DDOS Attack Redirection via Remote Mitigation Tools
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Autonomous systems lacking threat mitigation systems face challenges in managing Distributed Denial of Service (DDOS) attacks, as they cannot locally process and filter packets, leading to potential overload and service disruption.
Innovation Solution
Implementing a system where a first network device in an autonomous system modifies packet addresses to redirect service requests to a second autonomous system with threat mitigation capabilities, allowing the first system to offload processing and mitigate attacks by sending packets to a scrubbing center for filtering, and then returning responses to the original request source.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If an autonomous system lacks threat mitigation systems, then device complexity is reduced, but the system becomes vulnerable to DDOS attacks and cannot filter packets locally
Solution Approach 1:
The patent introduces a second autonomous system with threat mitigation capabilities as an intermediary. When the first autonomous system detects a DDOS attack or exceeds load thresholds, it redirects packets to the second system for filtering and processing. The second system acts as a mediator that handles threat mitigation while the first system maintains its simplicity.
2Reliability
If packets are redirected to another autonomous system for processing, then threat mitigation capability is improved, but network latency and complexity increase
Solution Approach 1:
The system dynamically adjusts its operation mode based on conditions. The first autonomous system normally processes packets locally but switches to redirecting to the second system when attacked or overloaded. This dynamic behavior allows the network to maintain simplicity under normal conditions while gaining threat mitigation capabilities when needed.
Solution Approach 2:
The second autonomous system serves multiple functions: it acts as a threat mitigation system for the first autonomous system, provides load balancing capabilities, and can handle packets from multiple sources. This multi-functionality justifies the added network complexity by providing diverse benefits.
3Device complexity
If all packets are processed locally in the first autonomous system, then network simplicity is maintained, but the system becomes overloaded during DDOS attacks
Solution Approach 1:
The patent segments the packet processing function between two autonomous systems. The first system handles normal traffic and local processing, while the second system handles threat mitigation and overloaded traffic. This segmentation allows each system to specialize and prevents any single system from becoming overwhelmed.
Solution Approach 2:
The second autonomous system serves as an intermediary processing center that the first system can utilize when overloaded. Packets are redirected to this intermediary system for filtering and processing, effectively expanding the overall packet processing capacity without requiring the first system to handle everything alone.
4Productivity
If the first autonomous system redirects packets to the second system, then load distribution is improved, but packet modification and routing complexity increase
Solution Approach 1:
The packet routing logic is dynamic rather than static. The first autonomous system monitors its load and attack conditions, then dynamically decides whether to process packets locally or redirect to the second system. This dynamic approach optimizes load distribution while minimizing unnecessary routing complexity during normal operation.
Data Source
AI summary
Distributed denial of service (DDOS) attacks may occur in various networks and may target any of various servers. A DDOS attack on a server in a first autonomous system may be launched from within another autonomous system, or from within the same autonomous system. Some autonomous systems may include threat mitigations systems, whereas some autonomous system may lack threat mitigations systems. As such, systems and methods to redirect DDOS attack using remote mitigation tools are provided.


