Bunker Data Centers Absorb DDoS Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data centers in telecommunications networks are vulnerable to distributed denial of service (DDOS) attacks, which overwhelm applications with traffic, making it difficult to distinguish between legitimate and malicious packets, leading to reduced availability and reliability.
Innovation Solution
Implementing a system with redundant 'bunker' data centers that absorb and process traffic intended for primary data centers during attacks, using scrubbing applications to identify and filter out malicious packets, and routing legitimate packets to the primary data centers, while distributing applications across multiple centers to balance load.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data centers host applications to provide network services, then service availability is improved, but vulnerability to DDOS attacks increases
Solution Approach 1:
The patent divides the data center infrastructure into separate functional components: primary data centers that host applications and bunker data centers that provide redundancy. This segmentation allows the system to isolate attack impacts and maintain service availability even when primary centers are compromised by DDOS attacks.
Solution Approach 2:
The patent implements bunker data centers as pre-positioned redundant infrastructure that can activate when primary data centers are attacked. These bunker centers are prepared in advance with identical application configurations, enabling them to absorb DDOS traffic and maintain service availability without requiring real-time reconstruction of backup systems.
2Object-affected harmful factors
If scrubbing applications filter malicious packets, then attack mitigation is improved, but processing complexity increases
Solution Approach 1:
The patent introduces scrubbing applications as intermediary components positioned between the network and data center infrastructure. These scrubbers analyze and filter malicious packets before they reach the data centers, absorbing the complexity of attack detection and mitigation while protecting the core infrastructure from direct exposure to harmful traffic patterns.
Solution Approach 2:
The patent extracts the packet filtering and attack detection functions from the data center core infrastructure and places them in separate scrubbing applications. This extraction allows the scrubbing complexity to be isolated in dedicated components while keeping the data center infrastructure simpler and more focused on service delivery.
3Productivity
If applications are distributed across multiple data centers, then load balancing is improved, but system complexity increases
Solution Approach 1:
The patent designs bunker data centers with universal functionality to mirror primary data centers, enabling them to perform identical application hosting functions. This universality simplifies the distribution architecture by using standardized, interchangeable components rather than requiring specialized infrastructure for different functions.
Solution Approach 2:
The patent creates replicated copies of data center infrastructure and applications in bunker centers, allowing traffic to be distributed across identical templates. This copying approach simplifies load balancing by using uniform structures that can be automatically replicated and scaled without requiring complex heterogeneous system management.
Data Source
AI summary
Aspects of the present disclosure involve systems, methods, computer program products, and the like, for data center redundancy in relation to a computer network. In particular, the present disclosure provides for one or more available redundant data centers, or bunkers, associated with a computer network. In one embodiment, the bunker data centers are configured to absorb traffic intended for an application operating on a data center when the traffic threatens to overwhelm the application. For example, during a distributed denial of service (DDOS) attack, the bunker data centers are configured to absorb some of the traffic from the DDOS attack to prevent the application that is the target of the attack from being overwhelmed.


