Multi-Tiered Security System for Denial-of-Service Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer systems are vulnerable to denial-of-service and SYN-flood attacks, which can exhaust resources and disrupt communications, leading to severe degradation or complete disruption of electronic communications, particularly in critical infrastructure like domain-name servers and Internet-based services.

Innovation Solution

A multi-tiered security system incorporating probabilistic packet droppers, packet-rate throttles, resource controls, and automated firewalls, along with efficient connection-state-information storage and distribution, is implemented to prevent resource exhaustion and mitigate these attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If computer systems are highly interconnected through high-bandwidth electronic communications systems, then communication benefits and productivity are enormously improved, but vulnerability to denial-of-service attacks and resource-draining phenomena increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidvulnerability to attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the communication processing system into multiple independent components: connection request handlers, state information storage systems, and resource management modules. This segmentation allows the system to isolate and protect critical resources from overwhelming connection requests by distributing the handling of communication tasks across separate functional units, thereby maintaining communication efficiency while reducing vulnerability to denial-of-service attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a state information storage system that mediates between incoming connection requests and the core processing resources. This intermediary layer buffers and manages connection state information, preventing direct resource exhaustion of critical system components while maintaining efficient communication processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If resource controls and packet filtering mechanisms are implemented to prevent attacks, then system security is improved, but communication throughput and productivity may deteriorate

Engineering Contradiction:
Improvesystem securityVSAvoidcommunication throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-allocating and pre-managing connection state information storage resources before attacks occur. The system establishes predetermined resource limits and storage capacities in advance, enabling it to automatically throttle and filter excessive connection requests without requiring complex real-time analysis. This preliminary configuration maintains system security while minimizing impact on legitimate communication throughput.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs parameter changes by dynamically adjusting resource allocation parameters and filtering thresholds based on system conditions. The state information storage system modifies storage capacity parameters and request handling parameters in response to detected attack patterns, thereby maintaining security reliability while preserving communication throughput for legitimate traffic.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8341727B2Method and system for protecting a computer system from denial-of-service attacks and other deleterious resource-draining phenomena related to communications
Publication Date: 2012.12.25 SECURE64 SOFTWARE CORP
  • US8341727B2 patent drawing
  • US8341727B2 patent drawing
  • US8341727B2 patent drawing

AI summary

Embodiments of the present invention include a variety of different integrated, multi-tiered methods and systems for preventing various types of attacks on computer systems, including denial-of-service attacks and SYN-flood attacks. Components of these integrated methods and systems include probabilistic packet droppers, packet-rate throttles, resource controls, automated firewalls, and efficient connection-state-information storage in memory resources and connection-state-information distribution in order to prevent draining of sufficient communications-related resources within a computer system to seriously degrade or disable electronics communications components within the computer system.