DDoS Handling Device Load Distribution via Dynamic Path Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DDoS attack mitigation technologies face challenges in distributing resource loads among locations without increasing communication delay, especially when attack origins are concentrated, leading to resource shortages and inefficiencies.

Innovation Solution

A DDoS handling device that utilizes a load distribution determination unit, load distribution processing unit, and attack handling setting unit to dynamically reroute communication paths through available mitigating locations, optimizing resource utilization and minimizing delay by selecting paths with comparable latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If communication is routed to a mitigation location in a remote region different from the original communication path, then resource load is distributed among locations, but communication delay increases

Engineering Contradiction:
Improveresource load distributionVSAvoidcommunication delay
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The patent applies local quality by selecting mitigation locations based on the specific characteristics of each attack flow, including the origin AS, target AS, and entry gateway. Instead of using a single remote mitigation location for all attacks, the system routes each attack to the most appropriate mitigation location that can handle the attack while minimizing delay for that specific traffic flow.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by dynamically selecting mitigation locations based on real-time attack characteristics and network conditions. The mitigation location selection is not static but adapts to the specific attack scenario, changing the routing path based on the origin AS, target AS, and entry gateway of each attack flow to optimize both load distribution and delay performance.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If multiple mitigation locations are deployed globally to handle attacks from different regions, then resource availability increases, but system complexity increases

Engineering Contradiction:
Improveresource availabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the global mitigation network into multiple regional mitigation locations, each responsible for handling attacks from specific regions or ASes. This segmentation allows the system to distribute attack handling across multiple locations, improving resource availability while managing complexity through clear division of responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses an intermediary mechanism (the anycast routing system and BGP path control) that simplifies the complexity of managing multiple mitigation locations. Instead of requiring complex direct routing configurations between all components, the anycast system acts as an intermediary that automatically directs traffic to appropriate mitigation locations based on network conditions and attack characteristics.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If IP anycast is used to route communication to the closest mitigation location, then communication delay is minimized, but resource concentration occurs when attack origins are concentrated in a specific region

Engineering Contradiction:
Improvecommunication speedVSAvoidresource concentration
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The patent applies parameter changes by modifying the routing parameters (BGP paths) dynamically based on attack characteristics. Instead of always using the closest mitigation location determined by anycast, the system changes the routing parameters to direct traffic to mitigation locations that have adequate resource capacity, balancing delay optimization with load distribution.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamics by making the mitigation location selection adaptive rather than static. The system dynamically adjusts which mitigation location handles each attack based on real-time conditions including resource availability at each location, origin AS, target AS, and entry gateway, preventing resource concentration while maintaining efficient routing.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11876831B2DDoS coping apparatus, DDoS coping method and program
Publication Date: 2024.01.16 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11876831B2 patent drawing
  • US11876831B2 patent drawing
  • US11876831B2 patent drawing

AI summary

A DDoS handling device configured to handle communication directed to a target of a DDoS attack flowing in from an adjacent autonomous system in an autonomous system provided with a plurality of mitigating locations includes: a load distribution determination unit configured to determine whether or not to execute load distribution processing on the basis of an amount of available resources at mitigating locations corresponding to a gateway device into which the communication directed to the target flows and an amount of the communication directed to the target in a case in which at least one attack has been detected; a load distribution processing unit configured to decide mitigating locations to be used to handle the communication directed to the target from among the plurality of mitigating locations to solve shortage of resources at the mitigating locations for each attack, in a case in which the load distribution determination unit determines to execute the load distribution processing; and an attack handling setting unit configured to execute path control such that the communication directed to the target pertaining to the attack passes through the mitigating locations decided by the load distribution processing unit for each attack.