Cyber Attack Mitigation Coordination Across DDoS Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DDoS protection services often lack mutual visibility and coordination, leading to ineffective mitigation strategies when multiple services are involved, resulting in issues like routing loops and inappropriate traffic handling, especially when managed by distinct administrative entities.
Innovation Solution
A method and device that coordinate mitigation plans across multiple DDoS protection services by detecting incompatibilities and adjusting incompatible plans to ensure effective and compatible traffic handling, allowing for real-time resolution of cyber attacks targeting computing domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple DDoS protection services are deployed to protect computing domain resources, then the coverage and capability of attack mitigation is improved, but the complexity of coordinating and managing these services increases
Solution Approach 1:
The patent introduces a coordinator as an intermediary entity that manages communication and coordination between multiple DDoS protection services. This coordinator receives attack detection information from various protection services, processes the information, and sends coordinated mitigation instructions to the appropriate services, thereby reducing the complexity of direct multi-service coordination.
Solution Approach 2:
The system pre-establishes communication protocols and coordination mechanisms between multiple protection services before an attack occurs. The coordinator is pre-configured with the necessary information about available protection services and their capabilities, enabling rapid coordinated response when an attack is detected without requiring real-time negotiation.
2Reliability
If protection services are managed by distinct administrative entities without mutual visibility, then operational independence and security are improved, but the effectiveness of combined mitigation actions deteriorates
Solution Approach 1:
The coordinator acts as a neutral intermediary that enables information exchange between protection services managed by different administrative entities. It receives attack information from one service, processes it, and forwards appropriate mitigation instructions to other services without requiring direct trust or visibility between the administrative entities themselves.
Solution Approach 2:
The patent segments the coordination function from the protection services themselves. The coordinator is a separate entity that handles the coordination logic, allowing each protection service to maintain its operational independence while still contributing to coordinated mitigation efforts through standardized information exchange protocols.
3Object-affected harmful factors
If filtering policies are implemented to isolate attack traffic, then the ability to block harmful traffic is improved, but the risk of creating routing loops and blocking legitimate traffic increases
Solution Approach 1:
The system implements feedback mechanisms where protection services continuously monitor the effects of their filtering policies and report back to the coordinator. When routing loops or unintended blocking of legitimate traffic is detected, the coordinator receives this feedback and adjusts the mitigation instructions sent to the protection services to resolve the issues.
Solution Approach 2:
The filtering policies are made dynamic rather than static. The coordinator continuously updates mitigation instructions based on real-time conditions, adjusting filter criteria and routing rules to adapt to changing network states and attack characteristics, thereby reducing the risk of routing loops and unnecessary traffic blocking.
Data Source
AI summary
A method for coordinating mitigation of a cyber attack, an associated device and system. The coordination method is implemented by a device managing resources in a computing domain, wherein the resources are protected by a plurality of services protecting against cyber attacks. The method includes: producing mitigation plans implemented by protection services from the plurality of protection services in response to a cyber attack targeting at least one of the resources in the computing domain; and following a detection of at least one incompatibility between the mitigation plans produced, coordinating an adjustment to all or some of the incompatible mitigation plans, among the protection services that have implemented the incompatible mitigation plans, so as to eliminate the incompatibility.


