Commodity Server Shim Layer for Data Center Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware devices used for detecting and mitigating attacks in data centers are inadequate due to high costs, inflexibility, limited effectiveness against sophisticated attacks, and potential for collateral damage, especially under high-volume DDoS attacks.

Innovation Solution

A system utilizing commodity servers to implement a distributed 'shim' layer within the data center architecture, which generates and aggregates traffic flow summaries to detect both inbound and outbound attacks, allowing for near real-time mitigation strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If commercial hardware devices (firewalls, IDS, DDoS protection appliances) are deployed at the network level, then attack detection capability is improved, but device cost and procurement complexity increase significantly

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddevice procurement and deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces expensive commercial hardware devices with commodity hardware appliances that can be deployed in large numbers. Each commodity appliance performs basic attack detection functions, and multiple appliances work together to provide comprehensive protection. This approach trades individual device cost for system-scale effectiveness, allowing the data center to handle attacks that would overwhelm single expensive devices.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent divides the attack detection function across multiple commodity appliances rather than relying on a few expensive devices. Each appliance handles specific traffic flows or attack types, and their collective capability provides comprehensive protection. This segmentation allows parallel processing of attack detection tasks and improves overall system capacity without requiring any single device to be overly complex or expensive.

Inventive Principle:
Principle #1Segmentation

2Productivity

If hardware devices are deployed to handle high-volume DDoS attacks, then attack mitigation capacity is improved, but operational cost increases due to redundancy requirements

Engineering Contradiction:
Improveattack mitigation capacityVSAvoidnumber of hardware devices required
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The commodity hardware appliances are designed to perform multiple functions: attack detection, attack mitigation, and traffic forwarding. Each appliance can handle various types of attacks (DDoS, intrusion attempts, malware detection) and can be dynamically configured based on threat levels. This multi-functionality reduces the need for specialized expensive hardware for each attack type, allowing a single class of device to handle diverse threats.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements automated attack detection and mitigation without requiring manual intervention or complex human management. The commodity appliances automatically detect attacks, analyze traffic patterns, and apply mitigation strategies. This self-service capability reduces operational overhead and allows the system to scale without proportionally increasing management complexity or human resources.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If proprietary software is used in hardware devices, then device functionality is improved, but operational flexibility and adaptability to new attack types deteriorate

Engineering Contradiction:
Improveadaptability to new attack typesVSAvoidoperational flexibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent replaces proprietary closed software systems with open-source software running on commodity hardware. The open-source nature allows operators to inspect, modify, and adapt the software to handle new attack types. This substitution of proprietary mechanisms with open, modifiable software provides both adaptability to emerging threats and operational flexibility to customize detection and mitigation strategies based on specific data center needs.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If traffic is redirected to scrubbers for deep packet inspection, then attack detection accuracy is improved, but detection time and response latency increase causing collateral damage

Engineering Contradiction:
Improveattack detection accuracyVSAvoiddetection time and response latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a two-stage detection approach where commodity appliances first perform rapid initial assessment of traffic using lighter-weight inspection methods. Only traffic that fails this initial check or exhibits suspicious patterns is then subjected to more intensive deep packet inspection. This partial action approach maintains high detection accuracy for malicious traffic while allowing legitimate traffic to pass through with minimal delay, avoiding collateral damage from excessive inspection latency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3178216B1Data center architecture that supports attack detection and mitigation
Publication Date: 2020.04.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3178216B1 patent drawingFigure 1
  • EP3178216B1 patent drawingFigure 2
  • EP3178216B1 patent drawingFigure 3~5

AI summary

Described herein are various technologies pertaining to identification of inbound and outbound network and application attacks with respect to a data center. Commodity servers are used to monitor ingress and egress traffic flows, and anomalies are detected in the traffic flows. Responsive to detecting an anomaly, a mitigation strategy is executed to mitigate damage caused by a cyber-attack.