BGP-Based DDoS Mitigation via User-Generated Filter Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current defense techniques against DDoS attacks, such as traffic scrubbing, ACL filters, BGP blackholing, and BGP FlowSpec, are inadequate due to high costs, limited scalability, coarse granularity, and the need for network cooperation, and lack effective feedback on attack status.
Innovation Solution
A computer-implemented method that receives user-generated filter rules via BGP signals, calculates a desired system state, translates these rules into hardware-specific configurations, and activates filtering mechanisms in router hardware to block malicious traffic, allowing for fine-granular filtering without third-party cooperation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic scrubbing services are used to filter malicious traffic, then filter quality is improved, but running costs and performance delays increase
Solution Approach 1:
The system enables self-service by allowing affected users to autonomously generate and distribute filter rules through BGP signals without requiring centralized traffic scrubbing services. The routing server automatically processes these rules and propagates them to autonomous systems, eliminating the need for expensive external filtering infrastructure while maintaining effective attack mitigation.
2Reliability
If ACL filters are manually configured to block malicious traffic, then filtering effectiveness is improved, but scalability and ease of operation deteriorate
Solution Approach 1:
The system performs preliminary action by pre-configuring filter rules in the routing server before attacks occur. When attacks are detected, the pre-established BGP signal mechanism immediately distributes the appropriate filter rules to affected autonomous systems, eliminating the need for manual real-time configuration and enabling rapid scalable response to diverse attack scenarios.
3Reliability
If BGP blackholing is implemented to stop attack traffic, then attack mitigation is improved, but network availability and service accessibility deteriorate
Solution Approach 1:
The system applies local quality by implementing fine-grained filtering that targets only the specific malicious traffic flows identified in user-generated filter rules. Unlike coarse blackholing that blocks all traffic to a destination, this approach selectively filters attack traffic while allowing legitimate services to remain accessible, achieving localized mitigation without broad service disruption.
4Ease of operation
If fine-granular filtering is implemented without third-party cooperation, then ease of operation is improved, but device complexity increases
Solution Approach 1:
The system achieves universality by designing a multi-functional BGP-based architecture where the routing server simultaneously performs multiple roles: receiving user filter rules, calculating desired system states, translating rules into routing configurations, and propagating signals to autonomous systems. This universal approach enables fine-grained filtering without requiring specialized third-party infrastructure or complex point-to-point configurations.
Data Source
AI summary
The disclosure relates to computer-based communication systems, such as the Internet, and in particular systems and methods for defending against DoS attacks (denial of service attacks) on Internet servers.


