Container Migration for DDoS Mitigation in Cloud Frameworks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for reducing network latency between software containers are resource-intensive and expensive, and can facilitate denial of service attacks, often requiring high-capacity equipment that becomes a bottleneck in data centers.
Innovation Solution
A system that dynamically migrates software applications based on tracking metrics, such as communication frequency and latency, to optimize proximity and prevent denial of service threats by determining threat levels and performing actions like migration, throttling, or quarantining applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If applications are migrated to be closer in proximity to reduce network latency, then communication efficiency is improved, but the risk of facilitating denial of service attacks increases
Solution Approach 1:
The patent introduces a container migration service as an intermediary between applications and the physical infrastructure. This service evaluates communication metrics and threat levels before migrating containers, acting as a mediator that balances latency reduction with security protection. The service prevents direct migration that could expose applications to denial of service attacks while still enabling proximity optimization when safe.
Solution Approach 2:
The system performs preliminary evaluation of communication frequency and threat levels before executing container migration. By assessing metrics in advance and determining threat levels, the system takes preliminary protective action to prevent denial of service attacks while enabling latency optimization when conditions are safe, resolving the contradiction between speed and security.
2Reliability
If conventional techniques filter all network traffic through a central point to identify and filter out bad traffic, then security is improved, but resource consumption and cost increase
Solution Approach 1:
The patent extracts the security evaluation function from a centralized filtering point and distributes it to individual container migration decisions. Instead of routing all traffic through a central filtering point, the system evaluates communication metrics at the source (container level) and makes migration decisions locally, reducing the resource burden on centralized equipment while maintaining security.
Solution Approach 2:
The container migration service performs self-service security evaluation by monitoring its own communication metrics and determining its own threat level. Each container's traffic patterns are evaluated independently without requiring external centralized filtering, reducing resource consumption while maintaining security through autonomous decision-making.
3Reliability
If high-capacity dedicated equipment is deployed to filter network traffic, then security filtering capability is improved, but device complexity and space requirements increase
Solution Approach 1:
The container migration service performs multiple functions using a single system: it optimizes communication latency, evaluates security threat levels, makes migration decisions, and prevents denial of service attacks. This multi-functional approach eliminates the need for separate high-capacity dedicated filtering equipment, reducing device complexity and space requirements while maintaining security capability.
4Productivity
If container migration is performed to optimize communication proximity, then communication efficiency is improved, but the system becomes more vulnerable to denial of service attacks
Solution Approach 1:
The system continuously monitors communication frequency and determines threat levels based on feedback from observed traffic patterns. This feedback mechanism enables the system to adjust migration decisions dynamically - enabling proximity optimization when communication patterns are normal and preventing migration when threat levels indicate potential denial of service attacks, thus resolving the contradiction between efficiency and vulnerability.
Data Source
AI summary
In response to a process being triggered, at least in part by receipt of information regarding communication directed to a first application by a second application, a threat level is computed based at least in part on the information. As a result of the threat level being of a first severity, the second application is migrated to a destination zone that allows for improved communications with the first application. As a result of the threat level being of a second severity, migration of the second application to the destination zone is delayed. As a result of the threat level being of a third severity, a mitigation action is performed.


