Dynamic Traffic Regulation for DoS Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Defending against network attacks, particularly Denial-of-Service (DoS) attacks, is challenging due to the complexity of managing security measures across large networks with numerous computing resources, where existing solutions struggle to dynamically regulate traffic effectively.

Innovation Solution

Implementing dynamic traffic regulation mechanisms that adjust available bandwidth by deploying traffic regulators capable of packet processing, prioritization, and routing, which can be configured based on the packet processing capabilities of computing resources and health information to manage traffic flow during attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (firewalls, routers, switches) are deployed to defend against network attacks, then network security is improved, but device complexity and difficulty of management increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidcomplexity of managing security measures
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions (firewall, router, switch, traffic regulation) into a single integrated traffic regulator device. This consolidation reduces the number of separate components that need to be managed while maintaining comprehensive security capabilities, directly addressing the complexity issue while preserving security effectiveness.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The traffic regulator is designed as a multi-functional device that can perform packet filtering, routing, switching, and dynamic bandwidth regulation simultaneously. This universal device replaces multiple specialized security components, simplifying the overall system architecture and management overhead while maintaining robust security defense.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If static bandwidth allocation is used in network security measures, then device complexity is reduced, but adaptability to dynamic attack conditions deteriorates

Engineering Contradiction:
Improvedynamic traffic regulation capabilityVSAvoidcomplexity of traffic regulation mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The traffic regulator implements dynamic bandwidth allocation that automatically adjusts traffic flow parameters based on real-time network conditions and detected attack patterns. This dynamic capability allows the system to adapt to changing attack conditions without manual intervention, achieving high adaptability while the automated nature keeps operational complexity manageable.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms that monitor network traffic patterns and automatically adjust bandwidth allocation in response to detected attacks. This closed-loop control enables the traffic regulator to learn from and respond to attack conditions, providing adaptability while the automated feedback process reduces the need for complex manual configuration.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple security devices are deployed throughout the network, then network security coverage is improved, but ease of operation and management deteriorates

Engineering Contradiction:
Improvenetwork security coverageVSAvoidease of managing security measures
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By consolidating firewall, routing, switching, and traffic regulation functions into a single integrated device, the patent reduces the number of separate security components that operators must configure and manage. This merger maintains comprehensive security coverage while significantly improving ease of operation through centralized management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The universal traffic regulator device performs multiple security functions simultaneously, eliminating the need for operators to manage multiple specialized devices. This multi-functionality approach maintains broad security coverage while simplifying operational procedures and reducing management overhead.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9847970B1Dynamic traffic regulation
Publication Date: 2017.12.19 AMAZON TECH INC
  • US9847970B1 patent drawing
  • US9847970B1 patent drawing
  • US9847970B1 patent drawing

AI summary

Functionality is disclosed herein for regulating bandwidth that is available for network traffic flowing through a data communications network. In response to attack traffic being detected, one or more traffic regulators are set to control an available bandwidth to be used by the attack traffic. The one or more traffic regulators are adjusted until an attack is no longer detected. After the attack ends, the traffic regulator may be disabled or set to a different mode of operation.