Infrastructure DDoS Protection Using Anycast GRE Tunnels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DDoS protection systems require a minimum number of IP addresses and manual network administration, making them inaccessible to smaller organizations, and existing cloud-based solutions either lack capacity or break firewall configurations, while on-premises solutions are inadequate against sophisticated attacks.

Innovation Solution

A DDoS protection module utilizing a virtual GRE tunnel with scrubbing centers that employ anycasting and spoofed IP addresses to provide DDoS protection for networks with as few as a single IP address, ensuring redundancy and transparency while handling traffic through a globally distributed CDN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional infrastructure protection services are used, then DDoS protection is provided, but a minimum number of IP addresses (256) is required and manual network administration is needed

Engineering Contradiction:
ImproveDDoS protectionVSAvoidAccessibility to small organizations
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system provides universal DDoS protection that works for organizations of any size, from single IP address to large networks. The anycasting infrastructure and automated GRE tunnel establishment make the service universally accessible without requiring minimum IP allocations or manual network administration expertise.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary DDoS protection service layer between the organization's network and the Internet. This intermediary handles the complexity of DDoS mitigation, anycasting, and tunnel management, allowing small organizations to access enterprise-grade protection without needing in-house expertise.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud-based solutions are used, then DDoS protection capacity is improved, but firewall configurations are broken and client IP addresses are hidden

Engineering Contradiction:
ImproveDDoS protection capacityVSAvoidFirewall configuration breaking
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system creates a copy of the organization's network traffic through GRE tunneling, sending replicated traffic through the DDoS protection infrastructure while maintaining the original traffic flow. This copying approach allows inspection and filtering of malicious traffic without breaking existing firewall configurations or hiding client IP addresses from legitimate applications.

Inventive Principle:
Principle #26Copying

3Ease of operation

If on-premises solutions are used, then network control is maintained, but capacity to handle sophisticated attacks is insufficient

Engineering Contradiction:
ImproveNetwork controlVSAvoidAttack handling capacity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges on-premises network control with cloud-based DDoS protection capacity by establishing GRE tunnels from the organization's edge router to scrubbing centers. This combination allows organizations to maintain full control over their network infrastructure while leveraging the massive attack handling capacity of the cloud-based anycasting infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If manual GRE tunnel establishment is required, then dedicated connectivity to scrubbing centers is achieved, but network administration complexity increases

Engineering Contradiction:
ImproveDedicated connectivityVSAvoidNetwork administration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service automation where the DDoS protection infrastructure automatically establishes GRE tunnels with customer networks without requiring manual network administration. The anycasting mechanism and automated tunnel provisioning eliminate the need for customers to manually configure connectivity to multiple scrubbing centers, making the service accessible to organizations without specialized network administration skills.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12407719B2Infrastructure distributed denial of service protection
Publication Date: 2025.09.02 IMPERVA INC
  • US12407719B2 patent drawing
  • US12407719B2 patent drawing
  • US12407719B2 patent drawing

AI summary

A method of providing infrastructure protection for a server of a network organization, the method including announcing, as an internet protocol (IP) address associated with a server of a plurality of servers, a first anycast IP address, the first anycast IP address being one of a plurality of anycast IP addresses that each serve as an anycast address for a scrubbing center network. Each of the plurality of anycast IP addresses is allocated to a respective server of the plurality of servers by the scrubbing center network. The scrubbing center network may receive an incoming network packet intended for the server, the incoming network packet identified using the first anycast IP address. The scrubbing center network may determine whether the incoming network packet is legitimate and if so, the incoming network packet may be routed to the server using a generic routing encapsulation (GRE) tunnel.