Cloud-Based DDoS Mitigation via Traffic Rerouting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DDoS detection systems are limited in scalability and cannot be deployed across large networks, making it difficult for service providers to offer effective DDoS mitigation services to multiple customers without incurring significant hardware costs, and there is a need for a solution that allows third-party providers to offer mitigation services independently of service providers.

Innovation Solution

Implementing a service provider-independent on-demand DDoS mitigation system that establishes a baseline of normal IP traffic for customers, develops customer profiles for mitigation devices, and routes IP traffic through these devices to filter out malicious packets during attacks, allowing third-party providers to offer mitigation services across multiple networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service providers deploy network-based infrastructure for DDoS detection, then detection capability is improved, but hardware cost increases significantly

Engineering Contradiction:
ImproveDDoS detection capabilityVSAvoidhardware cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent creates a universal DDoS detection system that can serve multiple customers across different service providers through a centralized cloud-based platform. The system performs multiple functions including traffic analysis, attack detection, and mitigation coordination, eliminating the need for each service provider to deploy separate dedicated hardware infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements virtualized detection capabilities that can be replicated and distributed across multiple service provider networks without requiring physical hardware copies. The detection system is instantiated as software that can be deployed and scaled across different network infrastructures, reducing hardware investment while maintaining detection effectiveness.

Inventive Principle:
Principle #26Copying

2Measurement precision

If DDoS detection systems are tailored to per-customer arrangements, then detection accuracy is improved, but scalability deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidscalability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the detection system into customer-specific analysis modules that operate within a unified cloud platform. Each customer's traffic patterns are analyzed independently to maintain detection accuracy, while the overall system remains scalable through centralized resource management and shared infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic customer profiles that adapt to each customer's specific traffic patterns and requirements, allowing the system to maintain high detection accuracy for individual customers while scaling across multiple customers through automated profile creation and updates based on observed behavior.

Inventive Principle:
Principle #15Dynamics

3Reliability

If service providers invest in costly infrastructure, then mitigation service quality is improved, but deployment speed deteriorates

Engineering Contradiction:
Improvemitigation service qualityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-configures detection and mitigation capabilities in the cloud before they are needed, with customer profiles and detection rules established in advance. When a DDoS attack occurs, the system can immediately activate pre-prepared mitigation strategies without requiring time-consuming hardware deployment or infrastructure setup.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8510826B1Carrier-independent on-demand distributed denial of service (DDoS) mitigation
Publication Date: 2013.08.13 T MOBILE INNOVATIONS LLC
  • US8510826B1 patent drawing
  • US8510826B1 patent drawing
  • US8510826B1 patent drawing

AI summary

Service provider-independent on-demand distributed denial of service (DDoS) mitigation. A mitigation provider provides a service to customers to remove or reduce DDoS attacks regardless of the customer's relationship with a service provider. Customer profiles about the customers' IP traffics are loaded into mitigation devices. When a DDoS attack occurs, customer profiles are activated in a set of the mitigation devices. Routes are also modified to steer customer traffic to the mitigation devices. DDoS packets are removed at the mitigation devices and the “cleaned” IP traffic is subsequently routed to the destination.