Bunker Data Centers Absorb DDoS Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data centers in telecommunications networks are vulnerable to distributed denial of service (DDOS) attacks, which overwhelm applications with traffic, making it difficult to distinguish between legitimate and malicious packets, leading to reduced availability and reliability.

Innovation Solution

Implementing a system with redundant 'bunker' data centers that absorb and process traffic intended for primary data centers during attacks, using scrubbing applications to identify and filter out malicious packets, and routing legitimate packets to the primary data centers, while distributing applications across multiple centers to balance load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data centers host applications to provide network services, then service availability is improved, but vulnerability to DDOS attacks increases

Engineering Contradiction:
Improveservice availabilityVSAvoidDDOS attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the data center infrastructure into separate functional components: primary data centers that host applications and bunker data centers that provide redundancy. This segmentation allows the system to isolate attack impacts and maintain service availability even when primary centers are compromised by DDOS attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements bunker data centers as pre-positioned redundant infrastructure that can activate when primary data centers are attacked. These bunker centers are prepared in advance with identical application configurations, enabling them to absorb DDOS traffic and maintain service availability without requiring real-time reconstruction of backup systems.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Object-affected harmful factors

If scrubbing applications filter malicious packets, then attack mitigation is improved, but processing complexity increases

Engineering Contradiction:
Improvemalicious packet filteringVSAvoidscrubbing application complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces scrubbing applications as intermediary components positioned between the network and data center infrastructure. These scrubbers analyze and filter malicious packets before they reach the data centers, absorbing the complexity of attack detection and mitigation while protecting the core infrastructure from direct exposure to harmful traffic patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the packet filtering and attack detection functions from the data center core infrastructure and places them in separate scrubbing applications. This extraction allows the scrubbing complexity to be isolated in dedicated components while keeping the data center infrastructure simpler and more focused on service delivery.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If applications are distributed across multiple data centers, then load balancing is improved, but system complexity increases

Engineering Contradiction:
Improveload balancing capabilityVSAvoiddistribution system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent designs bunker data centers with universal functionality to mirror primary data centers, enabling them to perform identical application hosting functions. This universality simplifies the distribution architecture by using standardized, interchangeable components rather than requiring specialized infrastructure for different functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates replicated copies of data center infrastructure and applications in bunker centers, allowing traffic to be distributed across identical templates. This copying approach simplifies load balancing by using uniform structures that can be automatically replicated and scaled without requiring complex heterogeneous system management.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10785257B2Data center redundancy in a network
Publication Date: 2020.09.22 LEVEL 3 COMMUNICATIONS LLC
  • US10785257B2 patent drawing
  • US10785257B2 patent drawing
  • US10785257B2 patent drawing

AI summary

Aspects of the present disclosure involve systems, methods, computer program products, and the like, for data center redundancy in relation to a computer network. In particular, the present disclosure provides for one or more available redundant data centers, or bunkers, associated with a computer network. In one embodiment, the bunker data centers are configured to absorb traffic intended for an application operating on a data center when the traffic threatens to overwhelm the application. For example, during a distributed denial of service (DDOS) attack, the bunker data centers are configured to absorb some of the traffic from the DDOS attack to prevent the application that is the target of the attack from being overwhelmed.