Anycast Mitigation Network for DDoS Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for mitigating distributed denial of service (DDoS) attacks are inadequate, as they fail to effectively distinguish between legitimate and malicious traffic, leading to network paralysis and significant financial losses, with existing security measures like firewalls and intrusion detection systems unable to provide comprehensive protection against sophisticated attacks.

Innovation Solution

Implementing a method that uses a group of mitigation devices with anycast addresses to receive and process traffic, removing malicious traffic while forwarding legitimate traffic back to the customer device, utilizing techniques such as dynamic filtering and GRE tunneling to ensure uninterrupted service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter security technologies (firewalls, IDS) are used, then basic security protection is provided, but they cannot effectively mitigate sophisticated DDoS attacks

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoideffectiveness against sophisticated attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments DDoS mitigation into multiple specialized components: anycast routing distributes traffic across geographically dispersed mitigation devices, dynamic filtering separates malicious from legitimate traffic, and GRE tunneling redirects cleaned traffic back to customers. This segmentation allows each component to specialize in specific mitigation tasks, achieving comprehensive protection against sophisticated attacks that single-device firewalls cannot handle.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If blackholing and router filtering are used, then some attack traffic is blocked, but legitimate traffic may also be affected and business continuity is not ensured

Engineering Contradiction:
Improveattack traffic blockingVSAvoidbusiness continuity
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system introduces GRE tunneling as an intermediary mechanism between the anycast mitigation devices and customer devices. Legitimate traffic that passes through the mitigation devices is encapsulated in GRE tunnels and forwarded back to customers, ensuring business continuity. This intermediary approach allows aggressive filtering at the anycast nodes without impacting legitimate service delivery.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If overprovisioning is used to protect against larger attacks, then adequate protection is provided, but the cost becomes far too high

Engineering Contradiction:
Improveprotection capability against large attacksVSAvoidcost
Core Design Contradiction:
Object-affected harmful factorsVSQuantity of substance

Solution Approach 1:

The system merges multiple mitigation devices into a coordinated anycast network, combining their collective filtering capabilities to handle large-scale attacks. Rather than each customer provisioning excessive individual capacity, the shared anycast infrastructure distributes and aggregates mitigation resources, providing scalable protection against ever-larger attacks at reasonable cost.

Inventive Principle:
Principle #5Merging (Combining)

4Device complexity

If a single mitigation device is used, then simple architecture is maintained, but traffic distribution and redundancy are insufficient

Engineering Contradiction:
Improvearchitecture simplicityVSAvoidtraffic distribution and redundancy
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The anycast address serves as a universal entry point that automatically routes traffic to appropriate mitigation devices based on network conditions. This multi-functional anycast mechanism provides both load distribution and failover redundancy without requiring complex manual configuration, maintaining architectural simplicity while achieving high reliability through the BGP-based anycast routing infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8839427B2WAN defense mitigation service
Publication Date: 2014.09.16 VERIZON PATENT & LICENSING INC
  • US8839427B2 patent drawing
  • US8839427B2 patent drawing
  • US8839427B2 patent drawing

AI summary

A mitigation service may be used to mitigate a network attack in a network including a group of mitigation devices. Datagrams, intended for a customer that is subject of a network attack, may be received by at least one of the mitigation devices based on an anycast address associated with the mitigation devices. Each of the mitigation devices is addressable via the anycast address. The received datagrams may be processed to remove malicious datagrams and leave legitimate datagrams. The legitimate datagrams may be forwarded to the customer via a tunnel configured between an address associated with the customer and the anycast address associated with the mitigation devices.