Infrastructure DDoS Protection Using Anycast GRE Tunnels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DDoS protection systems require a minimum number of IP addresses and manual network administration, making them inaccessible to smaller organizations, and existing cloud-based solutions either lack capacity or break firewall configurations, while on-premises solutions are inadequate against sophisticated attacks.
Innovation Solution
A DDoS protection module utilizing a virtual GRE tunnel with scrubbing centers that employ anycasting and spoofed IP addresses to provide DDoS protection for networks with as few as a single IP address, ensuring redundancy and transparency while handling traffic through a globally distributed CDN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional infrastructure protection services are used, then DDoS protection is provided, but a minimum number of IP addresses (256) is required and manual network administration is needed
Solution Approach 1:
The system provides universal DDoS protection that works for organizations of any size, from single IP address to large networks. The anycasting infrastructure and automated GRE tunnel establishment make the service universally accessible without requiring minimum IP allocations or manual network administration expertise.
Solution Approach 2:
The patent introduces an intermediary DDoS protection service layer between the organization's network and the Internet. This intermediary handles the complexity of DDoS mitigation, anycasting, and tunnel management, allowing small organizations to access enterprise-grade protection without needing in-house expertise.
2Reliability
If cloud-based solutions are used, then DDoS protection capacity is improved, but firewall configurations are broken and client IP addresses are hidden
Solution Approach 1:
The system creates a copy of the organization's network traffic through GRE tunneling, sending replicated traffic through the DDoS protection infrastructure while maintaining the original traffic flow. This copying approach allows inspection and filtering of malicious traffic without breaking existing firewall configurations or hiding client IP addresses from legitimate applications.
3Ease of operation
If on-premises solutions are used, then network control is maintained, but capacity to handle sophisticated attacks is insufficient
Solution Approach 1:
The patent merges on-premises network control with cloud-based DDoS protection capacity by establishing GRE tunnels from the organization's edge router to scrubbing centers. This combination allows organizations to maintain full control over their network infrastructure while leveraging the massive attack handling capacity of the cloud-based anycasting infrastructure.
4Reliability
If manual GRE tunnel establishment is required, then dedicated connectivity to scrubbing centers is achieved, but network administration complexity increases
Solution Approach 1:
The system implements self-service automation where the DDoS protection infrastructure automatically establishes GRE tunnels with customer networks without requiring manual network administration. The anycasting mechanism and automated tunnel provisioning eliminate the need for customers to manually configure connectivity to multiple scrubbing centers, making the service accessible to organizations without specialized network administration skills.
Data Source
AI summary
A method of providing infrastructure protection for a server of a network organization, the method including announcing, as an internet protocol (IP) address associated with a server of a plurality of servers, a first anycast IP address, the first anycast IP address being one of a plurality of anycast IP addresses that each serve as an anycast address for a scrubbing center network. Each of the plurality of anycast IP addresses is allocated to a respective server of the plurality of servers by the scrubbing center network. The scrubbing center network may receive an incoming network packet intended for the server, the incoming network packet identified using the first anycast IP address. The scrubbing center network may determine whether the incoming network packet is legitimate and if so, the incoming network packet may be routed to the server using a generic routing encapsulation (GRE) tunnel.


