DDOS Mitigation via DNS Traffic Analysis and Domain Shifting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems, including firewalls and specialized routers, are overwhelmed by the unprecedented scale and duration of Distributed Denial of Service (DDOS) attacks, which overwhelm authoritative DNS servers and prevent legitimate connections.
Innovation Solution
A system comprising DTAF Firewalls that analyze network traffic, a Central Master DTAF for dynamic access control, and a domain shifting subsystem that creates new authoritative DNS servers to reroute traffic, utilizing access control lists and DNS look-ups to manage and mitigate malicious traffic by diverting suspicious traffic and rotating DNS servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewalls and specialized routers are used to filter malicious traffic, then basic DDOS protection is provided, but the systems are overwhelmed by unprecedented scale and duration of attacks
Solution Approach 1:
The system segments the DDOS mitigation function into multiple specialized components: DTAF Firewalls for traffic analysis and filtering, Central Master DTAF for coordination and rule management, and Authoritative DNS servers for domain resolution. This segmentation allows each component to handle specific aspects of the attack, distributing the processing load and preventing any single system from being overwhelmed.
Solution Approach 2:
The patent introduces DTAF Firewalls as intermediary devices positioned between the internet and the protected network infrastructure. These firewalls analyze incoming traffic, identify malicious patterns, and filter attacks before they reach the core systems. The Central Master DTAF acts as a mediator that coordinates multiple firewalls and manages access control lists, enabling collaborative defense against large-scale attacks.
2Reliability
If access control lists and traffic filtering are implemented to block malicious traffic, then attack mitigation is improved, but legitimate traffic may be inadvertently blocked
Solution Approach 1:
The system implements dynamic access control lists that are continuously updated based on real-time traffic analysis. The Central Master DTAF monitors attack patterns and adjusts filtering rules dynamically, allowing legitimate traffic patterns to pass through while blocking evolving attack vectors. This dynamic adaptation prevents false positives that would block legitimate users.
Solution Approach 2:
The patent incorporates feedback mechanisms where the DTAF Firewalls continuously monitor traffic patterns and report to the Central Master DTAF. The central system analyzes this feedback, updates access control lists, and redistributes rules to firewalls. This closed-loop feedback system ensures that filtering rules remain accurate and adapt to changing attack patterns without blocking legitimate traffic.
3Productivity
If multiple DNS servers are deployed to handle increased traffic, then traffic distribution is improved, but system complexity increases
Solution Approach 1:
The patent merges the DNS server functionality with the DDOS mitigation infrastructure. Authoritative DNS servers are integrated with DTAF Firewalls and Central Master DTAF, creating a unified system that provides both domain resolution and attack protection. This merging allows traffic distribution across multiple DNS servers while maintaining centralized coordination and simplified management through the Central Master DTAF.
Data Source
AI summary
A system and method for mitigating the effects of malicious internet traffic, including DDOS attacks, by utilizing a DNS Traffic Analyzer and Firewall to analyze network traffic intended for a DNS server and preventing some network traffic from accessing the DNS server.


