Encapsulation Tunnel Provisioning with Dynamic Capacity Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face challenges in mitigating DDoS attacks, where malicious actors overwhelm network components by flooding them with superfluous requests, making it difficult to distinguish legitimate from malicious traffic due to spoofed IP addresses.

Innovation Solution

A system dynamically identifies available capacity of threat mitigation systems and automatically configures encapsulation tunnels based on desired capacity to forward clean packets, using scrubbing centers and provider Internet circuits to protect target services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration of encapsulation tunnels is used, then setup time is reduced and control is precise, but operational complexity increases and response speed to attacks decreases

Engineering Contradiction:
ImproveConfiguration simplicityVSAvoidSetup time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs self-configuration by automatically detecting attack patterns, calculating optimal tunnel parameters, and provisioning encapsulation tunnels without manual intervention. The threat mitigation system autonomously monitors network traffic, identifies DDoS attacks, and configures appropriate mitigation capabilities including tunnel establishment and bandwidth allocation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures multiple encapsulation tunnel templates with different bandwidth capacities and routing paths before attacks occur. When an attack is detected, the system can immediately activate pre-prepared tunnel configurations, significantly reducing the response time from minutes to seconds.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If fixed bandwidth allocation is used for encapsulation tunnels, then configuration is simple, but adaptability to varying attack intensities deteriorates

Engineering Contradiction:
ImproveBandwidth flexibilityVSAvoidConfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements dynamic bandwidth allocation where encapsulation tunnel capacities are automatically adjusted based on real-time attack characteristics. The threat mitigation system continuously monitors attack intensity, traffic patterns, and tunnel performance, then dynamically modifies bandwidth allocation and routing decisions to optimize mitigation effectiveness while managing resources efficiently.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes key parameters including tunnel bandwidth capacity, routing paths, and traffic filtering rules based on attack severity and type. By dynamically adjusting these parameters rather than using fixed configurations, the system adapts to varying attack intensities and patterns while maintaining operational simplicity through automated parameter optimization.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple scrubbing centers are deployed, then mitigation capacity increases, but system complexity and capacity management difficulty increase

Engineering Contradiction:
ImproveMitigation capacityVSAvoidSystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the threat mitigation function across multiple scrubbing centers, each handling specific traffic flows or attack types. This segmentation increases overall mitigation capacity and reliability by distributing the workload, while the centralized control plane manages the complexity of coordinating multiple centers through automated traffic steering and capacity allocation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal threat mitigation platform where scrubbing centers can handle multiple attack types (DDoS, botnet traffic, application-layer attacks) and serve multiple customers. This multi-functionality increases reliability and capacity utilization while reducing overall system complexity by providing standardized mitigation capabilities across the network infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12401682B2Systems and methods for configuring encapsulation tunnels based on dynamic capacity checks
Publication Date: 2025.08.26 LEVEL 3 COMMUNICATIONS LLC
  • US12401682B2 patent drawing
  • US12401682B2 patent drawing
  • US12401682B2 patent drawing

AI summary

An automatic provisioning and configuration system for threat mitigation may be provided. Hardware and software resources may be automatically configured to designate a return path for forwarding clean data packets to a target network. A return path from a scrubbing center to the target network may be selected and configured, for example, based on the geographic location of the scrubbing center and information regarding available capacity of the return path to the target network, among other information. The system may also perform a set of dynamic checks to determine whether one or more scrubbing centers have capacity (and/or are likely to continue to have capacity) to provide an encapsulation tunnel between the scrubbing center and the target network for clean return traffic.