DOCSIS Network Traffic Throttling for DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
DOCSIS 1.x networks face challenges in managing quality of service (QoS) and defending against distributed denial-of-service (DDoS) attacks, which can lead to network congestion and service degradation due to excessive bandwidth consumption by malicious subscribers or infected devices.
Innovation Solution
The PacketCable Multimedia (PCMM) architecture is used to dynamically monitor and throttle excessive bandwidth usage on a per-subscriber and per-application basis by identifying affected devices through traffic monitoring and implementing policies to restrict access to specific ports, thereby protecting the network without affecting other subscribers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DOCSIS 1.x networks allow unrestricted bandwidth usage, then network capacity and service availability are maintained, but the network becomes vulnerable to DDoS attacks and excessive bandwidth consumption by malicious subscribers
Solution Approach 1:
The patent segments the network traffic into different service flows with distinct QoS parameters. Each service flow is assigned a unique SFID and can be independently policed and shaped. This segmentation allows the network to identify and restrict malicious traffic while maintaining normal service operations, resolving the contradiction between network security and management complexity by organizing traffic control into manageable units.
Solution Approach 2:
The patent introduces an intermediary QoS enforcement mechanism between the CM and CMTS that automatically polices and shapes traffic based on pre-configured service flow parameters. This intermediary layer handles the complexity of traffic management, allowing the network to enforce security policies without requiring complex real-time decision-making at each network node, thus improving reliability while managing complexity.
2Reliability
If the network implements comprehensive traffic monitoring and throttling policies, then DDoS attacks are mitigated and network quality is maintained, but the system complexity and processing overhead increase
Solution Approach 1:
The patent implements preliminary action by pre-configuring service flow parameters, QoS policies, and policing rules before traffic arrives. The CMTS is pre-programmed with service flow templates that define bandwidth limits, priority levels, and classification criteria. When traffic arrives, the system simply matches packets against these pre-defined templates rather than making complex decisions in real-time, thereby maintaining network quality while reducing system complexity and processing overhead.
Solution Approach 2:
The patent employs feedback mechanisms where the traffic monitoring system continuously observes network conditions and automatically adjusts traffic management policies based on observed patterns. The system monitors service flow performance, detects anomalies indicating DDoS attacks, and dynamically modifies policing parameters to maintain network quality. This feedback loop automates the response to threats, reducing the need for complex manual intervention while maintaining high network quality.
3Productivity
If the network restricts bandwidth for identified malicious devices, then DDoS attack impact is reduced, but legitimate services from those devices may also be affected
Solution Approach 1:
The patent applies local quality by implementing differentiated QoS treatment for different service flows from the same device. Instead of blocking all traffic from a potentially malicious device, the system selectively applies policing and shaping only to specific service flows that match malicious patterns. Legitimate service flows from the same device continue to operate with normal QoS parameters, thereby improving network resource efficiency while avoiding collateral service disruption through precise, localized traffic control.
Data Source
AI summary
A system and method for mitigating a denial of service attack in a subscriber network. A traffic monitor monitors bandwidth usage of a subscriber network that is directed to a particular port. The traffic monitor detects excessive traffic based on preset thresholds or algorithms. When excessive traffic is detected, the traffic monitor may obtain the source IP address from headers in the packet stream and identify the device or devices from which the packets were delivered to the network. Using the IP addresses of affected devices, a policy may be implemented to throttle packets originating from those devices that are directed to the particular port.


