Commodity Server Shim Layer for Data Center Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hardware devices used for detecting and mitigating attacks in data centers are inadequate due to high costs, inflexibility, limited effectiveness against sophisticated attacks, and potential for collateral damage, especially under high-volume DDoS attacks.
Innovation Solution
A system utilizing commodity servers to implement a distributed 'shim' layer within the data center architecture, which generates and aggregates traffic flow summaries to detect both inbound and outbound attacks, allowing for near real-time mitigation strategies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If commercial hardware devices (firewalls, IDS, DDoS protection appliances) are deployed at the network level, then attack detection capability is improved, but device cost and procurement complexity increase significantly
Solution Approach 1:
The patent replaces expensive commercial hardware devices with commodity hardware appliances that can be deployed in large numbers. Each commodity appliance performs basic attack detection functions, and multiple appliances work together to provide comprehensive protection. This approach trades individual device cost for system-scale effectiveness, allowing the data center to handle attacks that would overwhelm single expensive devices.
Solution Approach 2:
The patent divides the attack detection function across multiple commodity appliances rather than relying on a few expensive devices. Each appliance handles specific traffic flows or attack types, and their collective capability provides comprehensive protection. This segmentation allows parallel processing of attack detection tasks and improves overall system capacity without requiring any single device to be overly complex or expensive.
2Productivity
If hardware devices are deployed to handle high-volume DDoS attacks, then attack mitigation capacity is improved, but operational cost increases due to redundancy requirements
Solution Approach 1:
The commodity hardware appliances are designed to perform multiple functions: attack detection, attack mitigation, and traffic forwarding. Each appliance can handle various types of attacks (DDoS, intrusion attempts, malware detection) and can be dynamically configured based on threat levels. This multi-functionality reduces the need for specialized expensive hardware for each attack type, allowing a single class of device to handle diverse threats.
Solution Approach 2:
The system implements automated attack detection and mitigation without requiring manual intervention or complex human management. The commodity appliances automatically detect attacks, analyze traffic patterns, and apply mitigation strategies. This self-service capability reduces operational overhead and allows the system to scale without proportionally increasing management complexity or human resources.
3Adaptability or versatility
If proprietary software is used in hardware devices, then device functionality is improved, but operational flexibility and adaptability to new attack types deteriorate
Solution Approach 1:
The patent replaces proprietary closed software systems with open-source software running on commodity hardware. The open-source nature allows operators to inspect, modify, and adapt the software to handle new attack types. This substitution of proprietary mechanisms with open, modifiable software provides both adaptability to emerging threats and operational flexibility to customize detection and mitigation strategies based on specific data center needs.
4Measurement precision
If traffic is redirected to scrubbers for deep packet inspection, then attack detection accuracy is improved, but detection time and response latency increase causing collateral damage
Solution Approach 1:
The patent implements a two-stage detection approach where commodity appliances first perform rapid initial assessment of traffic using lighter-weight inspection methods. Only traffic that fails this initial check or exhibits suspicious patterns is then subjected to more intensive deep packet inspection. This partial action approach maintains high detection accuracy for malicious traffic while allowing legitimate traffic to pass through with minimal delay, avoiding collateral damage from excessive inspection latency.
Data Source
Figure 1
Figure 2
Figure 3~5
AI summary
Described herein are various technologies pertaining to identification of inbound and outbound network and application attacks with respect to a data center. Commodity servers are used to monitor ingress and egress traffic flows, and anomalies are detected in the traffic flows. Responsive to detecting an anomaly, a mitigation strategy is executed to mitigate damage caused by a cyber-attack.