Edge Network Defense Policy for Attack Packet Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network attack defense methods require high costs and inefficiently use network resources, as they rely on special cleaning devices and allow network attack packets to transmit extensively before being addressed.
Innovation Solution
A method and apparatus that send a defense policy to the first edge network device when a network attack packet is detected, instructing it to process and discard packets destined for a target IP address, thereby reducing transmission and resource usage within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a cleaning device is deployed to identify and discard network attack packets, then the network attack packets can be cleaned, but the deployment cost is high and network resources are occupied during transmission to the cleaning device
Solution Approach 1:
The patent applies preliminary action by sending defense policies to edge network devices before attack packets enter the network. The edge devices are pre-configured with policies that enable them to identify and discard attack packets autonomously, eliminating the need for centralized cleaning devices and reducing deployment complexity while maintaining defense effectiveness.
Solution Approach 2:
The patent extracts the attack packet filtering function from centralized cleaning devices and relocates it to edge network devices. This distribution of functionality allows edge devices to independently handle attack packets, reducing the need for expensive centralized infrastructure and minimizing network resource occupation during packet transmission.
2Reliability
If network attack packets are transmitted to a cleaning device for processing, then the attack packets can be identified and discarded, but network resources are occupied during the transmission process
Solution Approach 1:
The patent converts the harmful effect of attack packet transmission into a benefit by using the edge network devices' existing packet forwarding capability. Instead of transmitting attack packets across the network to cleaning devices, the edge devices use their normal packet processing functions to identify and discard attack packets locally, turning potential resource waste into an efficient defense mechanism.
Solution Approach 2:
The patent enables edge network devices to self-serve in defending against network attacks by providing them with defense policies. These policies allow edge devices to autonomously identify and discard attack packets without requiring centralized cleaning devices, thereby eliminating network resource occupation during packet transmission while maintaining effective attack packet filtering.
Data Source
AI summary
A network attack defense policy sending method and apparatus are presented. The method includes receiving attack information which includes a target Internet Protocol (IP) address, and the attack information is used to indicate that a network attack packet whose destination address is the target IP address exists in a first network; determining that the network attack packet enters the first network through a first edge network device, where the first edge network device is an edge device in the first network; sending a defense policy to the first edge network device, where the defense policy is used to instruct the first edge network device to process, according to the defense policy, a packet whose destination address is the target IP address. By means of this application, network resources occupied by a network attack packet can be reduced, and an effect of defending against the network attack packet can be improved.


