Anycast IP Prefix Segmentation for Volumetric Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing traffic and controlling load across multiple scrubbing centers is challenging, especially when handling traffic for many different customers, as it is difficult to effectively thwart attacks while minimizing performance degradation for other customers.
Innovation Solution
The system employs an anycast IP prefix scheme, where multiple infrastructure deployments are associated with a group of anycasted IP prefixes, and DNS servers select IP addresses to distribute traffic load. During an attack, the targeted IP address is removed from the DNS selection pool, and BGP advertisements are altered to redirect traffic, thereby mitigating the attack and minimizing collateral damage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traffic engineering communities or AS path prepend are used to manage inbound traffic, then load distribution across scrubbing centers is attempted, but the complexity increases and safety issues arise
Solution Approach 1:
The patent segments the anycast IP prefix into multiple individual IP addresses that are advertised from different scrubbing centers. This segmentation allows independent control of traffic to each scrubbing center without requiring complex traffic engineering communities or AS path prepend operations, thereby reducing overall system complexity while maintaining load distribution capability.
2Reliability
If scrubbing centers handle traffic for many different customers, then attack mitigation capability is improved, but performance degradation for non-affected customers increases
Solution Approach 1:
The patent applies local quality by making scrubbing center availability customer-specific through selective BGP advertisement. Each scrubbing center can be independently advertised to specific customers based on their attack risk profiles, allowing attack mitigation for targeted customers while maintaining normal service performance for others who are not currently under attack.
3Object-affected harmful factors
If the targeted IP address is removed from DNS selection pool during attack, then attack traffic is contained, but traffic redistribution control becomes more difficult
Solution Approach 1:
The patent implements dynamics by making the set of advertised IP addresses flexible and changeable. The system can dynamically add or remove individual IP addresses from BGP advertisements based on real-time attack conditions, providing granular control over traffic redistribution without requiring complex DNS manipulation, thus ease of operation is maintained while attack containment is achieved.
Data Source
AI summary
Techniques for managing inbound traffic and/or mitigating volumetric attacks are disclosed. A preparatory phase can involve configuring an IP addressing scheme to associate multiple infrastructure deployments with a group of anycasted IP prefixes, and advertising each of those anycasted IP prefixes as reachable from each deployment. A DNS server answers queries for a domain name with an IP address from one of the IP prefixes in the group, preferably selecting such that each anycast IP prefix gets substantially equal share of the load. An attack mitigation phase can involve defending against an attack by removing the IP prefix that is under attack from the group of anycasted IP prefixes, among other things. In another embodiment, a group of several IP addresses from a single IP prefix is used, with the DNS selecting amongst the IP addresses to spread the load.

