DDOS Attack Redirection via Remote Mitigation Tools

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous systems lacking threat mitigation systems face challenges in managing Distributed Denial of Service (DDOS) attacks, as they cannot locally process and filter packets, leading to potential overload and service disruption.

Innovation Solution

Implementing a system where a first network device in an autonomous system modifies packet addresses to redirect service requests to a second autonomous system with threat mitigation capabilities, allowing the first system to offload processing and mitigate attacks by sending packets to a scrubbing center for filtering, and then returning responses to the original request source.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If an autonomous system lacks threat mitigation systems, then device complexity is reduced, but the system becomes vulnerable to DDOS attacks and cannot filter packets locally

Engineering Contradiction:
Improvethreat mitigation systemVSAvoidattack resistance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a second autonomous system with threat mitigation capabilities as an intermediary. When the first autonomous system detects a DDOS attack or exceeds load thresholds, it redirects packets to the second system for filtering and processing. The second system acts as a mediator that handles threat mitigation while the first system maintains its simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If packets are redirected to another autonomous system for processing, then threat mitigation capability is improved, but network latency and complexity increase

Engineering Contradiction:
Improvethreat mitigation capabilityVSAvoidnetwork architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts its operation mode based on conditions. The first autonomous system normally processes packets locally but switches to redirecting to the second system when attacked or overloaded. This dynamic behavior allows the network to maintain simplicity under normal conditions while gaining threat mitigation capabilities when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The second autonomous system serves multiple functions: it acts as a threat mitigation system for the first autonomous system, provides load balancing capabilities, and can handle packets from multiple sources. This multi-functionality justifies the added network complexity by providing diverse benefits.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If all packets are processed locally in the first autonomous system, then network simplicity is maintained, but the system becomes overloaded during DDOS attacks

Engineering Contradiction:
Improvenetwork structureVSAvoidpacket processing capacity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments the packet processing function between two autonomous systems. The first system handles normal traffic and local processing, while the second system handles threat mitigation and overloaded traffic. This segmentation allows each system to specialize and prevents any single system from becoming overwhelmed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The second autonomous system serves as an intermediary processing center that the first system can utilize when overloaded. Packets are redirected to this intermediary system for filtering and processing, effectively expanding the overall packet processing capacity without requiring the first system to handle everything alone.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If the first autonomous system redirects packets to the second system, then load distribution is improved, but packet modification and routing complexity increase

Engineering Contradiction:
Improveload distributionVSAvoidpacket routing logic
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The packet routing logic is dynamic rather than static. The first autonomous system monitors its load and attack conditions, then dynamically decides whether to process packets locally or redirect to the second system. This dynamic approach optimizes load distribution while minimizing unnecessary routing complexity during normal operation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240372892A1Systems and methods to redirect DDOS attack using remote mitigation tools
Publication Date: 2024.11.07 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US20240372892A1 patent drawing
  • US20240372892A1 patent drawing
  • US20240372892A1 patent drawing

AI summary

Distributed denial of service (DDOS) attacks may occur in various networks and may target any of various servers. A DDOS attack on a server in a first autonomous system may be launched from within another autonomous system, or from within the same autonomous system. Some autonomous systems may include threat mitigations systems, whereas some autonomous system may lack threat mitigations systems. As such, systems and methods to redirect DDOS attack using remote mitigation tools are provided.