Filter Request Server for DoS Source Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for mitigating Denial-of-Service (DoS) attacks in networks are inefficient, either burdening destination systems with processing malicious traffic or failing to reliably identify and block malicious sources, and often require costly router updates or upgrades.

Innovation Solution

Implementing accountability among Autonomous Systems (ASs) through ingress filtering and on-request filtering, where each AS uses a Filter Request Server to identify and block malicious traffic at its source, ensuring reliable source identification and defensibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end host-based solutions are used to recognize and discard DoS traffic at the destination, then the targeted system can filter malicious traffic, but the destination system is unduly burdened with processing the entire volume of DoS traffic

Engineering Contradiction:
ImproveDoS traffic filtering capabilityVSAvoidCPU cycles and bandwidth at destination
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements ingress filtering at the autonomous system boundary before traffic enters the network, performing the filtering action in advance rather than at the destination. This preliminary action prevents malicious traffic from consuming destination resources in the first place, resolving the contradiction by shifting the filtering location upstream.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If router-based solutions are used to detect and filter DoS traffic, then the filtering capability is improved, but the cost of updating and replacing routers increases

Engineering Contradiction:
ImproveDoS traffic filtering capabilityVSAvoidNetwork setup cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent makes existing routers multi-functional by enabling them to perform both traditional routing functions and ingress filtering functions. Instead of requiring specialized filtering hardware, standard routers are configured to handle both purposes, eliminating the need for costly router replacements while maintaining filtering capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If upstream routers are used to push back detection and filtration toward the source, then the destination is protected, but reliable identification of the originating source cannot be achieved

Engineering Contradiction:
ImproveSource identification accuracyVSAvoidAbility to identify malicious source
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the network into autonomous systems with clearly defined boundaries, implementing filtering at the AS boundary rather than within individual routers. This segmentation allows for reliable source identification because the ingress filter operates at a level where source IP addresses can be verified against the sending AS's authorized address space, preventing spoofing while maintaining source identification capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9363233B2Network accountability among autonomous systems
Publication Date: 2016.06.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9363233B2 patent drawing
  • US9363233B2 patent drawing
  • US9363233B2 patent drawing

AI summary

In one kind of DoS attack, malicious customers may try to send a large number of filter requests against an innocent customer. In one implementation, a Filter Request Server (FRS) may allow a customer against who a filter request is made to dispute the implicit accusation of the filter request or stop sending malicious traffic. If the customer claims innocence, the FRS may log destination addresses of data packets sent by the customer and identify and ignore false filter requests if these filter requests come from customers who do not correspond to one or more of the destination addresses that have previously been logged by the FRS.