Distributed Security System for DDoS Mitigation in Multi-Tenant Data Centers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing DDoS Open Threat Signaling (DOTS) standards in a distributed security architecture is challenging due to the mismatch between data plane-based forwarders and control plane functionality, particularly in multi-tenant data centers or container networking architectures, where identifying DOTS clients and enforcing policies per node or pod is difficult and processor-intensive.
Innovation Solution
A distributed security system that includes a host computer with a host interface, processing machinery to instantiate worker nodes, security clients, and a security gateway agent to monitor and report malicious traffic, with a security server computing policies to mitigate attacks and enforcing them at domain ingress nodes or external nodes, leveraging DOTS architecture and extending it to a dynamic data plane signaled approach.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DOTS standards are implemented in a distributed security architecture with data plane-based forwarders, then security policy enforcement capability is improved, but device complexity and difficulty of identifying DOTS clients increases
Solution Approach 1:
The patent introduces a control plane-based security gateway as an intermediary between data plane forwarders and the DOTS server. This gateway aggregates security telemetry data from multiple forwarders and coordinates with the DOTS server, simplifying the architecture by reducing direct client-server connections and consolidating control functions in a dedicated security gateway component.
2Measurement precision
If security policies are enforced per node or pod in multi-tenant environments, then security precision is improved, but processing power consumption increases
Solution Approach 1:
The patent segments security client functionality into distributed security clients deployed on individual worker nodes or pods, while maintaining centralized coordination through the security gateway. This allows per-node security policy enforcement with precise control, while the gateway aggregates telemetry and manages policy distribution to reduce overall processing overhead compared to fully distributed enforcement.
Solution Approach 2:
The patent implements selective security monitoring where security clients on worker nodes monitor and report only relevant security telemetry data to the gateway, rather than performing complete security enforcement locally. This partial action approach reduces processing power consumption while maintaining security precision through centralized policy enforcement at the gateway for critical threats.
3Difficulty of detecting and measuring
If security telemetry is collected from all worker nodes, then detection capability is improved, but loss of time in processing and transmitting data increases
Solution Approach 1:
The patent merges security telemetry data from multiple worker nodes at the centralized security gateway, which aggregates and consolidates security events before processing. This combining approach improves detection capability by providing a comprehensive view of security threats across the infrastructure, while reducing time loss by processing aggregated data centrally rather than independently at each node.
Data Source
AI summary
In one embodiment, a system includes a first host computer including a host interface configured to receive traffic from a domain ingress node of a first domain, and processing machinery configured to instantiate worker nodes, instantiate a master node and a security gateway agent on the master node, instantiate a plurality of security clients on the worker nodes, wherein each worker node includes at least one security client, wherein each security client is configured to monitor at least part of the traffic being forwarded in the one worker node for malicious traffic, and report a first data item about the malicious traffic to the security gateway agent, and wherein the security gateway agent is configured to forward a second data item about the malicious traffic to a security server to determine at least one security policy to mitigate the malicious traffic, and to be enforced by a node.


