruction set (RISC) processor, a very long instruction word (VLIW) processor, a state machine, and other processors or control circuitry.

[0033] The first network interface 108 is configured to enable communication of the first controller 104 and the communication channel 110. Similarly, the second network interface 118 is configured to enable communication of the second controller 114 and the communication channel 110. Examples of the first network interface 108 and the second network interface 118 include but are not limited to, a network interface card, and the like.

[0034] The communication channel 110 includes a medium (e.g., a communication channel) through which the sender node 102 communicates with the receiver node 112. The communication channel 110 may be a wired or wireless communication network. Examples of the communication channel 110 may include, but are not limited to, Internet, a Local Area Network (LAN), a wireless personal area network (WPAN), a Wireless Local Area Network (WLAN), a wireless wide area network (WWAN), a cloud network, a Long-Term Evolution (LTE) network, a plain old telephone service (POTS), a Metropolitan Area Network (MAN), and / or the Internet.

[0035] There is provided the system 100 for performing amplification attack mitigation in a data communications network implementing network control protocols. The amplification attacks exploit network control protocols by generating large volumes of response data from small requests, leading to network inefficiencies and vulnerabilities. Therefore, the system 100 is configured to mitigate the amplification attack by controlling the size and rate of the responses based on a token mechanism with an improved, robust, and enhanced network security and data management.

[0036] In operation, the receiver node 112 of the network is configured to receive a set of one or more token messages from the sender node 102 of the network. Prior to that, the sender node 102 needs to send a request that triggers an amplified response, the sender node 102 is configured to send the set of one or more token messages to the receiver node 112 that aggregates the tokens based on the received set of one or more token messages. As a result, the receiver node 112 is configured to receive the set of one or more token messages from the sender node 102 that are further used to track and control the size of subsequent responses.

[0037] Furthermore, the receiver node 112 of the network is configured to update a token counter based on the received set of one or more token messages. For example, the sender node 102 sends the set of one or more token messages to node the receiver node 112 and upon receiving the set of one or more token messages, the receiver node 112 updates the token counter. In this regard, the token counter refers to a counter that records the number of tokens received, which could represent either the number of packets or the total bytes. Therefore, when the sender node 102 sends the actual request packet to the receiver node 112, then, in that case, the receiver node 112 utilizes the token counter to generate response packets. Moreover, the size and rate of the response packets are controlled by the token counter, ensuring that the responses are proportional to the tokens received. As a result, the token counter is updated by the receiver node 112 in order to ensure that the responses generated by the receiver node 112 are proportional to the tokens received, thereby preventing amplification attacks that can exploit network control protocols, such as by triggering large responses from small requests.

[0038] Furthermore, the receiver node 112 of the network is configured to receive a packet from the sender node 102. The receiver node 112 is configured to receive the packet from the sender node 102 in order to ensure the communication flow between the sender node 102 and the receiver node 112. In an implementation, the sender node 102 sends a packet to the receiver node 112 and the receiver node 112 is equipped to receive and process the incoming packet. Thereafter, upon receiving the packet, the receiver node 112 updates the token counter based on the information contained within the packet and previously received token messages and generates the response packets based on the aggregated tokens and the received packet. Finally, the receiver node 112 generates a set of one or more response packets and sends them back to the sender node 102. Therefore, by efficiently receiving and processing packets, the network can maintain a smooth flow of data, optimize resource utilization, and minimize latency.

[0039] In accordance with an embodiment, the packet received from the sender node 102 includes the set of one or more token messages. By receiving the packet from the sender node 102, the system 100 is configured to prevent the amplification attacks, where small requests from the sender node 102 can generate disproportionately large responses. The set of one or more token messages received by the receiver node 112 is used to maintain and update the token counter and based on the updated token counter, the receiver node 112 is configured to restrict the packets that are generated as the response to the set of one or more token messages, thereby mitigating the risk of amplification attack.

[0040] In accordance with an embodiment, each packet received from the sender node 102 causes one token to be aggregated at the receiver node 112. The aggregated tokens based on the number of packets received allow for a controlled and proportional response mechanism in order to prevent the amplification attacks, which exploit network protocols by generating large responses from small requests. By linking the number of tokens to the number of packets received, the network can ensure that responses are appropriately sized and frequency- controlled, enhancing security and efficiency.

[0041] In accordance with an embodiment, each packet received from the sender node 102 causes n tokens to be aggregated at the receiver node 112, where n is an integer greater than 1. The receiver node 112 is configured to receive individual packets from the sender node 102 and for each packet received, the receiver node 112 aggregates n tokens, which means that the token counter is incremented by n for every packet received. Moreover, when generating the responses, the receiver node 112 uses the token counter to determine the size and number of response packets. The total size of the response is bounded by the number of aggregated tokens. Finally, the receiver node 112 sends the response packets back to the sender node 102, ensuring that the responses are controlled and proportional to the tokens aggregated. As a result, by aggregating multiple tokens for each received packet allows a reliable and effective control over the response mechanism that helps the system 100 to prevent amplification attacks by ensuring that the responses are proportional to the received packets but with greater granularity thereby, enhancing the overall security and efficiency of the data communication network.

[0042] Furthermore, the receiver node 112 of the network is configured to generate a set of one or more response packets such that the size of the response is bounded by the number of tokens specified in the token counter. Prior to generating responses, the receiver node 112 aggregates tokens based on the packets received from the sender node 102. Such an aggregation of tokens updates the token counter. When the receiver node 112 needs to generate response packets, the receiver node 112 consults the token counter to determine the permissible size and number of these response packets. The receiver node 112 creates the response packets, ensuring that the total size (number of packets or total bytes) does not exceed the limit set by the token counter. The receiver node 112 sends the generated response packets back to the sender node 102, maintaining a controlled and proportional response based on the tokens aggregated. Therefore, by generating response packets with the size that is bounded by the number of tokens in the token counter is helpful for preventing amplification attacks.

[0043] In accordance with an embodiment, generating a set of one or more response packets is carried out by counting a number of tokens in the set of one or more token messages according to the number of packets received from the sender node 102. The counting of the tokens based on the number of packets received from the sender node 102 is used to ensure that the responses are proportionate to the requests. In an implementation, the receiver node 112 receives individual packets from the sender node 102. For each packet received, the receiver node 112 counts tokens based on the number of packets received, such as by incrementing the token counter by a specific number for each packet. Furthermore, the token counter at the receiver node 112 keeps a cumulative count of tokens, which corresponds to the number of packets received. Moreover, when generating responses, the receiver node 112 utilizes the token counter to determine the size and number of response packets and the total size of the response is bounded by the number of aggregated tokens. Finally, the receiver node 112 sends the response packets back to the sender node 102, ensuring that the responses are controlled and proportional to the tokens counted. As a result, the system 100 is configured to mitigate the risk of amplification attacks, which exploit network protocols by generating large responses from small requests with enhanced overall security and efficiency of the data communication network.

[0044] In accordance with an embodiment, generating a set of one or more response packets is carried out by counting a number of tokens in the set of one or more token messages according to the number of bytes received from the sender node 102. Moreover, counting of the tokens based on the number of bytes received from the sender node 102 allows for more granular and precise control over response sizes. The system 100 is used to ensure that the responses are proportional to the volume of data received, rather than just the number of packets in order to prevent the amplification attacks by making sure that the response size is closely matched to the amount of data sent in the request, thereby enhancing security and efficiency.

[0045] In accordance with an embodiment, the one or more response packets is an amplified response. The amplified response is used to provide additional information that may include information, such as network diagnostics, performance monitoring, or other network control purposes to provide a comprehensive data for maintaining and optimizing the overall performance of the data communication network. As a result, by aligning the size and number of amplified response packets with the tokens received, the system 100 is configured to provide a robust defence against amplification attacks, significantly reducing the likelihood of such attacks disrupting network services.

[0046] Furthermore, the receiver node 112 of the network is configured to send the one or more response packets to the sender node 102. The transmission of the one or more response packets to the sender node 102 by the receiver node 112 allows an exchange of the data and maintains an active and responsive network, ensuring that the sender node 102 receives the necessary data or acknowledgements from the receiver node 112 that is further used to prevent potential amplification attacks and ensures efficient data transmission.

[0047] In accordance with an embodiment, the set of one or more response packets is based on a multiple of the number of tokens specified in the token counter. Moreover, the set of one or more response packets is generated based on the multiple of the number of tokens specified in the token counter to allow flexible and scalable response generation that the response size can be adjusted according to specific network requirements or performance needs, providing the ability to scale responses while maintaining control over the size of the responses. Therefore, by allowing for varying response sizes depending on the current data communication network conditions and requirements, the excessive data transmission can be limited, and the risk of network congestion or overload can also be reduced thereby providing a robust defence against amplification attacks. Therefore, aligning the size and number of response packets with the multiple of the tokens counted enhances the overall data communication network performance and security, mitigating the risk of such attacks that disrupt the data communication network services.

[0048] In accordance with an embodiment, the value of the multiple is configurable. Making the value of the multiple configurable allows a flexible and adaptable response generation that enables the data communication network to adjust the size of the response packets dynamically based on real-time network conditions, specific application requirements, or performance metrics. As a result, the system 100 is configured to adjust response sizes dynamically based on real-time conditions and specific requirements to optimize the overall data communication network performance and resource management thereby preventing excessive data transmission and reducing the risk of network congestion or overload.

[0049] In accordance with an embodiment, the value of the multiple is configurable based on prior knowledge of the topology of the network. By configuring the value of the multiple, based on prior knowledge of the network topology, the system 100 allows for an optimized response generation. In an implementation, the prior knowledge of the topology of the network includes the number of hops, bandwidth limitations, traffic patterns, and the like. Moreover, such value allows the receiver node 112 to adjust the response size more effectively to further ensure that the data communication network operates efficiently, reduces latency, and prevents overloading specific segments of the data communication network.

[0050] In accordance with an embodiment, the value of the multiple is configured based on a dynamic mechanism that learns the topology of the network and configures the fraction, in accordance with the learned topology of the network. The data communication network utilizes the dynamic mechanism that continuously monitors and learns the network topology, such as by using realtime data on the number of hops, bandwidth availability, node capacities, traffic patterns, and the like. The receiver node 112 is configured to receive the packets from the sender node 102 and aggregates tokens based on the received data. Furthermore, the receiver node 112 calculates the size of the response packets based on the dynamically configured multiple, which is set according to the learned network topology. For example, if the token counter has a value of T tokens and the dynamically configured multiple is M, the response size is calculated as M * T. After that, the receiver node 112 is configured to generate one or more response packets, ensuring that the total size is based on the calculated multiple of the tokens. Thereafter, the receiver node 112 sends the generated response packets back to the sender node 102, ensuring that the responses are timely and appropriately scaled. As a result, the system 100 is configured to provide real-time optimization of response sizes, ensuring that the network can adapt to changes in topology and maintain efficient operation under varying conditions. By dynamically adjusting the response sizes based on current network metrics, the system 100 can prevent network congestion, reduce latency, and optimize resource usage. Additionally, the dynamic mechanism ensures that responses remain proportionate to the tokens received, providing a robust defence against amplification attacks in order to enhance the overall network performance and security, reducing the likelihood of such attacks disrupting network services. In accordance with an embodiment, the multiple is a fraction. By using a fraction as the multiple allows for more granular control over the size of the response packets relative to the tokens received. Moreover, the multiple of the fraction is used to provide flexibility in managing network resources, ensuring efficient data transmission, and reducing the risk of network congestion or overload. Therefore, by using the fraction as the multiple allows for precise control over the response sizes, ensuring that the network can manage responses efficiently without overloading. By adjusting the response size to a fraction of the tokens received, the system 100 can prevent excessive data transmission, reduce latency, and optimize resource usage.

[0051] Advantageously, by bounding the response size to the number of tokens received, the system 100 is configured to prevent the receiver node from sending disproportionately large responses, which could be exploited in amplification attacks. Moreover, the token counter can be configured to aggregate tokens based on either the number of packets or the total number of bytes in order to provide flexibility for managing the responses and to ensure efficient network management, such as by preventing unnecessary data transmission with reduced risk of network congestion or overload. The system 100 is configured to adapt to network conditions by adjusting the token aggregation and response generation processes based on real-time network metrics that enhance overall network performance and network security. In addition, the system 100 is used to provide a robust defence against amplification attacks by aligning the number and size of response packets with the tokens received from the sender node 102, which reduces the likelihood of amplification attacks that could disrupt network services. Therefore, the system 100 is configured to ensure a secure, efficient, and adaptable network control protocol that mitigates the risks associated with amplification attacks.

[0052] FIG. 2 is a flowchart depicting a method for performing amplification attack mitigation in a data communication network control protocol comprising steps carried out at a receiver node of the network, in accordance with an embodiment of the present disclosure. With reference to FIG. 2, there is shown a flowchart of a method 200 for performing amplification attack mitigation in a data communication network control protocols comprising steps carried out at the receiver node 112 of the network. The method 200 includes steps 202 to 210.

[0053] There is provided the method 200 of performing amplification attack mitigation in the data communications network implementing network control protocols, comprising steps carried out at the receiver node 112 of the network. The amplification attacks exploit network control protocols by generating large volumes of response data from small requests, leading to network inefficiencies and vulnerabilities. Therefore, the method 200 is used to mitigate the amplification attack by controlling the size and rate of the responses based on a token mechanism with an improved, robust, and enhanced network security and data management.

[0054] At step 202, the method 200 includes receiving a set of one or more token messages from the sender node 102 of the network. The set of one or more token messages is used to track and control the size of subsequent responses. At step 204, the method 200 includes updating a token counter based on the received set of one or more token messages and further includes receiving a packet from the sender node 102, such as at step 206. the token counter is updated by the receiver node 112 in order to ensure that the responses generated by the receiver node 112 are proportional to the tokens received, thereby preventing amplification attacks that can exploit network control protocols, such as by triggering large responses from small requests. At step 208, the method 200 includes generating a set of one or more response packets such that the size of the response is bounded by the number of tokens specified in the token counter. By generating response packets with the size that is bounded by the number of tokens in the token counter is helpful for preventing amplification attacks. At step 210, the method 200 includes sending the one or more response packets to the sender node 102. The transmission of the one or more response packets to the sender node 102 by the receiver node 112 allows an exchange of the data and to maintain an active and responsive network, ensuring that the sender node 102 receives the necessary data or acknowledgements from the receiver node 112 that is further used to prevent potential amplification attacks and ensures efficient data transmission.

[0055] Advantageously, by bounding the response size to the number of tokens received, the method 200 is used to prevent the receiver node 112 from sending disproportionately large responses, which could be exploited in amplification attacks. Moreover, the token counter can be configured to aggregate tokens based on either the number of packets or the total number of bytes in order to provide flexibility for managing the responses and to ensure efficient network management, such as by preventing unnecessary data transmission with reduced risk of network congestion or overload. The method 200 is used to adapt to network conditions by adjusting the token aggregation and response generation processes based on real-time network metrics that enhance overall network performance and network security. In addition, the method 200 provides a robust defence against amplification attacks by aligning the number and size of response packets with the tokens received from the sender node 102, which reduces the likelihood of amplification attacks that could disrupt network services. Therefore, the method 200 is used to ensure a secure, efficient, and adaptable network control protocol that mitigates the risks associated with amplification attacks.

[0056] The steps 202 to 210 are only illustrative, and other alternatives can also be provided where one or more steps are added, one or more steps are removed, or one or more steps are provided in a different sequence without departing from the scope of the claims herein.

[0057] There is provided a computer program comprising instructions that, when executed by a computer system, cause the computer system to implement the method 200. In an example, the instructions are implemented on the computer-readable media, which include, but are not limited to, Electrically Erasable Programmable Read-Only Memory (EEPROM), Random Access Memory (RAM), Read-Only Memory (ROM), Hard Disk Drive (HDD), Flash memory, a Secure Digital (SD) card, Solid-State Drive (SSD), a computer-readable storage medium, and / or CPU cache memory.

[0058] FIG. 3 is a flowchart depicting a method for comprising steps carried out at a sender node of a network, in accordance with an embodiment of the present disclosure. With reference to FIG. 3, there is shown a flowchart of a method 300 for operating the sender node 102 (of FIG. 1). The method 300 includes steps 302 to 306.

[0059] At step 302, the method 300 includes sending a set of one or more token messages to the receiver node 112 of the network. Moreover, the receiver node 112 updates a token counter based on the received set of one or more token messages. By sending token messages to the receiver node 112 and updating the token counter, the method 300 is used to ensure that the receiver node 112 can accurately track the number of tokens received, which helps in controlling the size and number of response packets in order to mitigate the amplification attack. At step 304, the method 300 includes sending a packet to the receiver node 112. Moreover, the receiver node 112 generates a set of one or more response packets such that the size of the response is bounded by the number of tokens specified in the token counter and at step 306, the method 300 includes receiving one or more response packets from the receiver node 112. In an implementation, the sender node 102 sends the data packet to the receiver node 112. Upon receiving the data packet, the receiver node 112 uses the token counter to determine the size of the response packets. Thereafter, the receiver node 112 generates a set of one or more response packets, ensuring that the total size of the response is within the bounds specified by the token counter and sends the generated response packets back to the sender node 102. Finally, the sender node 102 receives the response packets from the receiver node 112. As a result, the generation of the response packets based on the token counter is used to control the data transmission and prevent amplification attacks.

[0060] Advantageously, the method 300 of performing amplification attack mitigation is used to prevent the receiver node 112 from sending disproportionately large responses, effectively mitigating the risk of amplification attacks through a flexible token aggregation mechanism that can be configured to count either the number of packets or the total bytes received, allowing for tailored management of response sizes by bounding the response size to the number of tokens received. The method 300 is also used to enhance the overall network efficiency by preventing unnecessary data transmission, thus reducing the risk of network congestion or overload. Additionally, the method 300 can dynamically adapt to network conditions by adjusting token aggregation and response generation processes based on real-time network metrics, which enhances overall network performance and security. Furthermore, by aligning the number and size of response packets with the tokens received from the sender node 102, the method 300 provides a robust defence against amplification attacks, significantly reducing the likelihood of such attacks disrupting network services. Therefore, the method 300 is used to ensure a secure, efficient, and adaptable network control protocol that mitigates the risks associated with amplification attacks.

[0061] The steps 302 to 306 are only illustrative, and other alternatives can also be provided where one or more steps are added, one or more steps are removed, or one or more steps are provided in a different sequence without departing from the scope of the claims herein.

[0062] There is provided a computer program comprising instructions that, when executed by a computer system, cause the computer system to implement the method 300. In an example, the instructions are implemented on the computer-readable media, which include, but are not limited to, Electrically Erasable Programmable Read-Only Memory (EEPROM), Random Access Memory (RAM), Read-Only Memory (ROM), Hard Disk Drive (HDD), Flash memory, a Secure Digital (SD) card, Solid-State Drive (SSD), a computer-readable storage medium, and / or CPU cache memory. FIG. 4 is a diagram that depicts mitigation of the amplification attack by using token messages with a single receiver node, in accordance with an embodiment of the present disclosure. FIG.4 is described in conjunction with elements from FIGs. 1, 2, and 3. With reference to FIG. 4, there is shown a flowchart 400 that includes a series of operations from 402 to 412.

[0063] In an implementation scenario, the sender node 102 is configured to send a request to the receiver node 112 (or a destination node). At operation 402 and operation 404, the sender node 102 is configured to send a set of one or more token messages that precede the packet that triggers the response. Thereafter, the receiver node 112 is configured to count the number of tokens (i.e., either the number of packets or the number of bytes) transmitted by the sender node 102. Further, at operation 406, the sender node 102 is configured to send the request packet, which also causes the receiver node 112 to update the tokens. Furthermore, at operations 408, 410, and 412, the receiver node 112 is configured to send one or more response messages, so that the size of the response is bounded by the number of tokens. Therefore, depending upon whether the tokens are used to count packets or to count bytes, the receiver node 112 either limits the number of packets in the response or limits the number of bytes, thereby mitigating the risk of amplification attack.

[0064] FIG. 5 is a diagram that depicts mitigation of the amplification attack by using token messages with multiple intermediate nodes and a receiver node, in accordance with an embodiment of the present disclosure. FIG.5 is described in conjunction with elements from FIGs. 1, 2, and 3. With reference to FIG. 5, there is shown a flowchart 500 that includes a series of operations from 506 to 516. Furthermore, there is shown a first intermediate node 502, a second intermediate node 504, the sender node 102, and the receiver node 112.

[0065] In an implementation scenario, the sender node 102 is configured to send a request to the receiver node 112 (or a destination node). At operation 506 and operation 508, the sender node 102 is configured to send a set of one or more token messages that precede the packet that triggers the response. Thereafter, the receiver node 112 is configured to count the number of tokens (i.e., either the number of packets or the number of bytes) transmitted by the sender node 102. Further, at operation 510, the sender node 102 is configured to send the request packet, which also causes the receiver node 112 to update the tokens. Furthermore, at operation 512, 514, and 516, the first intermediate node 502, the second intermediate node 504, and the receiver node 112 are respectively configured to send one or more response messages, so that the size of the response is bounded by the number of tokens. In an implementation, the intermediate node or the receiver node 112 is configured to limit the corresponding responses to the number of aggregated tokens multiplied by alpha (e.g., tokens*alpha). For example, the first intermediate node 502, the second intermediate node 504, and the receiver node 112 are configured to send the corresponding responses independently. Thus, if alpha=l / 3, then, in that case, each node (i.e., the first intermediate node 502, the second intermediate node 504, and the receiver node 112) generates a response that is 1 / 3 of the tokens received, causing the total number and length of responses to be balanced with the requests sent by the sender node 102. Moreover, the constant alpha is configurable and can be configured by a central controller based on the prior knowledge of the topology (e.g., number of hops) and can be configured based on a dynamic mechanism that learns the number of hops and configures alpha accordingly. Therefore, depending upon whether the tokens are used to count packets or to count bytes, the receiver node 112 either limits the number of packets in the response or limits the number of bytes, thereby mitigating the risk of amplification attack.

[0066] Modifications to embodiments of the present disclosure described in the foregoing are possible without departing from the scope of the present disclosure as defined by the accompanying claims. Expressions such as "including", "comprising", "incorporating", "have", "is" used to describe, and claim the present disclosure are intended to be construed in a non-exclusive manner, namely allowing for items, components or elements not explicitly described also to be present. Reference to the singular is also to be construed to relate to the plural. The word "exemplary" is used herein to mean "serving as an example, instance or illustration". Any embodiment described as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments or to exclude the incorporation of features from other embodiments. The word "optionally" is used herein to mean "is provided in some embodiments and not provided in other embodiments". It is appreciated that certain features of the present disclosure, which are, for clarity, described in the context of separate embodiments, may also be provided in combination in a single embodiment. Conversely, various features of the disclosure, which are, for brevity, described in the context of a single embodiment, may also be provided separately or in any suitable combination or as suitable in any other described embodiment of the disclosure.

Claims

CLAIMS1. A method (200) of performing amplification attack mitigation in a data communications network implementing network control protocols, comprising steps, carried out at a receiver node (112) of the network, of: receiving a set of one or more token messages from a sender node (102) of the network; updating a token counter based on the received set of one or more token messages; receiving a packet from the sender node (102); generating a set of one or more response packets such that the size of the response is bounded by the number of tokens specified in the token counter; and sending the one or more response packets to the sender node (102).

2. The method (200) of claim 1, wherein the generating a set of one or more response packets is carried out by counting a number of tokens in the set of one or more token messages according to the number of packets received from the sender node (102).

3. The method (200) of claim 2, wherein the generating a set of one or more response packets is carried out by counting a number of tokens in the set of one or more token messages according to the number of bytes received from the sender node (102).

4. The method (200) of claim 3, wherein the one or more response packets is an amplified response.

5. The method (200) of claim 1, wherein the receiver node (112) is an intermediate node in the network.

6. The method (200) of claim 2, wherein each packet received from the sender node (102) causes one token to be aggregated at the receiver node (112).

7. The method (200) of claim 2, wherein each packet received from the sender node (102) causes n tokens to be aggregated at the receiver node (112), where n is an integer greater than 1.

8. The method (200) of claim 1, wherein the set of one or more response packets is based on a multiple of the number of tokens specified in the token counter.

9. The method (200) of claim 8, wherein the value of the multiple is configurable.

10. The method (200) of claim 9, wherein the value of the multiple is configurable based on prior knowledge of the topology of the network.

11. The method (200) of claim 9, wherein the value of the multiple is configured based on a dynamic mechanism that learns the topology of the network and configures the fraction in accordance with the learned topology of the network.

12. The method (200) of claim 1, wherein the packet received from the sender node (102) includes the set of one or more token messages.

13. A method (300) of performing amplification attack mitigation in a data communications network implementing network control protocols, comprising steps, carried out at a sender node (102) of the network, of: sending a set of one or more token messages to a receiver node (112) of the network; wherein the receiver node (112) updates a token counter based on the received set of one or more token messages; sending a packet to the receiver node (112), wherein the receiver node (112) generates a set of one or more response packets such that the size of the response is bounded by the number of tokens specified in the token counter; and receiving the one or more response packets from the receiver node (112).

14. A system (100) comprising means adapted for carrying out all the steps of the method (200, 300) according to any preceding method (200,300) claim.

15. A computer program comprising instructions for carrying out all the steps of the method (200, 300) according to any preceding method (200,300) claim, when said computer program is executed on a computer system.

Citation Information

Patent Citations

  • Network amplification attack mitigation

    EP1592197A2