Scalable Cloud Protection Service for Network Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for protecting online services against denial of service attacks, especially for small and medium-scale services, are costly and reactive, often relying on third-party protection services that are ineffective against application-level attacks and have significant response times, leading to substantial downtime and financial damage.
Innovation Solution
Implementing a scalable protection service using dynamically scalable virtual machines hosted by a cloud service, which redirects network traffic from public to private links, processing and filtering malicious traffic while forwarding legitimate traffic, thereby reducing costs and response times.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party protection services are used to protect against denial of service attacks, then protection effectiveness is improved, but response time deteriorates (measured in tens of minutes or hours)
Solution Approach 1:
The patent implements preliminary action by pre-configuring protection services and establishing private network links before attacks occur. The system proactively sets up filtering rules, scales virtual machine resources, and establishes private links between protection services and online services in advance, enabling immediate response when attacks are detected without waiting for third-party services to react.
2Reliability
If sufficient network infrastructure is deployed to handle volumetric attacks (100-300 Gbps), then protection capability is improved, but cost deteriorates (cost prohibitive for small and medium-scale services)
Solution Approach 1:
The patent applies dynamics by implementing dynamically scalable virtual machine resources that can automatically adjust capacity based on attack intensity. The system scales computational resources up during attacks and down during normal operation, transforming static infrastructure costs into flexible, demand-based resource allocation that is cost-effective for services of all scales.
Solution Approach 2:
The protection service infrastructure is designed to handle multiple types of attacks (volumetric, application-level, partial handshakes) through a unified platform. The same virtual machine resources and filtering mechanisms provide universal protection across different attack vectors, eliminating the need for separate specialized infrastructure for each threat type.
3Reliability
If generic third-party protection services are used, then protection against volumetric attacks is improved, but protection against application-level attacks deteriorates (online services still left vulnerable)
Solution Approach 1:
The patent implements local quality by deploying protection services in close proximity to each online service through private network links. Each protection service can be customized with service-specific filtering rules and configurations tailored to the particular online service's characteristics, application protocols, and legitimate traffic patterns, enabling effective protection against application-level attacks while maintaining volumetric attack defense.
4Reliability
If manual re-routing of network traffic to third-party protection service is implemented, then protection is activated, but response time deteriorates (overall response time measured in tens of minutes or hours)
Solution Approach 1:
The system implements feedback mechanisms that continuously monitor network traffic patterns and automatically detect attacks in real-time. When attacks are detected, the feedback loop triggers automatic response actions including activating protection services, scaling resources, and filtering malicious traffic without requiring manual intervention, reducing response time from tens of minutes to near-real-time automatic response.
Data Source
AI summary
Techniques for protecting an online service against network-based attacks are described. In some cases, protection is performed by way of a scalable protection service including a dynamically scalable set of virtual machines hosted by a cloud service that is distinct from a data center that hosts the online service. The protection service is coupled to the online service via a private link. When an attack is detected by the online service, network traffic bound for the online service is redirected from the public network to the protection service. The protection service then processes the network traffic, such as by dropping network traffic associated with the attack and forwarding legitimate network traffic to the online service via the private link.


