Event Driven Route Control for DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DDoS mitigation systems rely heavily on expensive scrubbing centers, leading to a lack of infrastructure due to high costs and introducing latency by routing all traffic through few remote locations.
Innovation Solution
Implementing a system that combines mitigation systems with less expensive non-mitigation systems, using event-driven route control (EDRC) to dynamically reroute traffic from non-mitigation systems to mitigation systems during attacks, thereby reducing latency and improving access efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all traffic is routed through scrubbing centers to respond to DDoS attacks, then the network can effectively mitigate attacks, but latency increases due to traversing data over long distances to remote scrubbing centers
Solution Approach 1:
The system segments traffic handling into two paths: normal traffic flows through local non-mitigation systems for low-latency processing, while attack traffic is segmented and routed through mitigation systems. This segmentation allows the system to achieve both low latency for normal operations and effective attack mitigation when needed.
Solution Approach 2:
The routing system dynamically switches between different paths based on real-time network conditions and attack detection. During normal conditions, traffic flows through local systems; when attacks are detected, the system dynamically reroutes traffic through mitigation systems, providing adaptive response to changing network threats.
2Loss of time
If expensive scrubbing centers are deployed throughout the network to reduce latency, then network accessibility improves, but the high cost limits the number of scrubbing centers that can be deployed
Solution Approach 1:
Non-mitigation systems perform dual functions: they handle normal traffic flow with low latency and can also detect and report attacks. This multi-functionality eliminates the need for expensive scrubbing centers at every location, as local systems contribute to both performance and security monitoring.
Solution Approach 2:
The system introduces event-driven route control as an intermediary layer that coordinates between local non-mitigation systems and remote mitigation systems. This intermediary enables efficient traffic routing and attack response without requiring expensive infrastructure at every network location.
3Loss of time
If non-mitigation systems are used during attacks, then latency is reduced, but these systems cannot respond to attacks and may interfere with the mitigation process
Solution Approach 1:
The system extracts the attack mitigation function from local non-mitigation systems and concentrates it in dedicated mitigation systems. Local systems take out the burden of attack response, focusing only on normal traffic handling, while specialized mitigation systems handle attack response, ensuring both low latency and reliable attack mitigation.
Solution Approach 2:
The system implements feedback mechanisms where non-mitigation systems monitor traffic and report anomalies to mitigation systems. This feedback loop enables local systems to maintain low-latency operation while ensuring attacks are detected and responded to by specialized mitigation systems.
Data Source
AI summary
Embodiments provide system and methods for a DDoS service using a mix of mitigation systems (also called scrubbing centers) and non-mitigation systems. The non-mitigation systems are less expensive and thus can be placed at or near a customer's network resource (e.g., a computer, cluster of computers, or entire network). Under normal conditions, traffic for a customer's resource can go through a mitigation system or a non-mitigation system. When an attack is detected, traffic that would have otherwise gone through a non-mitigation system is re-routed to a mitigation system. Thus, the non-mitigation systems can be used to reduce latency and provide more efficient access to the customer's network resource during normal conditions. Since the non-mitigation servers are not equipped to respond to an attack, the non-mitigation systems are not used during an attack, thereby still providing protection to the customer network resource using the mitigation systems.


