DDoS Protection via Distributed Proxy Network Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for protecting against Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, such as using firewalls and scrubbing centers, are ineffective against large-scale malicious activities and introduce significant latency, affecting data performance.

Innovation Solution

A method that utilizes a global private network (GPN) of proxy servers to hide the location and IP address of a destination server from users, routing user data through edge servers and multiple low-latency or high-bandwidth servers within the GPN to minimize latency and maximize bandwidth, while allowing only non-malicious data to reach the destination server, and using redundant data streams to ensure uninterrupted service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a scrubbing center is used to remove malicious data, then malicious activity is filtered, but data performance deteriorates due to significant latency

Engineering Contradiction:
Improvemalicious activity filteringVSAvoiddata latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces edge servers as intermediary components between users and the destination server. These edge servers perform malicious activity detection and filtering locally, acting as mediators that protect the destination server without requiring all data to traverse a centralized scrubbing center, thereby reducing latency while maintaining filtering effectiveness

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the traditional centralized scrubbing center into distributed edge servers positioned at multiple network locations. This segmentation allows malicious activity filtering to occur at distributed points closer to users, reducing the distance data must travel and minimizing latency while maintaining comprehensive filtering coverage

Inventive Principle:
Principle #1Segmentation

2Reliability

If all traffic is processed through a scrubbing center, then comprehensive security is achieved, but processing efficiency decreases

Engineering Contradiction:
Improvesecurity coverageVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial action by having edge servers perform selective malicious activity detection on specific data characteristics rather than processing all traffic uniformly. This allows normal traffic to pass through with minimal processing while focusing computational resources on detecting and filtering malicious patterns, thereby maintaining security coverage while improving overall processing efficiency

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If the destination server IP address is exposed to users, then direct access is enabled, but vulnerability to DDoS attacks increases

Engineering Contradiction:
Improveuser accessVSAvoidDDoS attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces edge servers as intermediaries between users and the destination server. Users connect to edge servers which then communicate with the destination server, thereby enabling user access while concealing the destination server's IP address and protecting it from direct exposure to malicious actors

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates multiple edge server instances that can handle user connections. These edge servers act as copies or proxies of the destination server interface, allowing users to access services through multiple entry points while the actual destination server remains hidden and protected from direct attacks

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9985985B2Method of distributed denial of service (DDos) and hacking protection for internet-based servers using a private network of internet servers by executing computer-executable instructions stored on a non-transitory computer-readable medium
Publication Date: 2018.05.29 AAA INTERNET PUBLISHING
  • US9985985B2 patent drawing
  • US9985985B2 patent drawing
  • US9985985B2 patent drawing

AI summary

A method of DDoS and hacking protection for internet-based servers using a private network of internet servers utilizes multiple data streams sent over a network of proxy servers to mitigate malicious attacks and ensure fast connections from a user to a destination server. The destination server is hidden from the user and the redundancy of the proxy network serves to maintain security and connection quality between the user and the destination server.