Anycast Mitigation Network for DDoS Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for mitigating distributed denial of service (DDoS) attacks are inadequate, as they fail to effectively distinguish between legitimate and malicious traffic, leading to network paralysis and significant financial losses, with existing security measures like firewalls and intrusion detection systems unable to provide comprehensive protection against sophisticated attacks.
Innovation Solution
Implementing a method that uses a group of mitigation devices with anycast addresses to receive and process traffic, removing malicious traffic while forwarding legitimate traffic back to the customer device, utilizing techniques such as dynamic filtering and GRE tunneling to ensure uninterrupted service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional perimeter security technologies (firewalls, IDS) are used, then basic security protection is provided, but they cannot effectively mitigate sophisticated DDoS attacks
Solution Approach 1:
The system segments DDoS mitigation into multiple specialized components: anycast routing distributes traffic across geographically dispersed mitigation devices, dynamic filtering separates malicious from legitimate traffic, and GRE tunneling redirects cleaned traffic back to customers. This segmentation allows each component to specialize in specific mitigation tasks, achieving comprehensive protection against sophisticated attacks that single-device firewalls cannot handle.
2Object-affected harmful factors
If blackholing and router filtering are used, then some attack traffic is blocked, but legitimate traffic may also be affected and business continuity is not ensured
Solution Approach 1:
The system introduces GRE tunneling as an intermediary mechanism between the anycast mitigation devices and customer devices. Legitimate traffic that passes through the mitigation devices is encapsulated in GRE tunnels and forwarded back to customers, ensuring business continuity. This intermediary approach allows aggressive filtering at the anycast nodes without impacting legitimate service delivery.
3Object-affected harmful factors
If overprovisioning is used to protect against larger attacks, then adequate protection is provided, but the cost becomes far too high
Solution Approach 1:
The system merges multiple mitigation devices into a coordinated anycast network, combining their collective filtering capabilities to handle large-scale attacks. Rather than each customer provisioning excessive individual capacity, the shared anycast infrastructure distributes and aggregates mitigation resources, providing scalable protection against ever-larger attacks at reasonable cost.
4Device complexity
If a single mitigation device is used, then simple architecture is maintained, but traffic distribution and redundancy are insufficient
Solution Approach 1:
The anycast address serves as a universal entry point that automatically routes traffic to appropriate mitigation devices based on network conditions. This multi-functional anycast mechanism provides both load distribution and failover redundancy without requiring complex manual configuration, maintaining architectural simplicity while achieving high reliability through the BGP-based anycast routing infrastructure.
Data Source
AI summary
A mitigation service may be used to mitigate a network attack in a network including a group of mitigation devices. Datagrams, intended for a customer that is subject of a network attack, may be received by at least one of the mitigation devices based on an anycast address associated with the mitigation devices. Each of the mitigation devices is addressable via the anycast address. The received datagrams may be processed to remove malicious datagrams and leave legitimate datagrams. The legitimate datagrams may be forwarded to the customer via a tunnel configured between an address associated with the customer and the anycast address associated with the mitigation devices.


