DDoS Attack Protection Service for Inbound Traffic Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service provider systems face challenges in detecting and mitigating Distributed Denial of Service (DDoS) attacks without impacting legitimate traffic or compromising security, as malicious actors can utilize virtual machines and network resources to overwhelm targeted systems.
Innovation Solution
Implementing a DDoS attack protection service (DAPS) that includes traffic monitoring agents and a DDoS attack detector to identify malicious traffic and respond with targeted mitigation actions, such as blocking compromised compute instances, to minimize impact on legitimate users and network resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If service provider systems provide resources such as virtual machines and bandwidth to users, then service availability and resource utilization are improved, but the system becomes vulnerable to DDoS attacks where malicious actors can exploit these resources to overwhelm targeted systems
Solution Approach 1:
The patent segments the service provider system into multiple monitoring components including traffic monitoring agents deployed at network edges, a central DDoS attack detector, and individual compute instance monitors. This segmentation allows localized detection and response while maintaining overall system resource availability for legitimate users.
Solution Approach 2:
The patent introduces a DDoS attack protection service as an intermediary layer between legitimate traffic and potential attacks. This intermediary monitors traffic patterns, identifies malicious activity, and responds by isolating compromised resources without affecting the broader system, thus resolving the contradiction between resource availability and attack vulnerability.
2Reliability
If the system monitors and blocks malicious traffic to mitigate DDoS attacks, then security is improved, but legitimate traffic may be incorrectly identified and blocked causing service disruption
Solution Approach 1:
The patent applies partial action by initially isolating only the specific compute instance showing malicious behavior rather than blocking all traffic from the user account. This targeted approach maintains service continuity for legitimate operations while addressing the security threat, and only escalates to account-wide blocking if the instance is recovered and re-infected.
Solution Approach 2:
The system implements continuous feedback loops where traffic monitoring agents constantly report traffic patterns to the DDoS detector, which adjusts its response based on evolving traffic analysis. This feedback mechanism allows the system to distinguish between legitimate and malicious traffic dynamically, maintaining security while minimizing false positives that would disrupt service.
3Speed
If the system responds quickly to DDoS attacks by blocking traffic sources, then attack mitigation effectiveness is improved, but the response time to restore legitimate service may increase
Solution Approach 1:
The patent implements preliminary action by continuously monitoring traffic patterns and maintaining baseline profiles of normal user behavior before attacks occur. When anomalies are detected, the system can quickly compare against established baselines and respond immediately without extensive analysis, reducing both attack response time and service restoration time through automated decision-making.
Solution Approach 2:
The system employs dynamic response strategies that adjust isolation duration and scope based on real-time traffic analysis. Rather than applying fixed-time blocks, the system continuously evaluates whether the isolated instance has been compromised and can be safely restored, enabling rapid service recovery while maintaining security through adaptive, real-time decision-making.
Data Source
AI summary
Techniques for detecting and mitigating distributed denial of service (DDoS) attacks sourced from within a service provider system are described. A service obtains traffic data comprising a plurality of entries that describe outbound network traffic originated by a plurality of compute instances within the service provider system that is destined to locations outside the service provider system. The service determines that one or more destination network addresses identified within the traffic data are likely targets of a DDoS attack, determines a responsive action from a plurality of candidate responsive actions to perform with regard to the one or more compute instances, and causes the responsive action to be performed in the service provider system.


