Container Migration for DDoS Mitigation in Cloud Frameworks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for reducing network latency between software containers are resource-intensive and expensive, and can facilitate denial of service attacks, often requiring high-capacity equipment that becomes a bottleneck in data centers.

Innovation Solution

A system that dynamically migrates software applications based on tracking metrics, such as communication frequency and latency, to optimize proximity and prevent denial of service threats by determining threat levels and performing actions like migration, throttling, or quarantining applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If applications are migrated to be closer in proximity to reduce network latency, then communication efficiency is improved, but the risk of facilitating denial of service attacks increases

Engineering Contradiction:
Improvenetwork latencyVSAvoiddenial of service attack risk
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a container migration service as an intermediary between applications and the physical infrastructure. This service evaluates communication metrics and threat levels before migrating containers, acting as a mediator that balances latency reduction with security protection. The service prevents direct migration that could expose applications to denial of service attacks while still enabling proximity optimization when safe.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary evaluation of communication frequency and threat levels before executing container migration. By assessing metrics in advance and determining threat levels, the system takes preliminary protective action to prevent denial of service attacks while enabling latency optimization when conditions are safe, resolving the contradiction between speed and security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional techniques filter all network traffic through a central point to identify and filter out bad traffic, then security is improved, but resource consumption and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the security evaluation function from a centralized filtering point and distributes it to individual container migration decisions. Instead of routing all traffic through a central filtering point, the system evaluates communication metrics at the source (container level) and makes migration decisions locally, reducing the resource burden on centralized equipment while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The container migration service performs self-service security evaluation by monitoring its own communication metrics and determining its own threat level. Each container's traffic patterns are evaluated independently without requiring external centralized filtering, reducing resource consumption while maintaining security through autonomous decision-making.

Inventive Principle:
Principle #25Self-service

3Reliability

If high-capacity dedicated equipment is deployed to filter network traffic, then security filtering capability is improved, but device complexity and space requirements increase

Engineering Contradiction:
Improvesecurity filtering capabilityVSAvoidequipment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The container migration service performs multiple functions using a single system: it optimizes communication latency, evaluates security threat levels, makes migration decisions, and prevents denial of service attacks. This multi-functional approach eliminates the need for separate high-capacity dedicated filtering equipment, reducing device complexity and space requirements while maintaining security capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If container migration is performed to optimize communication proximity, then communication efficiency is improved, but the system becomes more vulnerable to denial of service attacks

Engineering Contradiction:
Improvecommunication efficiencyVSAvoiddenial of service threat
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The system continuously monitors communication frequency and determines threat levels based on feedback from observed traffic patterns. This feedback mechanism enables the system to adjust migration decisions dynamically - enabling proximity optimization when communication patterns are normal and preventing migration when threat levels indicate potential denial of service attacks, thus resolving the contradiction between efficiency and vulnerability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12034740B1Distributed denial of service mitigation in a container based framework
Publication Date: 2024.07.09 AMAZON TECH INC
  • US12034740B1 patent drawing
  • US12034740B1 patent drawing
  • US12034740B1 patent drawing

AI summary

In response to a process being triggered, at least in part by receipt of information regarding communication directed to a first application by a second application, a threat level is computed based at least in part on the information. As a result of the threat level being of a first severity, the second application is migrated to a destination zone that allows for improved communications with the first application. As a result of the threat level being of a second severity, migration of the second application to the destination zone is delayed. As a result of the threat level being of a third severity, a mitigation action is performed.