DDOS Mitigation via DNS Traffic Analysis and Domain Shifting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems, including firewalls and specialized routers, are overwhelmed by the unprecedented scale and duration of Distributed Denial of Service (DDOS) attacks, which overwhelm authoritative DNS servers and prevent legitimate connections.

Innovation Solution

A system comprising DTAF Firewalls that analyze network traffic, a Central Master DTAF for dynamic access control, and a domain shifting subsystem that creates new authoritative DNS servers to reroute traffic, utilizing access control lists and DNS look-ups to manage and mitigate malicious traffic by diverting suspicious traffic and rotating DNS servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls and specialized routers are used to filter malicious traffic, then basic DDOS protection is provided, but the systems are overwhelmed by unprecedented scale and duration of attacks

Engineering Contradiction:
ImproveDDOS protection capabilityVSAvoidtraffic handling capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the DDOS mitigation function into multiple specialized components: DTAF Firewalls for traffic analysis and filtering, Central Master DTAF for coordination and rule management, and Authoritative DNS servers for domain resolution. This segmentation allows each component to handle specific aspects of the attack, distributing the processing load and preventing any single system from being overwhelmed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces DTAF Firewalls as intermediary devices positioned between the internet and the protected network infrastructure. These firewalls analyze incoming traffic, identify malicious patterns, and filter attacks before they reach the core systems. The Central Master DTAF acts as a mediator that coordinates multiple firewalls and manages access control lists, enabling collaborative defense against large-scale attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control lists and traffic filtering are implemented to block malicious traffic, then attack mitigation is improved, but legitimate traffic may be inadvertently blocked

Engineering Contradiction:
Improveattack mitigation effectivenessVSAvoidlegitimate traffic accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements dynamic access control lists that are continuously updated based on real-time traffic analysis. The Central Master DTAF monitors attack patterns and adjusts filtering rules dynamically, allowing legitimate traffic patterns to pass through while blocking evolving attack vectors. This dynamic adaptation prevents false positives that would block legitimate users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where the DTAF Firewalls continuously monitor traffic patterns and report to the Central Master DTAF. The central system analyzes this feedback, updates access control lists, and redistributes rules to firewalls. This closed-loop feedback system ensures that filtering rules remain accurate and adapt to changing attack patterns without blocking legitimate traffic.

Inventive Principle:
Principle #23Feedback

3Productivity

If multiple DNS servers are deployed to handle increased traffic, then traffic distribution is improved, but system complexity increases

Engineering Contradiction:
Improvetraffic distribution capacityVSAvoidDNS server infrastructure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the DNS server functionality with the DDOS mitigation infrastructure. Authoritative DNS servers are integrated with DTAF Firewalls and Central Master DTAF, creating a unified system that provides both domain resolution and attack protection. This merging allows traffic distribution across multiple DNS servers while maintaining centralized coordination and simplified management through the Central Master DTAF.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9294483B2Method and system for mitigation of distributed denial of service (DDOS) attacks
Publication Date: 2016.03.22 WONG JOHN
  • US9294483B2 patent drawing
  • US9294483B2 patent drawing
  • US9294483B2 patent drawing

AI summary

A system and method for mitigating the effects of malicious internet traffic, including DDOS attacks, by utilizing a DNS Traffic Analyzer and Firewall to analyze network traffic intended for a DNS server and preventing some network traffic from accessing the DNS server.