Cloud-Based DDoS Mitigation via Traffic Rerouting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current DDoS detection systems are limited in scalability and cannot be deployed across large networks, making it difficult for service providers to offer effective DDoS mitigation services to multiple customers without incurring significant hardware costs, and there is a need for a solution that allows third-party providers to offer mitigation services independently of service providers.
Innovation Solution
Implementing a service provider-independent on-demand DDoS mitigation system that establishes a baseline of normal IP traffic for customers, develops customer profiles for mitigation devices, and routes IP traffic through these devices to filter out malicious packets during attacks, allowing third-party providers to offer mitigation services across multiple networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service providers deploy network-based infrastructure for DDoS detection, then detection capability is improved, but hardware cost increases significantly
Solution Approach 1:
The patent creates a universal DDoS detection system that can serve multiple customers across different service providers through a centralized cloud-based platform. The system performs multiple functions including traffic analysis, attack detection, and mitigation coordination, eliminating the need for each service provider to deploy separate dedicated hardware infrastructure.
Solution Approach 2:
The patent implements virtualized detection capabilities that can be replicated and distributed across multiple service provider networks without requiring physical hardware copies. The detection system is instantiated as software that can be deployed and scaled across different network infrastructures, reducing hardware investment while maintaining detection effectiveness.
2Measurement precision
If DDoS detection systems are tailored to per-customer arrangements, then detection accuracy is improved, but scalability deteriorates
Solution Approach 1:
The patent segments the detection system into customer-specific analysis modules that operate within a unified cloud platform. Each customer's traffic patterns are analyzed independently to maintain detection accuracy, while the overall system remains scalable through centralized resource management and shared infrastructure.
Solution Approach 2:
The patent implements dynamic customer profiles that adapt to each customer's specific traffic patterns and requirements, allowing the system to maintain high detection accuracy for individual customers while scaling across multiple customers through automated profile creation and updates based on observed behavior.
3Reliability
If service providers invest in costly infrastructure, then mitigation service quality is improved, but deployment speed deteriorates
Solution Approach 1:
The patent pre-configures detection and mitigation capabilities in the cloud before they are needed, with customer profiles and detection rules established in advance. When a DDoS attack occurs, the system can immediately activate pre-prepared mitigation strategies without requiring time-consuming hardware deployment or infrastructure setup.
Data Source
AI summary
Service provider-independent on-demand distributed denial of service (DDoS) mitigation. A mitigation provider provides a service to customers to remove or reduce DDoS attacks regardless of the customer's relationship with a service provider. Customer profiles about the customers' IP traffics are loaded into mitigation devices. When a DDoS attack occurs, customer profiles are activated in a set of the mitigation devices. Routes are also modified to steer customer traffic to the mitigation devices. DDoS packets are removed at the mitigation devices and the “cleaned” IP traffic is subsequently routed to the destination.


