Edge Server Traffic Routing for BGP Hijacking Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for managing traffic between devices and origin servers are inadequate in mitigating Border Gateway Protocol (BGP) hijacking, which often require manual intervention and significant infrastructure changes, making them impractical for widespread deployment.
Innovation Solution
A method and system utilizing a distributed network of edge servers deployed across multiple autonomous systems (AS) that act as intermediaries between clients and origin servers, employing DNS resolution, secure tunnels, and subnet management to dynamically route traffic, detect hijacking attempts, and reconfigure edge servers to secure tunnels or alternate subnets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods are used to address BGP hijacking, then security against hijacking is improved, but implementation complexity and infrastructure changes increase significantly
Solution Approach 1:
The patent introduces a DNS-based intermediary system that sits between clients and origin servers. Instead of directly connecting to origin servers, clients resolve DNS names to DNS server IP addresses, which then redirect to load balancer IP addresses. This multi-layer intermediary approach provides security against BGP hijacking without requiring fundamental infrastructure changes, as it works within the existing DNS and networking stack.
Solution Approach 2:
The system segments the network path into distinct functional layers: DNS resolution layer, load balancing layer, and origin server layer. Each layer handles specific functions independently - DNS servers manage name resolution and can dynamically update records, load balancers handle traffic distribution and security, and origin servers focus on content delivery. This segmentation allows security measures to be implemented at specific layers without affecting the entire infrastructure.
2Reliability
If manual intervention methods are used for BGP hijacking, then security response is improved, but response time and operational efficiency deteriorate
Solution Approach 1:
The system implements automated security response through DNS-based verification mechanisms. When potential BGP hijacking is detected, the system automatically verifies the legitimacy of routing changes by checking DNS records and load balancer responses. This self-service approach eliminates the need for manual security team intervention while maintaining high response capability, thereby improving both reliability and productivity simultaneously.
Solution Approach 2:
The patent incorporates continuous feedback loops where the system monitors DNS resolution outcomes, load balancer responses, and traffic patterns to detect potential hijacking attempts. When anomalies are detected, the system automatically adjusts DNS records or redirects traffic through legitimate paths. This real-time feedback mechanism ensures rapid security response without manual intervention, improving both response time and operational efficiency.
Data Source
AI summary
A method for facilitating managing traffic between devices and origin servers. The method includes receiving a request from a device, analyzing the request, determining a value of a parameter based on the analyzing of the request, identifying an edge server from edge servers based on the determining of the value of the parameter, configuring a first operational parameter associated with a traffic handling of the edge server based on the determining of the value of the parameter and the identifying of the edge server, and directing a traffic associated with the device to the edge server based on the configuring of the first operational parameter. The edge server is configured for handling the traffic between the device and an origin server based on the configuring of the first operational parameter and the directing of the traffic.


