DDoS Mitigation via Dynamic Traffic Routing and Threshold Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods are inadequate in effectively mitigating Distributed Denial-of-Service (DDoS) attacks on networks, as they fail to efficiently manage and redirect excessive traffic, leading to network overload and service disruption.

Innovation Solution

The implementation of a system using DDoS Devices that monitor and manage network traffic by determining throughput capabilities, operational limits, and malicious traffic rates, with notifications and traffic rerouting to prevent overload, combined with intrusion detection systems analyzing TCP headers and packet data to activate mitigation strategies based on predetermined thresholds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traffic rate is increased to handle more network load, then network throughput is improved, but network overload and service disruption occur during DDoS attacks

Engineering Contradiction:
Improvenetwork throughputVSAvoidservice availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system dynamically adjusts traffic routing based on real-time device capacity and attack conditions. DDoS Devices transition between active and standby roles, with traffic routing dynamically switched to capable devices when overload is detected, allowing the network to adapt its throughput capacity according to actual conditions without sacrificing reliability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A traffic routing mechanism acts as an intermediary between network traffic and DDoS Devices, directing traffic to appropriate devices based on their current capacity. This intermediary layer prevents direct overload of individual devices while maintaining overall network throughput by distributing traffic intelligently across multiple devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If DDoS mitigation is activated to block malicious traffic, then network security is improved, but legitimate traffic may be blocked and service disrupted

Engineering Contradiction:
Improvemalicious traffic blockingVSAvoidlegitimate service access
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system applies different mitigation strategies to different traffic flows based on their characteristics. Instead of blanket blocking, the system identifies and blocks only malicious traffic patterns while allowing legitimate traffic to pass through unaffected, achieving selective mitigation that protects security without disrupting service

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system continuously monitors traffic patterns and device performance, using this feedback to adjust mitigation actions in real-time. When legitimate traffic patterns are detected, the system adjusts its blocking behavior to allow such traffic through, preventing false positives that would disrupt service while maintaining protection against actual attacks

Inventive Principle:
Principle #23Feedback

3Productivity

If traffic is routed to a single DDoS Device with high capacity, then throughput capability is improved, but the device becomes a single point of failure and overload risk

Engineering Contradiction:
Improvethroughput capabilityVSAvoidsystem resilience
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the DDoS protection function across multiple devices rather than relying on a single high-capacity device. Each DDoS Device can operate independently, and the system distributes traffic across multiple devices, eliminating single points of failure while maintaining aggregate throughput capability through parallel processing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the operational parameters of multiple DDoS Devices from static to dynamic states, where devices can transition between active and standby modes. This allows the system to utilize high capacity when needed while distributing the load to prevent any single device from becoming overwhelmed, thereby maintaining both throughput and reliability

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If manual monitoring and intervention is used to manage DDoS traffic, then traffic management precision is improved, but response time increases and automation is reduced

Engineering Contradiction:
Improvetraffic rate monitoring accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The DDoS Devices perform self-monitoring of their own traffic rates and capacity utilization, automatically detecting when they are approaching overload conditions. This self-service capability eliminates the need for external manual monitoring while maintaining precise traffic rate measurement and enabling immediate automated response to attack conditions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements automated feedback loops where DDoS Devices continuously report their status and the routing system automatically adjusts traffic distribution in response. This closed-loop control maintains precise monitoring accuracy while reducing response time by eliminating manual intervention steps, allowing the system to react automatically to changing conditions

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9781157B1Mitigating denial of service attacks
Publication Date: 2017.10.03 GO DADDY OPERATING CO LLC
  • US9781157B1 patent drawing
  • US9781157B1 patent drawing
  • US9781157B1 patent drawing

AI summary

Several methods are disclosed for detecting and mitigating Distributed Denial-of-Service (DDoS) attacks that are intended to exhaust network resources. The methods use DDoS mitigation devices to detect DDoS attacks using operationally based thresholds. The methods also keep track of ongoing attacks, have an understanding of “protected IP space,” and activate appropriate mitigation tactics based on the severity of the attack and the capabilities of the DDoS mitigation devices.