Multi-Tiered Security System for Denial-of-Service Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer systems are vulnerable to denial-of-service and SYN-flood attacks, which can exhaust resources and disrupt communications, leading to severe degradation or complete disruption of electronic communications, particularly in critical infrastructure like domain-name servers and Internet-based services.
Innovation Solution
A multi-tiered security system incorporating probabilistic packet droppers, packet-rate throttles, resource controls, and automated firewalls, along with efficient connection-state-information storage and distribution, is implemented to prevent resource exhaustion and mitigate these attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If computer systems are highly interconnected through high-bandwidth electronic communications systems, then communication benefits and productivity are enormously improved, but vulnerability to denial-of-service attacks and resource-draining phenomena increases
Solution Approach 1:
The patent segments the communication processing system into multiple independent components: connection request handlers, state information storage systems, and resource management modules. This segmentation allows the system to isolate and protect critical resources from overwhelming connection requests by distributing the handling of communication tasks across separate functional units, thereby maintaining communication efficiency while reducing vulnerability to denial-of-service attacks.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a state information storage system that mediates between incoming connection requests and the core processing resources. This intermediary layer buffers and manages connection state information, preventing direct resource exhaustion of critical system components while maintaining efficient communication processing.
2Reliability
If resource controls and packet filtering mechanisms are implemented to prevent attacks, then system security is improved, but communication throughput and productivity may deteriorate
Solution Approach 1:
The patent implements preliminary action by pre-allocating and pre-managing connection state information storage resources before attacks occur. The system establishes predetermined resource limits and storage capacities in advance, enabling it to automatically throttle and filter excessive connection requests without requiring complex real-time analysis. This preliminary configuration maintains system security while minimizing impact on legitimate communication throughput.
Solution Approach 2:
The patent employs parameter changes by dynamically adjusting resource allocation parameters and filtering thresholds based on system conditions. The state information storage system modifies storage capacity parameters and request handling parameters in response to detected attack patterns, thereby maintaining security reliability while preserving communication throughput for legitimate traffic.
Data Source
AI summary
Embodiments of the present invention include a variety of different integrated, multi-tiered methods and systems for preventing various types of attacks on computer systems, including denial-of-service attacks and SYN-flood attacks. Components of these integrated methods and systems include probabilistic packet droppers, packet-rate throttles, resource controls, automated firewalls, and efficient connection-state-information storage in memory resources and connection-state-information distribution in order to prevent draining of sufficient communications-related resources within a computer system to seriously degrade or disable electronics communications components within the computer system.


