DDoS Signature Embedding in Inter-Domain Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed denial of service (DDoS) attacks pose a significant challenge due to their complexity and scale, making it difficult for websites and networks to quickly identify and mitigate these attacks, which can lead to service disruptions and resource saturation.

Innovation Solution

A system and method that automates the recognition and response to DDoS attacks by using a monitoring router with an attack recognition module, anomaly signature identification module, and signature encoding module to identify and communicate DDoS signatures through inter-domain routing protocols, enabling internet nodes to filter out malicious traffic and mitigate the attack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If a monitoring router with attack recognition module is deployed to identify DDoS attacks, then the speed of attack detection is improved, but the device complexity and resource burden on the targeted network increase

Engineering Contradiction:
Improveattack detection speedVSAvoidnetwork device complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system (anomaly signature identification module and signature encoding module) that acts as a mediator between the attack recognition module and the targeted network. This intermediary extracts attack signatures and encodes them for propagation through routing protocols, allowing the targeted network to benefit from fast attack detection without directly bearing the full computational burden of the monitoring router's analysis functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If DDoS signatures are propagated through inter-domain routing protocols to internet nodes, then the ability to filter malicious traffic is improved, but the loss of time for signature transmission and propagation occurs

Engineering Contradiction:
Improvemalicious traffic filtering capabilityVSAvoidsignature transmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-encoding the anomaly signature into a compact format suitable for routing protocol propagation before transmission. The signature is prepared in advance with proper encoding (e.g., ASN.1 encoding) and structured format, so that when it needs to be propagated through the network, it can be quickly transmitted and processed without requiring complex real-time encoding or formatting operations.

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If multiple compromised systems are used to mount DDoS attacks, then the scale and impact of the attack is increased, but the difficulty of identifying the attack source is also increased

Engineering Contradiction:
Improvenumber of attacking hostsVSAvoidattack source identification difficulty
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies the extraction principle by isolating and extracting the essential characteristics of the attack from the complex multi-host DDoS scenario. The anomaly signature identification module extracts the core attack signature that represents the malicious pattern, separating it from the noise of multiple attacking hosts. This extracted signature can then be propagated and matched against traffic from any source, making the detection process independent of the number or identity of attacking hosts.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9166990B2Distributed denial-of-service signature transmission
Publication Date: 2015.10.20 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9166990B2 patent drawing
  • US9166990B2 patent drawing
  • US9166990B2 patent drawing

AI summary

A system and method of transmitting a DDoS, or distributed denial of service, signature from an intra-network to an internet is presented. The method includes identifying a DDoS signature and employing an inter-domain routing protocol configured to enable-operational information to be exchanged between nodes. The DDoS signature is embedded as payload of the standards-compliant inter-domain routing protocol. The step of embedding occurs within a network. The embedded DDoS signature is then sent from the network to an internet node outside of the network. The method further includes applying the DDoS signature to enable the internet nodes to filter packets matching the DDoS signature.