DDoS Handling Device Load Distribution via Dynamic Path Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current DDoS attack mitigation technologies face challenges in distributing resource loads among locations without increasing communication delay, especially when attack origins are concentrated, leading to resource shortages and inefficiencies.
Innovation Solution
A DDoS handling device that utilizes a load distribution determination unit, load distribution processing unit, and attack handling setting unit to dynamically reroute communication paths through available mitigating locations, optimizing resource utilization and minimizing delay by selecting paths with comparable latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If communication is routed to a mitigation location in a remote region different from the original communication path, then resource load is distributed among locations, but communication delay increases
Solution Approach 1:
The patent applies local quality by selecting mitigation locations based on the specific characteristics of each attack flow, including the origin AS, target AS, and entry gateway. Instead of using a single remote mitigation location for all attacks, the system routes each attack to the most appropriate mitigation location that can handle the attack while minimizing delay for that specific traffic flow.
Solution Approach 2:
The patent implements dynamics by dynamically selecting mitigation locations based on real-time attack characteristics and network conditions. The mitigation location selection is not static but adapts to the specific attack scenario, changing the routing path based on the origin AS, target AS, and entry gateway of each attack flow to optimize both load distribution and delay performance.
2Adaptability or versatility
If multiple mitigation locations are deployed globally to handle attacks from different regions, then resource availability increases, but system complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the global mitigation network into multiple regional mitigation locations, each responsible for handling attacks from specific regions or ASes. This segmentation allows the system to distribute attack handling across multiple locations, improving resource availability while managing complexity through clear division of responsibilities.
Solution Approach 2:
The patent uses an intermediary mechanism (the anycast routing system and BGP path control) that simplifies the complexity of managing multiple mitigation locations. Instead of requiring complex direct routing configurations between all components, the anycast system acts as an intermediary that automatically directs traffic to appropriate mitigation locations based on network conditions and attack characteristics.
3Speed
If IP anycast is used to route communication to the closest mitigation location, then communication delay is minimized, but resource concentration occurs when attack origins are concentrated in a specific region
Solution Approach 1:
The patent applies parameter changes by modifying the routing parameters (BGP paths) dynamically based on attack characteristics. Instead of always using the closest mitigation location determined by anycast, the system changes the routing parameters to direct traffic to mitigation locations that have adequate resource capacity, balancing delay optimization with load distribution.
Solution Approach 2:
The patent implements dynamics by making the mitigation location selection adaptive rather than static. The system dynamically adjusts which mitigation location handles each attack based on real-time conditions including resource availability at each location, origin AS, target AS, and entry gateway, preventing resource concentration while maintaining efficient routing.
Data Source
AI summary
A DDoS handling device configured to handle communication directed to a target of a DDoS attack flowing in from an adjacent autonomous system in an autonomous system provided with a plurality of mitigating locations includes: a load distribution determination unit configured to determine whether or not to execute load distribution processing on the basis of an amount of available resources at mitigating locations corresponding to a gateway device into which the communication directed to the target flows and an amount of the communication directed to the target in a case in which at least one attack has been detected; a load distribution processing unit configured to decide mitigating locations to be used to handle the communication directed to the target from among the plurality of mitigating locations to solve shortage of resources at the mitigating locations for each attack, in a case in which the load distribution determination unit determines to execute the load distribution processing; and an attack handling setting unit configured to execute path control such that the communication directed to the target pertaining to the attack passes through the mitigating locations decided by the load distribution processing unit for each attack.


