Cloud Protection Node for Internal DDoS Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DDoS prevention mechanisms are ineffective in addressing attacks between virtual machines within a cloud system, leaving cloud systems vulnerable to internal DDoS attacks.

Innovation Solution

A protection node is deployed in the cloud system to monitor data traffic, extract abnormal data streams, and send them to a traffic cleaning apparatus for cleaning, ensuring only cleaned data streams are input into virtual machines, thereby preventing both external and internal DDoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing DDoS prevention mechanisms are used, then external DDoS attacks are prevented, but internal DDoS attacks between virtual machines in the cloud system remain vulnerable

Engineering Contradiction:
ImproveDDoS attack prevention capabilityVSAvoidapplicability to internal virtual machine attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The protection node is designed to handle multiple types of DDoS attacks uniformly - both external attacks from outside the cloud system and internal attacks between virtual machines within the cloud system. The node monitors data traffic from all sources and applies consistent detection and cleaning mechanisms, making the DDoS prevention capability universally applicable across different attack scenarios without requiring separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a protection node is deployed to monitor all data traffic, then internal DDoS attacks are detected, but system complexity increases

Engineering Contradiction:
Improveinternal attack detection capabilityVSAvoidtraffic monitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The protection node functions as an intermediary component positioned between the network interface and the virtual machine. It intercepts data traffic, performs monitoring and analysis, and then forwards cleaned traffic to the virtual machine. This intermediary role allows centralized monitoring and processing of traffic patterns without requiring complex distributed monitoring across all virtual machines, simplifying the overall system architecture while maintaining effective internal attack detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2570954B1Method, device and system for preventing distributed denial of service attack in cloud system
Publication Date: 2016.03.02 HUAWEI TECH CO LTD
  • EP2570954B1 patent drawingFigure 1a~1b
  • EP2570954B1 patent drawingFigure 1c~1d
  • EP2570954B1 patent drawingFigure 2

AI summary

A method, an apparatus and a system for preventing DDos attacks in a cloud system are disclosed. The method for preventing DDos attacks in a cloud system includes: monitoring, by a protection node in a cloud computing system, data traffic input into virtual machines, where the cloud computing system includes the protection node and multiple virtual machines, and data streams communicated between the virtual machines pass through the protection node; extracting data streams to be input into virtual machines if it is detected that the data traffic input into the virtual machines is abnormal; sending the extracted data streams to a traffic cleaning apparatus for cleaning; receiving the data streams cleaned by the traffic cleaning apparatus; and inputting the cleaned data streams into the virtual machines. The technical solutions provided in the embodiments of the present invention can effectively prevent DDos attacks between virtual machines in the cloud system.