DDoS Mitigation via Traffic Pattern Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed denial-of-service (DDoS) attacks are challenging to mitigate due to their distributed nature and the use of sophisticated spoofing techniques, leading to high latency between attack detection and mitigation, which can result in service denial to legitimate users.

Innovation Solution

A method and apparatus that proactively initiate DDoS attack mitigation by comparing current data traffic to historical pre-DDoS traffic patterns, enabling mitigation before actual attack detection, thereby reducing latency and conserving resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If traditional DDoS attack mitigation methods are used, then attack traffic can be blocked, but latency between attack detection and mitigation is high

Engineering Contradiction:
Improvelatency between attack detection and mitigationVSAvoidservice availability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing baseline traffic patterns before attacks occur and proactively comparing current traffic against these baselines. This allows the system to detect and respond to attacks in their early stages, before they fully develop and cause service disruption, thereby reducing the latency between attack onset and mitigation while maintaining service availability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops by monitoring traffic patterns, comparing them against established baselines, and dynamically adjusting mitigation strategies. This real-time feedback mechanism enables the system to quickly adapt to changing attack conditions and reduce detection-to-mitigation latency while ensuring reliable service through automated response adjustments.

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If broad packet-filtering or rate-limiting measures are employed to mitigate DDoS attacks, then attack traffic is blocked, but legitimate service is shut down causing denial of service to legitimate users

Engineering Contradiction:
Improveattack traffic blockingVSAvoidlegitimate service accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system applies local quality by implementing differentiated treatment for different types of traffic. Instead of uniform packet filtering or rate limiting, it analyzes traffic patterns and applies mitigation measures selectively to malicious traffic while allowing legitimate traffic to pass through unchanged. This localized approach blocks attack traffic effectively while preserving legitimate service accessibility.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters dynamically by adjusting mitigation intensity based on traffic pattern analysis. Rather than applying fixed filtering rules, it modifies mitigation parameters in real-time based on the degree of deviation from baseline patterns, enabling effective attack blocking while maintaining service accessibility for legitimate users whose traffic remains within normal parameters.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If DDoS attacks use sophisticated spoofing techniques and legitimate protocols, then attack stealth and disruption increase, but detection difficulty increases

Engineering Contradiction:
Improveattack stealth and disruptionVSAvoidattack detection difficulty
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The system maintains continuous monitoring and comparison of traffic patterns against baselines, ensuring uninterrupted detection capability. This continuous analysis allows the system to detect subtle deviations caused by sophisticated spoofing techniques and legitimate protocol-based attacks, maintaining detection effectiveness even when attacks use stealthy methods that blend with normal traffic.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11729209B2Distributed denial-of-service attack mitigation with reduced latency
Publication Date: 2023.08.15 CHARTER COMM OPERATING LLC
  • US11729209B2 patent drawing
  • US11729209B2 patent drawing
  • US11729209B2 patent drawing

AI summary

An apparatus for mitigating a DDoS attack in a networked computing system includes at least one detector coupled with a corresponding router in the networked computing system. The detector is configured: to obtain network flow information from the router regarding current data traffic to at least one host; to compare the current data traffic to the host with stored traffic patterns associated with at least one prior DDoS attack; and to generate an output indicative of a match between the current data traffic and at least one of the stored traffic patterns. The apparatus further includes at least one mitigation unit coupled with the at least one detector. The mitigation unit is configured: to receive the output indicative of the match between the current data traffic and at least one of the stored traffic patterns; and to initiate a DDoS attack mitigation action in response to the received output.