DDoS Attack Source Identification via DNS Distribution Hashing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Content delivery systems face challenges in identifying and mitigating distributed denial-of-service (DDoS) attacks due to the limited uniqueness of network addresses, making it difficult to determine the target distribution and implement effective mitigation strategies.
Innovation Solution
Assigning unique or semi-unique combinations of network addresses to each distribution using hashing algorithms, allowing for identification of attacked distributions even when only a subset of network addresses is targeted, and implementing mitigation techniques such as halting DNS queries and blackholing to limit attack impact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If network addresses are reused across multiple distributions to improve address utilization, then the quantity of usable network addresses increases, but the ability to uniquely identify attacked distributions during DDoS attacks deteriorates
Solution Approach 1:
The patent segments the identification problem by introducing distribution-specific identifiers (such as hashing the distribution name or using resource records) that are embedded within DNS queries. This allows the system to maintain address reuse while adding a unique segmentation element that enables precise identification of the targeted distribution during attacks.
Solution Approach 2:
The patent introduces an intermediary identification mechanism - a distribution-specific identifier that acts as a mediator between the reused network address and the target distribution. This intermediary element (embedded in DNS queries or resource records) enables precise identification without requiring unique network addresses for each distribution.
2Measurement precision
If network addresses are uniquely assigned to each distribution to improve attack identification, then the precision of identifying attacked distributions increases, but the quantity of required network addresses increases
Solution Approach 1:
The patent merges the network address with distribution-specific identification information by embedding identifiers within DNS query structures or resource records. This combination allows the system to use a smaller pool of network addresses while maintaining the ability to uniquely identify distributions through the combined address-identifier pair.
Solution Approach 2:
The patent adds another dimension to network address identification by incorporating distribution-specific identifiers (such as hashed distribution names or resource record types) into the DNS query structure. This dimensional addition allows precise identification without requiring additional network address space.
3Reliability
If DDoS attacks are mitigated by blocking all traffic to attacked network addresses, then the reliability of the attacked distribution improves, but the availability of non-attacked distributions deteriorates
Solution Approach 1:
The patent applies local quality by enabling differentiated treatment of traffic based on the distribution-specific identifier embedded in DNS queries. This allows the system to block traffic targeted at a specific distribution while permitting traffic to other distributions, achieving localized mitigation that preserves overall system availability.
Solution Approach 2:
The patent implements partial action by blocking only the specific distribution identifier associated with the attack rather than all traffic to the network address. This selective blocking mitigates the attack on the targeted distribution while maintaining service availability for non-attacked distributions.
Data Source
AI summary
Systems and methods are described to enable identification of computing devices associated with network attacks, such as denial of service attacks. Data packets used to execute a network attack often include forged source address information, such that the address of an attacker is difficult or impossible to determine based on those data packets. However, attackers generally provide legitimate address information when resolving an identifier, such as a universal resource identifier (URI), of an attack target into corresponding destination addresses. The application enables individual client computing devices to be provided with different combinations of destination addresses, such that when an attack is detected on a given combination of destination address, the client computing device to which that combination of destination addresses was provided can be identified as a source of the attack.


