DDoS Attack Source Identification via DNS Distribution Hashing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content delivery systems face challenges in identifying and mitigating distributed denial-of-service (DDoS) attacks due to the limited uniqueness of network addresses, making it difficult to determine the target distribution and implement effective mitigation strategies.

Innovation Solution

Assigning unique or semi-unique combinations of network addresses to each distribution using hashing algorithms, allowing for identification of attacked distributions even when only a subset of network addresses is targeted, and implementing mitigation techniques such as halting DNS queries and blackholing to limit attack impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If network addresses are reused across multiple distributions to improve address utilization, then the quantity of usable network addresses increases, but the ability to uniquely identify attacked distributions during DDoS attacks deteriorates

Engineering Contradiction:
Improvequantity of usable network addressesVSAvoidprecision of identifying attacked distribution
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent segments the identification problem by introducing distribution-specific identifiers (such as hashing the distribution name or using resource records) that are embedded within DNS queries. This allows the system to maintain address reuse while adding a unique segmentation element that enables precise identification of the targeted distribution during attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary identification mechanism - a distribution-specific identifier that acts as a mediator between the reused network address and the target distribution. This intermediary element (embedded in DNS queries or resource records) enables precise identification without requiring unique network addresses for each distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If network addresses are uniquely assigned to each distribution to improve attack identification, then the precision of identifying attacked distributions increases, but the quantity of required network addresses increases

Engineering Contradiction:
Improveprecision of identifying attacked distributionVSAvoidquantity of required network addresses
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent merges the network address with distribution-specific identification information by embedding identifiers within DNS query structures or resource records. This combination allows the system to use a smaller pool of network addresses while maintaining the ability to uniquely identify distributions through the combined address-identifier pair.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent adds another dimension to network address identification by incorporating distribution-specific identifiers (such as hashed distribution names or resource record types) into the DNS query structure. This dimensional addition allows precise identification without requiring additional network address space.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If DDoS attacks are mitigated by blocking all traffic to attacked network addresses, then the reliability of the attacked distribution improves, but the availability of non-attacked distributions deteriorates

Engineering Contradiction:
Improvereliability of attacked distributionVSAvoidavailability of non-attacked distributions
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by enabling differentiated treatment of traffic based on the distribution-specific identifier embedded in DNS queries. This allows the system to block traffic targeted at a specific distribution while permitting traffic to other distributions, achieving localized mitigation that preserves overall system availability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by blocking only the specific distribution identifier associated with the attack rather than all traffic to the network address. This selective blocking mitigates the attack on the targeted distribution while maintaining service availability for non-attacked distributions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9794281B1Identifying sources of network attacks
Publication Date: 2017.10.17 AMAZON TECH INC
  • US9794281B1 patent drawing
  • US9794281B1 patent drawing
  • US9794281B1 patent drawing

AI summary

Systems and methods are described to enable identification of computing devices associated with network attacks, such as denial of service attacks. Data packets used to execute a network attack often include forged source address information, such that the address of an attacker is difficult or impossible to determine based on those data packets. However, attackers generally provide legitimate address information when resolving an identifier, such as a universal resource identifier (URI), of an attack target into corresponding destination addresses. The application enables individual client computing devices to be provided with different combinations of destination addresses, such that when an attack is detected on a given combination of destination address, the client computing device to which that combination of destination addresses was provided can be identified as a source of the attack.