Dynamic DDOS Traffic Isolation via Virtual Circuit Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing traffic management techniques in communications networks are inefficient in distinguishing and isolating distributed denial of service (DDOS) traffic from legitimate traffic, often resulting in the disruption of legitimate communications during attack mitigation.
Innovation Solution
A dynamic traffic management system utilizing an intelligent route service control point (IRSCP) that monitors and reroutes DDOS traffic to a cleaning center, dynamically adjusting edge router routing information using BGP and IBGP protocols to isolate and remove attacking traffic while ensuring legitimate traffic reaches its destination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic management techniques are used to stop DDOS traffic, then the server is protected from attack, but legitimate traffic is also disrupted
Solution Approach 1:
The patent segments traffic flow at the router level by implementing individual virtual circuits for different traffic sources. Each virtual circuit can be independently controlled, allowing the system to distinguish between DDOS traffic from specific sources and legitimate traffic from other sources, thereby protecting the server while maintaining legitimate communications.
Solution Approach 2:
The patent applies local quality control by assigning different handling characteristics to different virtual circuits. DDOS traffic on specific virtual circuits is blocked or redirected, while legitimate traffic on other virtual circuits continues uninterrupted. This localized differentiation enables selective traffic management that protects the server without disrupting overall network productivity.
2Reliability
If network traffic is deactivated to stop DDOS traffic flow, then the attacked server is protected, but network productivity decreases
Solution Approach 1:
The patent divides network traffic into separate virtual circuits identified by source addresses, destination addresses, and protocol types. This segmentation allows the system to selectively deactivate only the specific virtual circuits carrying DDOS traffic while keeping other virtual circuits active, thus protecting the server without unnecessarily reducing overall network productivity.
Solution Approach 2:
Instead of deactivating all traffic to the attacked server (excessive action), the patent implements partial action by targeting only the specific virtual circuits identified as carrying DDOS traffic. This selective approach removes harmful traffic while preserving legitimate traffic flow, thereby protecting the server with minimal impact on network productivity.
3Reliability
If traffic is reflected by the router servicing the attacked server, then DDOS traffic is stopped, but legitimate traffic is also affected
Solution Approach 1:
The patent segments traffic handling by implementing separate virtual circuits for different traffic sources. The router can selectively reflect or block traffic on specific virtual circuits identified as DDOS traffic, while allowing legitimate traffic on other virtual circuits to pass through normally. This segmentation enables efficient traffic handling that protects the server without unnecessarily affecting legitimate operations.
Solution Approach 2:
The patent applies local quality differentiation by assigning different handling policies to different virtual circuits. DDOS traffic on specific virtual circuits is reflected or blocked, while legitimate traffic on other virtual circuits continues uninterrupted. This localized approach improves traffic handling efficiency by treating different traffic types differently, rather than applying a blanket reflection policy that would affect all traffic.
Data Source
AI summary
A method and apparatus for providing traffic management for distributed denial of service (DDOS) traffic. Within a communications network, a DDOS detection system monitors network traffic to identify traffic that is designed to attack a particular server within the network and their entry points into the network. A traffic routing control unit is requested to deny service to the DDOS traffic. By selectively manipulating the routing information propagated to network edge routers, the traffic that is denied service is limited to mostly DDOS traffic and is routed to a cleaning center or a null address in the most effective fashion.


