Dynamic Internet Circuit Selection for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network threat mitigation systems face challenges in effectively addressing distributed denial-of-service (DDoS) attacks, as malicious traffic often originates from multiple sources, making it difficult to identify and block, and existing solutions require manual configuration which is time-consuming and inefficient.

Innovation Solution

A method for dynamically identifying and filtering Internet circuits based on qualification criteria, automatically configuring threat mitigation systems to use selected Internet Protocol (IP) addresses and scrubbing centers, and routing clean traffic through encapsulation tunnels or provider Internet circuits, allowing for quicker setup and improved protection against DDoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual configuration is used for threat mitigation systems, then setup accuracy can be ensured, but setup time increases significantly

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidsetup time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system automatically identifies Internet circuits associated with the target system, filters them based on qualification criteria, and configures the threat mitigation system without requiring manual intervention. The system serves itself by autonomously completing the configuration process, thereby eliminating the time-consuming manual setup while maintaining accuracy through automated qualification filtering.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary filtering of Internet circuits based on qualification criteria before the actual configuration is needed. By pre-identifying and filtering suitable circuits, the system prepares the configuration data in advance, which speeds up the overall setup process while ensuring that only qualified circuits are considered for configuration.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated filtering of Internet circuits is implemented, then configuration speed increases, but system complexity increases

Engineering Contradiction:
Improveconfiguration speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The automated filtering process is divided into distinct segments: identifying Internet circuits associated with the target system, filtering circuits based on qualification criteria, and selecting circuits for configuration. This segmentation of the filtering process into manageable stages reduces the perceived complexity while maintaining high configuration speed, as each segment can be processed independently and systematically.

Inventive Principle:
Principle #1Segmentation

3Reliability

If multiple Internet circuits are monitored for DDoS attacks, then detection capability improves, but analysis complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidanalysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and isolates specific Internet circuits that are associated with the target system from the broader network infrastructure. By focusing only on the relevant circuits rather than analyzing all network traffic, the system improves detection capability for DDoS attacks on monitored circuits while reducing analysis complexity by excluding unrelated network elements from the monitoring scope.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20230300110A1Systems and methods for dynamically determining compatible internet circuits for threat mitigation services
Publication Date: 2023.09.21 LEVEL 3 COMMUNICATIONS LLC
  • US20230300110A1 patent drawing
  • US20230300110A1 patent drawing
  • US20230300110A1 patent drawing

AI summary

An automatic provisioning and configuration system for threat mitigation may be provided. Hardware and software resources may be automatically configured to designate a return path for forwarding clean data packets to a target network. A return path from a scrubbing center to the target network may be selected and configured, for example, based on the geographic location of the scrubbing center and information regarding available capacity of the return path to the target network, among other information. The system may provide for selection a list of Internet circuits already used by the customer. The system may also perform a set of dynamic checks to determine whether one or more of the Internet circuits are eligible for use for the return traffic.