DDoS Defense via Terminal Shield and Control Server Coordination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems fail to efficiently detect and mitigate Distributed Denial of Service (DDoS) attacks at the source, particularly in identifying and blocking attacks from multiple terminals.

Innovation Solution

A method and system where an attack target server determines if it is under DDoS attack, informs a control server, which then transmits an attack prevention message to terminals, and these terminals block the attack based on their determination, using modules for connection, monitoring, and blocking data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional backbone-based network control is used to defend DDoS attacks, then network security is maintained to some extent, but the system cannot detect attacks within attack agent terminals and cannot deal with corresponding sources properly and efficiently

Engineering Contradiction:
ImproveDDoS attack defense capabilityVSAvoidAttack detection capability at terminal level
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The invention segments the DDoS defense function into two parts: a control server that manages coordination and a shield program distributed to individual terminals that performs local detection and blocking. This segmentation enables terminal-level attack detection while maintaining centralized coordination, resolving the contradiction between network-wide security and localized detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The shield program enables terminals to autonomously detect and block DDoS attacks originating from themselves or their local network. Each terminal with the shield program can independently identify attack patterns and block malicious traffic without requiring external intervention, thereby achieving self-service defense at the terminal level.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If conventional security devices are used, then basic network protection is provided, but attacks cannot be detected within attack agent terminals and corresponding sources cannot be dealt with properly and efficiently

Engineering Contradiction:
ImproveNetwork attack protectionVSAvoidAttack response efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The shield program is installed in advance on terminals before attacks occur. This preliminary action enables the system to detect and block attacks at the source immediately when they occur, rather than reacting after detection by external devices. The pre-installed shield program can quickly identify attack patterns and block malicious traffic, significantly improving response efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The control server receives attack information from the shield program and sends blocking instructions back to relevant terminals. This feedback mechanism enables rapid coordinated response: when an attack is detected, the control server processes the information and directs affected terminals to block the attack source, creating an efficient closed-loop defense system.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2161898B1Method and system for defending DDoS attack
Publication Date: 2014.10.22 ESTSOFT CORP
  • EP2161898B1 patent drawingFigure 1
  • EP2161898B1 patent drawingFigure 2
  • EP2161898B1 patent drawingFigure 3

AI summary

In a method of defending a Distributed Denial of Service (DDoS) attack, an attack target server determines whether the attack target server suffers a DDoS attack from a plurality of terminals and, according to a result of the determination, informs a control server that the attack target server suffers the DDoS attack by transmitting its own information to the control server. The control server which has received the information of the attack target server confirms the plurality of terminals which transmits data to the attack target server and transmits an attack prevention message to the plurality of confirmed terminals. Each of the plurality of terminals which has received the attack prevention message determines whether the terminal launches the DDoS attack and, according to a result of the determination, blocking the DDoS attack.