Exchange Point DDoS Mitigation via VLAN Traffic Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for mitigating Distributed Denial-of-Service (DDoS) attacks in network exchanges often rely on tunneling methods that incur overhead and require dedicated cross-connects, which are costly and inefficient in handling large volumes of traffic.

Innovation Solution

Implementing separate virtual networks for clean and dirty traffic within an exchange point, using Virtual Local Area Networks (VLANs) to isolate and reroute traffic directly to DDoS scrubbing centers, thereby avoiding tunneling and reducing costs by enabling scalable DDoS mitigation without the need for dedicated connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tunneling methods are used for DDoS traffic mitigation, then traffic can be routed to scrubbing centers, but overhead and costs increase due to dedicated cross-connects

Engineering Contradiction:
ImproveDDoS mitigation effectivenessVSAvoiddedicated cross-connect requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments traffic into clean and dirty streams using VLAN tagging at the exchange point. Dirty traffic is routed to scrubbing centers while clean traffic continues normally, eliminating the need for dedicated cross-connects and reducing overhead while maintaining mitigation effectiveness

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The exchange point acts as an intermediary that identifies and separates dirty traffic from clean traffic using VLAN tags. This intermediary function allows traffic to be routed to scrubbing centers without requiring end-to-end tunneling or dedicated cross-connects, reducing complexity and costs

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If separate virtual networks (VLANs) are used for clean and dirty traffic, then traffic isolation and scalable mitigation are achieved, but network configuration complexity increases

Engineering Contradiction:
Improvescalable DDoS mitigationVSAvoidVLAN configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The exchange point is configured to perform multiple functions: normal traffic switching, VLAN tagging for dirty traffic identification, and routing to scrubbing centers. This multi-functionality allows scalable DDoS mitigation without requiring separate dedicated infrastructure, reducing overall system complexity while maintaining adaptability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3815337B1Distributed denial-of-service mitigation
Publication Date: 2024.07.10 EQUINIX INC
  • EP3815337B1 patent drawingFigure 1
  • EP3815337B1 patent drawingFigure 2
  • EP3815337B1 patent drawingFigure 3

AI summary

The techniques described in this disclosure provide resilient and reactive on-demand Distributed Denial-of-Service (DDoS) mitigation services using an exchange. For example, an exchange comprises a first virtual network for switching mixed traffic (including dirty (DDoS) traffic and clean (non-DDoS) traffic)) from one or more networks to one or more DDoS scrubbing centers; and a second virtual network for switching the clean traffic from the one or more DDoS scrubbing centers to the one or more networks, wherein the exchange is configured to receive the mixed traffic from the one or more networks and switch, using the first virtual network, the mixed traffic to a selected DDoS scrubbing center of the one or more DDoS scrubbing centers, and wherein the exchange is configured to receive the clean traffic from the selected DDoS scrubbing center and switch, using the second virtual network, the clean traffic to the one or more networks.