Client Route Control System for DDoS Attack Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional DDoS defense technologies fail to effectively identify and isolate the IP of network problem-causing clients, leading to service disruptions and increased costs due to excessive blocking of legitimate users and inefficiencies in managing network traffic during DDoS attacks.

Innovation Solution

A client route control system that allocates unique routes to each client using multiple edge servers, allowing for real-time identification and isolation of problem-causing clients by monitoring network issues and re-routing traffic through pre-designated edge servers, thereby maintaining continuous service and reducing the impact of DDoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If conventional DDoS defense technologies (honey pots, Null Routing, IP blocking) are used to block attacks, then attack traffic is blocked, but legitimate users are also blocked and attack sources cannot be identified

Engineering Contradiction:
ImproveDDoS attack trafficVSAvoidService availability for legitimate users
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system segments the network path into multiple independent routes between clients and servers. Each client is assigned a unique route through specific edge servers, allowing individual identification and isolation of problem clients without affecting others. This segmentation enables precise control over traffic flow and attack mitigation while preserving service for legitimate users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces edge servers as intermediaries between clients and the target server. These edge servers act as mediators that can monitor, detect, and control client traffic. When a problem client is detected, the edge server can block its traffic without requiring broad IP blocking that would affect legitimate users. The intermediary enables fine-grained traffic management and attack source identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If broad IP ranges or network lines are blocked to prevent DDoS attacks, then attack sources are blocked, but service continuity is disrupted and costs increase

Engineering Contradiction:
ImproveAttack trafficVSAvoidService continuity
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

By dividing the network into multiple segmented routes with dedicated edge servers, the system can isolate and block individual problem clients without disrupting service to other clients. Each client's traffic is handled by specific edge servers, enabling granular control that prevents broad blocking and maintains service continuity for legitimate users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different quality control measures to different clients based on their specific behavior. Problem clients receive blocking action at their specific edge server, while legitimate clients continue uninterrupted service. This localized approach to traffic control maintains overall service reliability while effectively mitigating attacks from specific sources.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If honey pots are used to detect attack sources, then attack detection is possible, but response time is delayed and honey pots become useless against network line overflow attacks

Engineering Contradiction:
ImproveAttack source detectionVSAvoidResponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-assigning specific edge servers to each client before attacks occur. This pre-established routing structure enables immediate identification of problem clients when attacks happen, eliminating the need for time-consuming detection processes. The preliminary route assignment allows instant localization of attack sources and rapid response without service disruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Edge servers serve as intermediaries that continuously monitor client traffic and can immediately identify problem clients when abnormal patterns are detected. This real-time monitoring capability through intermediary edge servers enables rapid response to attacks, eliminating the delayed response inherent in honey pot systems. The intermediary structure allows immediate detection and isolation of attack sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3160086B1Method and system for detecting failure-inducing client by using client route control system
Publication Date: 2019.10.09 SEO CO LTD
  • EP3160086B1 patent drawingFigure 1
  • EP3160086B1 patent drawingFigure 2
  • EP3160086B1 patent drawingFigure 3

AI summary

Provided are a method and a system for identifying an IP of a DDoS attack orderer by using a client route control server. A method for detecting a network problem-causing client by using a client route control server includes: forming an edge server IP allocation matrix; checking a network problem occurrence in an edge server; allocating an edge server IP according to the edge server IP allocation matrix when a network problem occurs in an edge server; and detecting user information or a client IP, which has no edge server IP to be allocated according to the edge server IP allocation matrix, as a network problem-causing client, wherein an edge server IP is allocated differently for each user information or client IP in the edge server IP allocation matrix, and the edge server IP allocation is performed by at least two-stage edge server IP for each user information or client IP.