Data Plane DDoS Detector Circuit for Network Forwarding Elements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
DDoS attacks pose a significant challenge due to their ability to overload network resources, causing service disruptions and data breaches, with increasing complexity and scale, and existing detection and mitigation solutions struggle to keep pace with exponentially growing network traffic.
Innovation Solution
A forwarding element with a data plane circuit configured to implement a DDoS attack detector, which includes a storage for tracked destinations, a statistics generator, and a statistics analyzer to estimate unique message flows, generating a DDoS attack signal when thresholds are exceeded, allowing for proactive mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional DDoS detection and mitigation solutions are used, then DDoS attack detection capability is provided, but the solution takes long to scale and is expensive as network traffic grows exponentially
Solution Approach 1:
The patent applies preliminary action by pre-configuring the data plane with DDoS detection circuits and tracking storages before attacks occur. The system proactively monitors traffic patterns and unique flow counts in advance, enabling rapid response when thresholds are exceeded without requiring complex real-time analysis during attack events.
Solution Approach 2:
The patent replaces traditional mechanical/conventional detection systems with a streamlined data-plane-based detection mechanism. By embedding detection circuits directly in the data plane and using hardware-efficient counting methods, the system achieves faster scaling and lower operational costs compared to traditional software-based approaches.
2Productivity
If network traffic volume increases exponentially, then network capacity and service availability are improved, but DDoS detection complexity and cost increase significantly
Solution Approach 1:
The patent segments the detection function into discrete components within the data plane: tracking storages for destinations and sources, counting circuits for unique flows, and threshold comparison logic. This modular segmentation allows the system to handle high traffic volumes by processing detection tasks in parallel across multiple independent counting units without increasing overall system complexity.
Solution Approach 2:
The patent changes the detection parameter from complex multi-field analysis to simplified counter-based measurement. By monitoring only essential parameters such as unique flow counts and threshold violations, the system maintains low detection complexity even as network traffic volume scales exponentially.
3Measurement precision
If comprehensive DDoS detection is implemented, then attack detection accuracy is improved, but processing time and resource consumption increase
Solution Approach 1:
The patent extracts only the essential detection functions from comprehensive analysis, focusing solely on counting unique flows and monitoring threshold violations. By taking out and implementing only these critical functions in the data plane, the system achieves high detection accuracy for DDoS attacks without the processing overhead of more comprehensive but less effective detection methods.
Data Source
AI summary
Some embodiments of the invention provide a forwarding element that has a data-plane circuit (data plane) that can be configured to implement a DDoS (distributed denial of service) attack detector. The data plane has several stages of configurable data processing circuits, which are typically configured to process data tuples associated with data messages received by the forwarding element in order to forward the data messages within a network. In some embodiments, the configurable data processing circuits of the data plane can also be configured to implement a DDoS attack detector (DDoS detector) in the data plane. In some embodiments, the forwarding element has a control-plane circuit (control plane) that configures the configurable data processing circuits of the data plane, while in other embodiments, a remote controller configures these data processing circuits.


