Automated Route Management for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing network routing, especially during DDoS attacks, are inefficient, lack scalability, and provide inadequate context for business managers, often relying on unqualified administrators and lacking historical data for route management.

Innovation Solution

A graphical user interface interacts with a Web server to update a configuration file, which is converted into router management commands and sent to border routers, providing automated and timely routing changes, central control, and logging of all routing updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual login to router is used to change routing rules, then network accessibility can be maintained during attack, but the method does not scale and lacks efficiency

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidresponse efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

An automated route management system acts as an intermediary between network administrators and border routers. The system receives routing change requests, automatically generates the necessary configuration commands, and pushes them to multiple border routers simultaneously, eliminating the need for manual router login while maintaining network accessibility during attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The route management system enables self-service automation where routing changes are automatically generated and deployed without human intervention in the actual router configuration process. The system monitors network conditions, determines necessary routing adjustments, and executes them autonomously across multiple routers, significantly improving response efficiency while maintaining reliability.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If fragmented team of network administrators manages multiple border routers, then network control is distributed, but junior administrators without proper certifications put the network at risk

Engineering Contradiction:
Improvedistributed network controlVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The automated route management system serves as a controlled intermediary that sits between administrators and router configuration. It implements authentication and authorization mechanisms to verify administrator credentials and certifications before allowing routing changes. The system validates commands and maintains an audit trail, ensuring that only qualified personnel can make network changes while distributing operational ease across the team.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If manual routing management is used, then network changes can be made, but little historical data is captured making it difficult to manage route injection over time

Engineering Contradiction:
Improverouting change capabilityVSAvoidhistorical routing data
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The route management system implements comprehensive feedback mechanisms that automatically capture, store, and analyze routing change history. Every routing modification is logged with timestamps, administrator identifiers, and change details. This historical data is retained in a structured format, enabling retrospective analysis, audit compliance, and improved route injection management over time while maintaining ease of operational routing changes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11032138B2Managing traffic control in a network mitigating DDOS
Publication Date: 2021.06.08 LEVEL 3 COMMUNICATIONS LLC
  • US11032138B2 patent drawing
  • US11032138B2 patent drawing
  • US11032138B2 patent drawing

AI summary

Embodiments are provided for managing routes of data traffic within a network. The management may be performed via a graphical user interface that interacts with a Web server to update a configuration file. The configuration file can be converted to router management commands by a network management device (e.g., a BGP speaker). The commands can then be sent to a border routers for controlling network traffic. Embodiments are also provided for capturing and logging routing updates made in a network.