Dynamic TCP Settings for DDoS Resilience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Default server settings are inadequate to handle distributed denial of service (DDoS) attacks, leading to resource overload and increased recovery time, as they are optimized for normal operations rather than attack scenarios.

Innovation Solution

Automatically adjusting transport layer settings, such as TCP settings, to increase server tolerance during DDoS attacks by monitoring server conditions and making systematic changes to parameters like connection limits, memory allocation, and timeouts, while reverting to standard settings during normal operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If default server settings are used, then the server operates optimally under normal conditions, but the server becomes vulnerable to resource overload during DDoS attacks

Engineering Contradiction:
Improveserver performance under normal operationsVSAvoidserver availability during DDoS attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic adjustment of server settings based on real-time monitoring of attack conditions. The system automatically modifies TCP parameters such as connection limits, memory allocation, and timeout values in response to detected DDoS attacks, allowing the server to adapt its configuration from normal operation mode to attack mitigation mode and back, thereby resolving the contradiction between optimal normal performance and attack resilience

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes specific TCP protocol parameters dynamically based on attack detection. Key parameters including connection limits, memory allocation for connection tracking, and timeout values are modified when attacks are detected. This parameter adjustment allows the server to increase tolerance to attack traffic while maintaining normal operation efficiency when under attack

Inventive Principle:
Principle #35Parameter changes

2Reliability

If server settings are adjusted to increase tolerance during attacks, then server availability improves, but resource allocation becomes suboptimal during normal operations

Engineering Contradiction:
Improveserver availability during DDoS attacksVSAvoidserver performance during normal operations
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent employs periodic monitoring of server conditions to detect attack states and trigger setting adjustments. The system continuously monitors incoming traffic patterns and server resource usage, switching between normal and attack mitigation configurations based on detected conditions. This periodic assessment ensures settings are optimized for current operational context, preventing permanent suboptimal resource allocation

Inventive Principle:
Principle #19Periodic action

3Use of energy by moving object

If default settings are maintained, then resource allocation is efficient for normal traffic, but recovery time increases after attacks

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidrecovery time after DDoS attacks
Core Design Contradiction:
Use of energy by moving objectVSLoss of time

Solution Approach 1:

The patent prepares the server by pre-configuring attack mitigation settings that can be rapidly activated when attacks are detected. Rather than waiting for resource exhaustion to occur, the system proactively adjusts parameters such as connection limits and memory allocation before the server becomes overwhelmed, enabling faster recovery by preventing complete resource depletion in the first place

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11190532B2Dynamic configuration of settings in response to DDoS attack
Publication Date: 2021.11.30 LEVEL 3 COMMUNICATIONS LLC
  • US11190532B2 patent drawing
  • US11190532B2 patent drawing

AI summary

A system can monitor the server for indications of an attack and adjusts server settings accordingly. In response, the system can increase server tolerance in a systematic way to deal with DDoS by adjusting server settings appropriately. Conversely, when the server is not under attack, the settings can be adjusted to those for standard operations (e.g., adjusted downward), as they are more optimal for normal, non-attack operations.