Cyber Attack Mitigation Coordination Across DDoS Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DDoS protection services often lack mutual visibility and coordination, leading to ineffective mitigation strategies when multiple services are involved, resulting in issues like routing loops and inappropriate traffic handling, especially when managed by distinct administrative entities.

Innovation Solution

A method and device that coordinate mitigation plans across multiple DDoS protection services by detecting incompatibilities and adjusting incompatible plans to ensure effective and compatible traffic handling, allowing for real-time resolution of cyber attacks targeting computing domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple DDoS protection services are deployed to protect computing domain resources, then the coverage and capability of attack mitigation is improved, but the complexity of coordinating and managing these services increases

Engineering Contradiction:
Improveattack mitigation capabilityVSAvoidservice coordination complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a coordinator as an intermediary entity that manages communication and coordination between multiple DDoS protection services. This coordinator receives attack detection information from various protection services, processes the information, and sends coordinated mitigation instructions to the appropriate services, thereby reducing the complexity of direct multi-service coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system pre-establishes communication protocols and coordination mechanisms between multiple protection services before an attack occurs. The coordinator is pre-configured with the necessary information about available protection services and their capabilities, enabling rapid coordinated response when an attack is detected without requiring real-time negotiation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If protection services are managed by distinct administrative entities without mutual visibility, then operational independence and security are improved, but the effectiveness of combined mitigation actions deteriorates

Engineering Contradiction:
Improveoperational independenceVSAvoidmitigation action effectiveness
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The coordinator acts as a neutral intermediary that enables information exchange between protection services managed by different administrative entities. It receives attack information from one service, processes it, and forwards appropriate mitigation instructions to other services without requiring direct trust or visibility between the administrative entities themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the coordination function from the protection services themselves. The coordinator is a separate entity that handles the coordination logic, allowing each protection service to maintain its operational independence while still contributing to coordinated mitigation efforts through standardized information exchange protocols.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If filtering policies are implemented to isolate attack traffic, then the ability to block harmful traffic is improved, but the risk of creating routing loops and blocking legitimate traffic increases

Engineering Contradiction:
Improveattack traffic isolationVSAvoidrouting loops and legitimate traffic blocking
Core Design Contradiction:
Object-affected harmful factorsVSObject-generated harmful factors

Solution Approach 1:

The system implements feedback mechanisms where protection services continuously monitor the effects of their filtering policies and report back to the coordinator. When routing loops or unintended blocking of legitimate traffic is detected, the coordinator receives this feedback and adjusts the mitigation instructions sent to the protection services to resolve the issues.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The filtering policies are made dynamic rather than static. The coordinator continuously updates mitigation instructions based on real-time conditions, adjusting filter criteria and routing rules to adapt to changing network states and attack characteristics, thereby reducing the risk of routing loops and unnecessary traffic blocking.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12105798B2Method for coordinating the mitigation of a cyber attack, associated device and system
Publication Date: 2024.10.01 ORANGE SA
  • US12105798B2 patent drawing
  • US12105798B2 patent drawing
  • US12105798B2 patent drawing

AI summary

A method for coordinating mitigation of a cyber attack, an associated device and system. The coordination method is implemented by a device managing resources in a computing domain, wherein the resources are protected by a plurality of services protecting against cyber attacks. The method includes: producing mitigation plans implemented by protection services from the plurality of protection services in response to a cyber attack targeting at least one of the resources in the computing domain; and following a detection of at least one incompatibility between the mitigation plans produced, coordinating an adjustment to all or some of the incompatible mitigation plans, among the protection services that have implemented the incompatible mitigation plans, so as to eliminate the incompatibility.