DDoS Attack Protection Service for Inbound Traffic Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service provider systems face challenges in detecting and mitigating Distributed Denial of Service (DDoS) attacks without impacting legitimate traffic or compromising security, as malicious actors can utilize virtual machines and network resources to overwhelm targeted systems.

Innovation Solution

Implementing a DDoS attack protection service (DAPS) that includes traffic monitoring agents and a DDoS attack detector to identify malicious traffic and respond with targeted mitigation actions, such as blocking compromised compute instances, to minimize impact on legitimate users and network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service provider systems provide resources such as virtual machines and bandwidth to users, then service availability and resource utilization are improved, but the system becomes vulnerable to DDoS attacks where malicious actors can exploit these resources to overwhelm targeted systems

Engineering Contradiction:
Improveresource availabilityVSAvoidDDoS attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the service provider system into multiple monitoring components including traffic monitoring agents deployed at network edges, a central DDoS attack detector, and individual compute instance monitors. This segmentation allows localized detection and response while maintaining overall system resource availability for legitimate users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a DDoS attack protection service as an intermediary layer between legitimate traffic and potential attacks. This intermediary monitors traffic patterns, identifies malicious activity, and responds by isolating compromised resources without affecting the broader system, thus resolving the contradiction between resource availability and attack vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system monitors and blocks malicious traffic to mitigate DDoS attacks, then security is improved, but legitimate traffic may be incorrectly identified and blocked causing service disruption

Engineering Contradiction:
ImprovesecurityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies partial action by initially isolating only the specific compute instance showing malicious behavior rather than blocking all traffic from the user account. This targeted approach maintains service continuity for legitimate operations while addressing the security threat, and only escalates to account-wide blocking if the instance is recovered and re-infected.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements continuous feedback loops where traffic monitoring agents constantly report traffic patterns to the DDoS detector, which adjusts its response based on evolving traffic analysis. This feedback mechanism allows the system to distinguish between legitimate and malicious traffic dynamically, maintaining security while minimizing false positives that would disrupt service.

Inventive Principle:
Principle #23Feedback

3Speed

If the system responds quickly to DDoS attacks by blocking traffic sources, then attack mitigation effectiveness is improved, but the response time to restore legitimate service may increase

Engineering Contradiction:
Improveattack response speedVSAvoidservice restoration time
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The patent implements preliminary action by continuously monitoring traffic patterns and maintaining baseline profiles of normal user behavior before attacks occur. When anomalies are detected, the system can quickly compare against established baselines and respond immediately without extensive analysis, reducing both attack response time and service restoration time through automated decision-making.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs dynamic response strategies that adjust isolation duration and scope based on real-time traffic analysis. Rather than applying fixed-time blocks, the system continuously evaluates whether the isolated instance has been compromised and can be safely restored, enabling rapid service recovery while maintaining security through adaptive, real-time decision-making.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10516695B1Distributed denial of service attack mitigation in service provider systems
Publication Date: 2019.12.24 AMAZON TECH INC
  • US10516695B1 patent drawing
  • US10516695B1 patent drawing
  • US10516695B1 patent drawing

AI summary

Techniques for detecting and mitigating distributed denial of service (DDoS) attacks sourced from within a service provider system are described. A service obtains traffic data comprising a plurality of entries that describe outbound network traffic originated by a plurality of compute instances within the service provider system that is destined to locations outside the service provider system. The service determines that one or more destination network addresses identified within the traffic data are likely targets of a DDoS attack, determines a responsive action from a plurality of candidate responsive actions to perform with regard to the one or more compute instances, and causes the responsive action to be performed in the service provider system.