Anycast IP Prefix Segmentation for Volumetric Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing traffic and controlling load across multiple scrubbing centers is challenging, especially when handling traffic for many different customers, as it is difficult to effectively thwart attacks while minimizing performance degradation for other customers.

Innovation Solution

The system employs an anycast IP prefix scheme, where multiple infrastructure deployments are associated with a group of anycasted IP prefixes, and DNS servers select IP addresses to distribute traffic load. During an attack, the targeted IP address is removed from the DNS selection pool, and BGP advertisements are altered to redirect traffic, thereby mitigating the attack and minimizing collateral damage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traffic engineering communities or AS path prepend are used to manage inbound traffic, then load distribution across scrubbing centers is attempted, but the complexity increases and safety issues arise

Engineering Contradiction:
Improveload distribution efficiencyVSAvoidtraffic management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the anycast IP prefix into multiple individual IP addresses that are advertised from different scrubbing centers. This segmentation allows independent control of traffic to each scrubbing center without requiring complex traffic engineering communities or AS path prepend operations, thereby reducing overall system complexity while maintaining load distribution capability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If scrubbing centers handle traffic for many different customers, then attack mitigation capability is improved, but performance degradation for non-affected customers increases

Engineering Contradiction:
Improveattack mitigation effectivenessVSAvoidcustomer service performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by making scrubbing center availability customer-specific through selective BGP advertisement. Each scrubbing center can be independently advertised to specific customers based on their attack risk profiles, allowing attack mitigation for targeted customers while maintaining normal service performance for others who are not currently under attack.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If the targeted IP address is removed from DNS selection pool during attack, then attack traffic is contained, but traffic redistribution control becomes more difficult

Engineering Contradiction:
Improveattack traffic containmentVSAvoidtraffic redistribution control
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements dynamics by making the set of advertised IP addresses flexible and changeable. The system can dynamically add or remove individual IP addresses from BGP advertisements based on real-time attack conditions, providing granular control over traffic redistribution without requiring complex DNS manipulation, thus ease of operation is maintained while attack containment is achieved.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250168194A1Mitigation of Volumetric Attacks With Controlled Traffic Spreading and Load Balancing
Publication Date: 2025.05.22 AKAMAI TECHNOLOGIES INC
  • US20250168194A1 patent drawing
  • US20250168194A1 patent drawing

AI summary

Techniques for managing inbound traffic and/or mitigating volumetric attacks are disclosed. A preparatory phase can involve configuring an IP addressing scheme to associate multiple infrastructure deployments with a group of anycasted IP prefixes, and advertising each of those anycasted IP prefixes as reachable from each deployment. A DNS server answers queries for a domain name with an IP address from one of the IP prefixes in the group, preferably selecting such that each anycast IP prefix gets substantially equal share of the load. An attack mitigation phase can involve defending against an attack by removing the IP prefix that is under attack from the group of anycasted IP prefixes, among other things. In another embodiment, a group of several IP addresses from a single IP prefix is used, with the DNS selecting amongst the IP addresses to spread the load.