Data Plane DDoS Detector Circuit for Network Forwarding Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

DDoS attacks pose a significant challenge due to their ability to overload network resources, causing service disruptions and data breaches, with increasing complexity and scale, and existing detection and mitigation solutions struggle to keep pace with exponentially growing network traffic.

Innovation Solution

A forwarding element with a data plane circuit configured to implement a DDoS attack detector, which includes a storage for tracked destinations, a statistics generator, and a statistics analyzer to estimate unique message flows, generating a DDoS attack signal when thresholds are exceeded, allowing for proactive mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DDoS detection and mitigation solutions are used, then DDoS attack detection capability is provided, but the solution takes long to scale and is expensive as network traffic grows exponentially

Engineering Contradiction:
ImproveDDoS attack detection capabilityVSAvoidscaling speed and cost efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-configuring the data plane with DDoS detection circuits and tracking storages before attacks occur. The system proactively monitors traffic patterns and unique flow counts in advance, enabling rapid response when thresholds are exceeded without requiring complex real-time analysis during attack events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical/conventional detection systems with a streamlined data-plane-based detection mechanism. By embedding detection circuits directly in the data plane and using hardware-efficient counting methods, the system achieves faster scaling and lower operational costs compared to traditional software-based approaches.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If network traffic volume increases exponentially, then network capacity and service availability are improved, but DDoS detection complexity and cost increase significantly

Engineering Contradiction:
Improvenetwork capacityVSAvoidDDoS detection complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the detection function into discrete components within the data plane: tracking storages for destinations and sources, counting circuits for unique flows, and threshold comparison logic. This modular segmentation allows the system to handle high traffic volumes by processing detection tasks in parallel across multiple independent counting units without increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the detection parameter from complex multi-field analysis to simplified counter-based measurement. By monitoring only essential parameters such as unique flow counts and threshold violations, the system maintains low detection complexity even as network traffic volume scales exponentially.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive DDoS detection is implemented, then attack detection accuracy is improved, but processing time and resource consumption increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the essential detection functions from comprehensive analysis, focusing solely on counting unique flows and monitoring threshold violations. By taking out and implementing only these critical functions in the data plane, the system achieves high detection accuracy for DDoS attacks without the processing overhead of more comprehensive but less effective detection methods.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11750622B1Forwarding element with a data plane DDoS attack detector
Publication Date: 2023.09.05 BAREFOOT NETWORKS INC
  • US11750622B1 patent drawing
  • US11750622B1 patent drawing
  • US11750622B1 patent drawing

AI summary

Some embodiments of the invention provide a forwarding element that has a data-plane circuit (data plane) that can be configured to implement a DDoS (distributed denial of service) attack detector. The data plane has several stages of configurable data processing circuits, which are typically configured to process data tuples associated with data messages received by the forwarding element in order to forward the data messages within a network. In some embodiments, the configurable data processing circuits of the data plane can also be configured to implement a DDoS attack detector (DDoS detector) in the data plane. In some embodiments, the forwarding element has a control-plane circuit (control plane) that configures the configurable data processing circuits of the data plane, while in other embodiments, a remote controller configures these data processing circuits.