Local DDoS Mitigation Rule Propagation in Provider Edge Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Telecommunication networks face challenges in mitigating distributed denial of service (DDOS) attacks as broadcasting DDOS mitigation rules throughout the network can overwhelm devices, while stopping their implementation at the network edge reduces the defense dispersal, necessitating a localized solution.

Innovation Solution

A provider edge device in a telecommunications network is configured to receive and implement DDOS mitigation rules from a customer network, applying them locally without broadcasting beyond the edge device, thereby preventing malicious packets from reaching the customer network while limiting the impact on the rest of the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DDOS mitigation rules are broadcast throughout the network, then the defense against DDOS attacks is dispersed throughout the network, but the devices of the network are overwhelmed

Engineering Contradiction:
Improvedefense dispersalVSAvoidnetwork device overload
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into customer networks and the provider network, and segments the mitigation rule propagation to only reach the provider edge device rather than propagating throughout the entire provider network. This segmentation allows defense dispersal at the customer network level while preventing overload of provider network devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing mitigation rules locally at the provider edge device for each customer network rather than uniformly across the entire provider network. Each provider edge device independently receives and implements rules from its connected customer networks, creating localized defense without network-wide propagation.

Inventive Principle:
Principle #3Local quality

2Device complexity

If DDOS mitigation rules are stopped at the network edge, then the network devices are not overwhelmed, but the dispersal of DDOS attack defense is reduced

Engineering Contradiction:
Improvenetwork device overloadVSAvoiddefense dispersal
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the mitigation function between customer networks and the provider network. Customer networks generate and propagate rules within their own networks for local dispersal of defense, while the provider edge device receives these rules and implements them at the boundary, preventing provider network device overload while maintaining customer network defense dispersal.

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual administration of DDOS mitigation rules is performed, then network control is maintained, but response speed is reduced and costs increase

Engineering Contradiction:
Improvenetwork controlVSAvoidresponse speed
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables customer networks to autonomously generate and propagate their own DDOS mitigation rules to the provider edge device without requiring manual administrator intervention. The customer network's DDOS mitigation system automatically detects attacks, creates rules, and propagates them, achieving fast response speed while the provider network maintains control through the automated rule implementation at the edge device.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11115435B2Local DDOS mitigation announcements in a telecommunications network
Publication Date: 2021.09.07 LEVEL 3 COMMUNICATIONS LLC
  • US11115435B2 patent drawing
  • US11115435B2 patent drawing
  • US11115435B2 patent drawing

AI summary

Implementations described and claimed herein provide systems and methods for mitigating network threats. In one implementation, a provider edge device of a telecommunications network is configured to accept distributed denial of service mitigation rule propagation from a customer edge device of a customer network in communication with the provider edge device. A distributed denial of service mitigation rule for the customer network is received at the provider edge device from the customer edge device. The distributed denial of service mitigation rule includes one or more routing parameters and a mitigation action. The distributed denial of service mitigation rule is implemented locally on the provider edge device of the telecommunications network. A broadcasting of the distributed denial of service mitigation rule in the telecommunications network is prevented beyond the provider edge device.