Application-Layer DDoS Mitigation Across Multi-Cloud Shared Ingress

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for addressing Layer 7 (L7) Distributed Denial of Service (DDoS) attacks in cloud computing environments are resource-intensive, time-consuming, and prone to errors due to heavy reliance on manual intervention, leading to inefficiencies and potential disruption of legitimate traffic.

Innovation Solution

An adaptive, automated system employing machine learning algorithms to detect and mitigate L7 DDoS attacks by analyzing real-time traffic patterns, implementing mitigation strategies with minimal human oversight, and transitioning between monitoring and active modes as needed, using an out-of-band approach to minimize performance impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual intervention methods are used to detect and mitigate L7 DDoS attacks, then detection can be performed, but the process becomes resource-intensive and time-consuming

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements automated self-service mechanisms where the DDOS protection system automatically detects, analyzes, and mitigates attacks without requiring manual human intervention. The system monitors traffic patterns, identifies malicious activity, and executes mitigation strategies autonomously, thereby reducing both response time and operational overhead while maintaining detection accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical intervention with automated computational systems. Machine learning models and algorithms substitute human analysts, automatically processing traffic data, identifying attack patterns, and executing mitigation actions. This substitution eliminates the time-consuming nature of manual detection while preserving or enhancing detection reliability through consistent automated analysis

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If automated mitigation strategies are implemented, then response time is reduced, but system complexity increases

Engineering Contradiction:
Improveresponse speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The automated mitigation system is segmented into distinct functional modules: traffic monitoring components, machine learning analysis engines, decision-making logic, and execution interfaces. Each module performs a specific function, allowing the complex automated system to be managed through modular components that can be independently configured, maintained, and scaled without overwhelming system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary components such as orchestration layers and abstraction interfaces that mediate between the automated detection mechanisms and mitigation execution. These intermediaries manage the complexity by providing standardized interfaces, coordinating between different automated subsystems, and handling the coordination overhead, thereby enabling fast automated response without proportionally increasing overall system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If out-of-band approach is used, then performance impact is minimized, but detection capability may be reduced

Engineering Contradiction:
Improveservice continuityVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system merges out-of-band monitoring capabilities with selective in-band inspection for suspicious traffic. While the primary approach uses out-of-band methods to minimize performance impact and maintain service continuity, the system combines this with targeted in-band analysis when anomalies are detected, thereby preserving detection accuracy without sacrificing the performance benefits of the out-of-band approach

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system applies partial in-band inspection only when necessary - specifically when out-of-band monitoring detects suspicious patterns. This partial action approach maintains service continuity through primarily non-intrusive out-of-band monitoring while applying more intensive in-band detection only to potentially malicious traffic, thereby balancing detection accuracy with performance minimization

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20260006069A1System And Methods Of Defense Against DDoS Attacks For Applications On A Multi-Substrate Multi-Ingress Shared Infrastructure With Multiple Cloud Architectures
Publication Date: 2026.01.01 SALESFORCE INC
  • US20260006069A1 patent drawing
  • US20260006069A1 patent drawing
  • US20260006069A1 patent drawing

AI summary

A computing services environment may provide computing services to a plurality of recipients via the Internet. The computing services environment may include application gateways receiving application-layer request messages from various sources. The computing services environment may also include an orchestration engine determining mitigation policies corresponding with the application gateways based on a classification of a subset of the application-layer request messages as being sent from sources associated with a distributed denial of service attack. The computing services environment may also include application-layer web application firewalls corresponding to the application gateways and being configured to transition from a deactivated state to an activated state upon receipt of an instruction from the orchestration engine. The activated application-layer web application firewalls may implement the mitigation policies prevent a subset of subsequent application-layer request messages from the subset of the sources from reaching one or more components of the computing services environment.