DDoS Mitigation via Remote Points of Presence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed denial-of-service (DDoS) attacks pose a significant threat to organizations by overwhelming their systems, affecting not only the intended victims but also other network users, leading to increased costs and network resource strain, with existing solutions often requiring costly infrastructure and intrusive reconfigurations.
Innovation Solution
The implementation of remotely deployed network points of presence (POPs) that reroute and mitigate illegitimate network traffic through geographically proximate locations, using border gateway protocol (BGP) routes and private channels to block malicious traffic while allowing legitimate traffic to reach its destination, thereby reducing the need for victims to reconfigure their IP addresses or invest in expensive DDoS mitigation devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DDoS mitigation devices are deployed at the victim's location, then protection against DDoS attacks is improved, but device complexity and cost increase
Solution Approach 1:
The patent introduces remotely deployed network points of presence (POPs) as intermediary components that act as mediators between the attack traffic source and the victim. These POPs receive, filter, and forward traffic without requiring the victim to deploy or manage complex mitigation infrastructure, thereby providing protection while reducing device complexity at the victim's location
Solution Approach 2:
The mitigation system performs self-service by automatically detecting DDoS attacks and dynamically routing traffic through appropriate POPs without requiring victim intervention. The system autonomously manages the complexity of mitigation devices while the victim simply benefits from the protection service
2Reliability
If IP addresses are frequently updated to evade DDoS attacks, then protection against DDoS attacks is improved, but loss of time and operational disruption increase
Solution Approach 1:
The patent implements preliminary action by pre-deploying multiple network POPs in various geographic locations before attacks occur. When a DDoS attack is detected, the system can immediately route traffic through alternative POPs without requiring any changes to the victim's IP addresses, thus providing protection while avoiding operational disruption and time loss
Solution Approach 2:
Instead of changing the victim's IP addresses to evade attacks, the patent inverts the approach by keeping the victim's IP addresses static and changing the routing path through which traffic reaches the victim. This inversion eliminates the need for IP address updates and their associated disruptions
3Productivity
If DDoS attack traffic is allowed to traverse the network, then network resource availability is maintained, but harmful effects from DDoS attacks increase
Solution Approach 1:
The patent applies local quality by deploying geographically distributed POPs that can locally filter DDoS attack traffic in the regions where it originates. This allows legitimate traffic to continue flowing through the network while malicious traffic is blocked at the source, thus maintaining network resource availability while reducing harmful effects
Solution Approach 2:
The system extracts harmful DDoS attack traffic from the network flow by identifying and routing it through specific POPs that filter and drop malicious packets. This extraction process separates harmful traffic from legitimate traffic, allowing the network to maintain availability for productive operations while eliminating the harmful effects of DDoS attacks
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods protect against denial of service attacks. Remotely originated network traffic addressed to one or more network destinations is routed through one or more locations. One or more of the locations may be geographically proximate to a source of a denial of service attack. One or more denial of service attack mitigation strategies is applied to portions of the network traffic received at the one or more locations. Network traffic not blocked pursuant to the one or more denial of service attack mitigation strategies is dispatched to its intended recipient. Dispatching the unblocked network traffic to its intended recipient may include the use of one or more private channels and/or one or more additional denial of service attack mitigation strategies.