Filter Request Server for DoS Source Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for mitigating Denial-of-Service (DoS) attacks in networks are inefficient, either burdening destination systems with processing malicious traffic or failing to reliably identify and block malicious sources, and often require costly router updates or upgrades.
Innovation Solution
Implementing accountability among Autonomous Systems (ASs) through ingress filtering and on-request filtering, where each AS uses a Filter Request Server to identify and block malicious traffic at its source, ensuring reliable source identification and defensibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end host-based solutions are used to recognize and discard DoS traffic at the destination, then the targeted system can filter malicious traffic, but the destination system is unduly burdened with processing the entire volume of DoS traffic
Solution Approach 1:
The patent implements ingress filtering at the autonomous system boundary before traffic enters the network, performing the filtering action in advance rather than at the destination. This preliminary action prevents malicious traffic from consuming destination resources in the first place, resolving the contradiction by shifting the filtering location upstream.
2Reliability
If router-based solutions are used to detect and filter DoS traffic, then the filtering capability is improved, but the cost of updating and replacing routers increases
Solution Approach 1:
The patent makes existing routers multi-functional by enabling them to perform both traditional routing functions and ingress filtering functions. Instead of requiring specialized filtering hardware, standard routers are configured to handle both purposes, eliminating the need for costly router replacements while maintaining filtering capability.
3Reliability
If upstream routers are used to push back detection and filtration toward the source, then the destination is protected, but reliable identification of the originating source cannot be achieved
Solution Approach 1:
The patent segments the network into autonomous systems with clearly defined boundaries, implementing filtering at the AS boundary rather than within individual routers. This segmentation allows for reliable source identification because the ingress filter operates at a level where source IP addresses can be verified against the sending AS's authorized address space, preventing spoofing while maintaining source identification capability.
Data Source
AI summary
In one kind of DoS attack, malicious customers may try to send a large number of filter requests against an innocent customer. In one implementation, a Filter Request Server (FRS) may allow a customer against who a filter request is made to dispute the implicit accusation of the filter request or stop sending malicious traffic. If the customer claims innocence, the FRS may log destination addresses of data packets sent by the customer and identify and ignore false filter requests if these filter requests come from customers who do not correspond to one or more of the destination addresses that have previously been logged by the FRS.


