DDoS Mitigation via Temporary Address Allocation and Traffic Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures are inadequate in effectively detecting and mitigating Distributed Denial of Service (DDoS) attacks, particularly due to the difficulty in identifying spoofed source IP addresses and the reliance on costly, proprietary solutions that fail to reliably and cost-effectively manage bandwidth consumption and service availability.

Innovation Solution

A system comprising mitigation servers, a DDoS mitigation platform, and a reputation database that employs temporary network address allocation, traffic tunneling, and black hole systems to reroute malicious traffic, track suspicious activity, and generate attack signatures, thereby mitigating DDoS attacks without disrupting legitimate traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If service providers use traditional packet inspection and source address verification to detect DDoS attacks, then they can identify malicious traffic, but the processing capacity required to perform packet diagnostics becomes prohibitively expensive and complex

Engineering Contradiction:
Improveattack detection accuracyVSAvoidprocessing capacity requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the DDoS mitigation function into two parts: (1) a monitoring component that passively collects traffic flow data and generates attack signatures without processing individual packets, and (2) a mitigation component that uses these signatures to filter traffic. This segmentation allows attack detection without requiring expensive real-time packet inspection capabilities at every network node.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary monitoring system that sits between the attacked services and the attack traffic sources. This intermediary passively monitors traffic flows, generates attack signatures, and provides mitigation guidance to upstream routers, thereby eliminating the need for expensive packet-by-packet inspection at the service provider's core network nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service providers implement comprehensive packet inspection and source verification to track forged datagrams, then they can identify attack sources, but the cost of proprietary anti-DDoS technology becomes prohibitive

Engineering Contradiction:
Improvesource tracking accuracyVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a self-service approach where the monitoring system automatically collects traffic flow data, analyzes patterns, generates attack signatures, and provides mitigation recommendations without requiring expensive proprietary tools or manual analysis. The system uses readily available network traffic data and open-standard protocols to achieve reliable source tracking at low cost.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses inexpensive traffic flow sampling and statistical analysis methods instead of expensive comprehensive packet inspection. By analyzing aggregated traffic patterns rather than individual packets, the system achieves reliable attack source identification using low-cost, readily available network monitoring capabilities.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If service providers deploy expensive proprietary anti-DDoS solutions, then they may achieve some level of protection, but they become locked into costly solutions and unable to cost-effectively mitigate attacks

Engineering Contradiction:
ImproveDDoS protection effectivenessVSAvoidsolution flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal monitoring and signature generation system that can detect and provide mitigation guidance for multiple types of DDoS attacks (UDP floods, ICMP floods, SYN floods, etc.) using a single platform. This multi-functional approach eliminates the need for multiple proprietary solutions and provides flexible, cost-effective protection across diverse attack scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements a dynamic system that continuously learns from traffic patterns, automatically updates attack signatures as new attack methods emerge, and adapts mitigation strategies in real-time. This dynamic capability ensures long-term effectiveness without requiring expensive proprietary updates or vendor lock-in, as the system evolves using open standards and automated machine learning.

Inventive Principle:
Principle #15Dynamics

4Object-affected harmful factors

If the system reroutes malicious traffic using black hole systems and traffic tunneling, then DDoS attack impact is reduced, but legitimate traffic may be affected if not properly distinguished

Engineering Contradiction:
ImproveDDoS attack impactVSAvoidlegitimate traffic delivery
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the monitoring system continuously validates attack signatures against actual traffic patterns and adjusts mitigation rules accordingly. This feedback loop ensures that legitimate traffic is not mistakenly routed to black hole systems, as the system learns from false positives and refines its classification accuracy over time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent uses multiple traffic flow parameters (packet rate, protocol type, source/destination addresses, port numbers, time-of-day patterns) to dynamically classify traffic as malicious or legitimate. By analyzing combinations of these parameters rather than single characteristics, the system accurately distinguishes attack traffic from legitimate traffic, ensuring proper routing decisions without affecting service availability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9197666B2Method and apparatus for mitigating distributed denial of service attacks
Publication Date: 2015.11.24 VERIZON PATENT & LICENSING INC
  • US9197666B2 patent drawing
  • US9197666B2 patent drawing
  • US9197666B2 patent drawing

AI summary

An approach for mitigating distributed denial of service (DDoS) attacks includes assigning a set of temporary network addresses to a hostname for a finite period and assigning one or more other sets of temporary network addresses to the hostname in one or more following finite periods, responding to a hostname lookup request based on the set of temporary network addresses, the one or more other sets of temporary network addresses, or a combination thereof that are active, responding to a network address lookup request based on at least one of the set of temporary network addresses and the one or more other sets of temporary network addresses that is associated with a current one of the finite period or the one or more following finite periods, and retiring the set of temporary network addresses, the one or more sets of temporary network addresses, or a combination thereof after a configurable number of finite periods, wherein no further network address or hostname lookup request is served based on the retired set of temporary network addresses, the retired one or more sets of temporary network addresses, or a combination thereof.