Distributed DDoS Early-Warning Nodes for Reliability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DDoS early-warning systems have poor reliability and security due to reliance on a single decision device, which can fail if it malfunctions or is overwhelmed by data processing demands, leading to network defense failures.
Innovation Solution
Implementing a distributed framework with multiple early-warning decision nodes that calculate and compare flow quantities based on weighted flow analysis results to determine abnormal conditions, allowing other nodes to take over if one fails, thereby enhancing reliability and processing capacity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single decision device is used in the DDoS early-warning system, then the device complexity is reduced and the system is easier to operate, but the reliability and security of the system deteriorate because the entire network defense fails when the single device malfunctions or is overwhelmed
Solution Approach 1:
The patent divides the single decision device into multiple distributed decision nodes. Each node independently performs flow analysis and makes early-warning decisions for a portion of service requests. This segmentation eliminates the single point of failure, improving system reliability while distributing the processing load across multiple nodes.
Solution Approach 2:
The patent combines multiple decision nodes into a distributed system that works together to provide comprehensive DDoS early-warning coverage. The nodes aggregate their flow analysis results to form a complete view of service request patterns, maintaining system coherence while benefiting from distributed reliability.
2Productivity
If a single decision device processes all flow analysis results, then the system structure is simple, but the processing capability and productivity are insufficient when the device is overwhelmed by data processing demands
Solution Approach 1:
The patent segments the processing of flow analysis results across multiple distributed decision nodes. Each node handles a specific portion of service requests, enabling parallel processing that significantly increases overall system productivity and prevents any single device from being overwhelmed.
Solution Approach 2:
The patent transitions from a single-device vertical processing architecture to a multi-node horizontal distributed architecture. This dimensional change allows the system to scale processing capability by adding more nodes, effectively increasing productivity without proportionally increasing central device burden.
3Reliability
If distributed nodes are implemented to improve reliability, then the system can continue operating if individual nodes fail, but the device complexity and system configuration become more complicated
Solution Approach 1:
The patent implements self-service mechanisms where distributed decision nodes automatically perform flow analysis, calculate flow quantities, and make early-warning decisions independently. Each node autonomously handles its assigned service requests without requiring complex manual configuration or coordination, simplifying operation despite the distributed architecture.
Solution Approach 2:
The patent incorporates feedback mechanisms where decision nodes continuously monitor service request flows and adjust their analysis and decisions based on real-time conditions. This automated feedback loop reduces the need for manual system configuration and maintenance, easing operational complexity while maintaining high reliability.
Data Source
AI summary
Early-warning decision method, node and system are provided in the present disclosure. The method includes obtaining a flow analysis result of a portion of service requests that are targeted at a same server; calculating a flow of all the service requests that are targeted at the server based on a flow indicated by the flow analysis result and a weight of a current distributed node, the weight being a weight or proportion of all the service requests targeted at the server that accounts for the flow indicated by the flow analysis result that is obtained by the current distributed node; comparing a flow of all the service requests that are targeted at the server with an abnormal flow threshold; and determining whether to send an instruction for performing subsequent processing on the server based on a comparison result.


