Automated DDoS Mitigation via BGP Route Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DDoS attack mitigation methods are inefficient as they require significant manual intervention and time to reconfigure routers, allowing attacks to continue and potentially rendering targeted systems inoperable during the transition.

Innovation Solution

A method utilizing BGP messaging to automatically detect and mitigate DDoS attacks by advertising a new route that directs malicious traffic to a mitigation server, reducing the time to recover and allowing legitimate traffic to resume quickly without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If manual router reconfiguration is used to mitigate DDoS attacks, then the mitigation process can be completed with existing infrastructure, but the time required to recover service is significantly increased

Engineering Contradiction:
Improvetime to mitigate DDoS attackVSAvoidautomation of mitigation process
Core Design Contradiction:
Loss of timeVSExtent of automation

Solution Approach 1:

The system performs preliminary action by pre-configuring the mitigation infrastructure and establishing BGP messaging relationships before attacks occur. When a DDoS attack is detected, the pre-established BGP sessions enable immediate route withdrawal announcements, diverting traffic to mitigation servers without requiring manual intervention during the critical response phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback through automated monitoring that continuously tracks network traffic patterns and detects DDoS attacks in real-time. Upon detection, the system automatically triggers BGP route withdrawals and activates mitigation protocols, creating a closed-loop feedback system that responds dynamically to attack conditions without human intervention.

Inventive Principle:
Principle #23Feedback

2Productivity

If automated BGP messaging is implemented for DDoS mitigation, then the response time is significantly reduced, but the system complexity increases

Engineering Contradiction:
Improvespeed of DDoS mitigationVSAvoidcomplexity of mitigation system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system applies universality by designing BGP speakers and routing infrastructure that perform multiple functions: normal traffic routing, attack detection, automated route withdrawal, and traffic diversion to mitigation servers. This multi-functionality reduces the need for separate specialized components, managing complexity while enabling rapid automated response to DDoS attacks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses BGP messaging as an intermediary mechanism that enables automated coordination between routing infrastructure and mitigation servers. The BGP protocol serves as a mediator that automatically communicates attack conditions and route changes between systems, reducing complexity compared to direct custom communication protocols while achieving fast automated mitigation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual configuration changes are made to routers during DDoS attacks, then the mitigation approach can be carefully controlled, but the targeted system remains inoperable during the transition period

Engineering Contradiction:
Improvecontrol over mitigation processVSAvoidoperational continuity during mitigation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service through automated BGP speakers that independently detect DDoS attacks, withdraw problematic routes, and activate mitigation protocols without human intervention. This self-service capability ensures operational continuity by immediately responding to attacks, preventing the targeted system from becoming inoperable during transition periods while maintaining control through pre-configured automated protocols.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10855719B2Automated DDOS attack mitigation via BGP messaging
Publication Date: 2020.12.01 VERISIGN INC
  • US10855719B2 patent drawing
  • US10855719B2 patent drawing
  • US10855719B2 patent drawing

AI summary

Various embodiments of the invention disclosed herein provide techniques for mitigating a distributed denial of service (DDoS) attack on a targeted computer system. A border gateway protocol (BGP) controller receives, via a first router, a BGP message that includes an indicator indicating that a computer system associated with the first router is under a DDoS attack. In response to receiving the BGP message, the BGP controller, in performs one or more operations to mitigate the DDoS attack. As a result, the time between detection of a DDoS attack and mitigating the attack is reduced relative to prior approaches. After receiving the BGP message indicating a DDoS attack is in progress, the DDoS attack mitigation platform automatically takes steps to mitigate the DDoS attack without further manual intervention. Consequently, the targeted computer system recovers more quickly and begins to respond to legitimate network requests sooner relative to prior approaches.