BGP-Based DDoS Mitigation via User-Generated Filter Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current defense techniques against DDoS attacks, such as traffic scrubbing, ACL filters, BGP blackholing, and BGP FlowSpec, are inadequate due to high costs, limited scalability, coarse granularity, and the need for network cooperation, and lack effective feedback on attack status.

Innovation Solution

A computer-implemented method that receives user-generated filter rules via BGP signals, calculates a desired system state, translates these rules into hardware-specific configurations, and activates filtering mechanisms in router hardware to block malicious traffic, allowing for fine-granular filtering without third-party cooperation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic scrubbing services are used to filter malicious traffic, then filter quality is improved, but running costs and performance delays increase

Engineering Contradiction:
Improvefilter qualityVSAvoidrunning costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system enables self-service by allowing affected users to autonomously generate and distribute filter rules through BGP signals without requiring centralized traffic scrubbing services. The routing server automatically processes these rules and propagates them to autonomous systems, eliminating the need for expensive external filtering infrastructure while maintaining effective attack mitigation.

Inventive Principle:
Principle #25Self-service

2Reliability

If ACL filters are manually configured to block malicious traffic, then filtering effectiveness is improved, but scalability and ease of operation deteriorate

Engineering Contradiction:
Improvefiltering effectivenessVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by pre-configuring filter rules in the routing server before attacks occur. When attacks are detected, the pre-established BGP signal mechanism immediately distributes the appropriate filter rules to affected autonomous systems, eliminating the need for manual real-time configuration and enabling rapid scalable response to diverse attack scenarios.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If BGP blackholing is implemented to stop attack traffic, then attack mitigation is improved, but network availability and service accessibility deteriorate

Engineering Contradiction:
Improveattack mitigationVSAvoidservice unavailability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by implementing fine-grained filtering that targets only the specific malicious traffic flows identified in user-generated filter rules. Unlike coarse blackholing that blocks all traffic to a destination, this approach selectively filters attack traffic while allowing legitimate services to remain accessible, achieving localized mitigation without broad service disruption.

Inventive Principle:
Principle #3Local quality

4Ease of operation

If fine-granular filtering is implemented without third-party cooperation, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveindependence from third-party cooperationVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system achieves universality by designing a multi-functional BGP-based architecture where the routing server simultaneously performs multiple roles: receiving user filter rules, calculating desired system states, translating rules into routing configurations, and propagating signals to autonomous systems. This universal approach enables fine-grained filtering without requiring specialized third-party infrastructure or complex point-to-point configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11122076B2Method for defending against or mitigating DDoS attacks on IT infrastructures
Publication Date: 2021.09.14 DE CIX MANAGEMENT GMBH
  • US11122076B2 patent drawing
  • US11122076B2 patent drawing
  • US11122076B2 patent drawing

AI summary

The disclosure relates to computer-based communication systems, such as the Internet, and in particular systems and methods for defending against DoS attacks (denial of service attacks) on Internet servers.