Distributed Security System for DDoS Mitigation in Multi-Tenant Data Centers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing DDoS Open Threat Signaling (DOTS) standards in a distributed security architecture is challenging due to the mismatch between data plane-based forwarders and control plane functionality, particularly in multi-tenant data centers or container networking architectures, where identifying DOTS clients and enforcing policies per node or pod is difficult and processor-intensive.

Innovation Solution

A distributed security system that includes a host computer with a host interface, processing machinery to instantiate worker nodes, security clients, and a security gateway agent to monitor and report malicious traffic, with a security server computing policies to mitigate attacks and enforcing them at domain ingress nodes or external nodes, leveraging DOTS architecture and extending it to a dynamic data plane signaled approach.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DOTS standards are implemented in a distributed security architecture with data plane-based forwarders, then security policy enforcement capability is improved, but device complexity and difficulty of identifying DOTS clients increases

Engineering Contradiction:
Improvesecurity policy enforcement capabilityVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a control plane-based security gateway as an intermediary between data plane forwarders and the DOTS server. This gateway aggregates security telemetry data from multiple forwarders and coordinates with the DOTS server, simplifying the architecture by reducing direct client-server connections and consolidating control functions in a dedicated security gateway component.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security policies are enforced per node or pod in multi-tenant environments, then security precision is improved, but processing power consumption increases

Engineering Contradiction:
Improvesecurity policy enforcement precisionVSAvoidprocessing power consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments security client functionality into distributed security clients deployed on individual worker nodes or pods, while maintaining centralized coordination through the security gateway. This allows per-node security policy enforcement with precise control, while the gateway aggregates telemetry and manages policy distribution to reduce overall processing overhead compared to fully distributed enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements selective security monitoring where security clients on worker nodes monitor and report only relevant security telemetry data to the gateway, rather than performing complete security enforcement locally. This partial action approach reduces processing power consumption while maintaining security precision through centralized policy enforcement at the gateway for critical threats.

Inventive Principle:
Principle #16Partial or excessive action

3Difficulty of detecting and measuring

If security telemetry is collected from all worker nodes, then detection capability is improved, but loss of time in processing and transmitting data increases

Engineering Contradiction:
Improvemalicious traffic detection capabilityVSAvoiddata processing and transmission time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The patent merges security telemetry data from multiple worker nodes at the centralized security gateway, which aggregates and consolidates security events before processing. This combining approach improves detection capability by providing a comprehensive view of security threats across the infrastructure, while reducing time loss by processing aggregated data centrally rather than independently at each node.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10567441B2Distributed security system
Publication Date: 2020.02.18 CISCO TECHNOLOGY INC
  • US10567441B2 patent drawing
  • US10567441B2 patent drawing
  • US10567441B2 patent drawing

AI summary

In one embodiment, a system includes a first host computer including a host interface configured to receive traffic from a domain ingress node of a first domain, and processing machinery configured to instantiate worker nodes, instantiate a master node and a security gateway agent on the master node, instantiate a plurality of security clients on the worker nodes, wherein each worker node includes at least one security client, wherein each security client is configured to monitor at least part of the traffic being forwarded in the one worker node for malicious traffic, and report a first data item about the malicious traffic to the security gateway agent, and wherein the security gateway agent is configured to forward a second data item about the malicious traffic to a security server to determine at least one security policy to mitigate the malicious traffic, and to be enforced by a node.