Flowspec Controller for Per-Customer Network Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Flowspec message processing systems lack granularity in customization for individual customer networks, leading to ineffective mitigation of network attacks as the same configuration is deployed across all connected customer networks.
Innovation Solution
A method and apparatus for processing Flowspec messages specifically configured for each customer network to detect and mitigate network attacks, allowing for unique configurations and reusability across multiple networks, enabling targeted filtering and reducing overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If Flowspec messages are deployed to all coupled customer networks, then network coverage is improved, but customization granularity deteriorates
Solution Approach 1:
The patent segments the network into multiple Virtual Routing and Forwarding (VRF) instances, each corresponding to a specific customer network. This segmentation allows the Flowspec controller to generate and deliver customized Flowspec messages to each VRF instance independently, thereby maintaining network coverage across multiple customers while enabling granular customization for each customer's specific requirements.
2Reliability
If customized Flowspec messages are generated for each customer network, then mitigation effectiveness is improved, but system complexity deteriorates
Solution Approach 1:
The patent implements a universal Flowspec controller that can generate customized Flowspec messages for multiple different customer networks through a single system. The controller is designed to handle multiple VRF instances and can adapt its message generation logic based on the specific attack patterns and requirements of each customer, thereby achieving high mitigation effectiveness without proportionally increasing system complexity.
Solution Approach 2:
The patent employs template-based message generation where standardized Flowspec message templates are created once and then customized for different customer networks by filling in specific parameters. This copying approach allows the system to maintain complexity at a manageable level while still generating highly customized mitigation messages for each customer's unique attack scenarios.
3Adaptability or versatility
If per-customer configuration is implemented, then customization capability is improved, but operational overhead deteriorates
Solution Approach 1:
The patent implements preliminary configuration by pre-establishing VRF instances and Flowspec message templates before attacks occur. When an attack is detected, the system can quickly instantiate customized mitigation messages by referencing these pre-configured elements, thereby reducing the operational overhead and time required for per-customer customization during actual attack mitigation scenarios.
Data Source
AI summary
A method and apparatus for processing flow specification (Flowspec) messages to one or more of a plurality of customer networks by a controller device coupled to the plurality of customer networks. Preferably a network controller monitors network traffic flowing through each of the customer networks for detecting a network attack in one of the plurality of customer networks, via monitoring of the network traffic. Upon detection of a network attack, a Flowspec message is generated for the customer network detected to be under network attack wherein the Flowspec message is configured specifically for that customer network. The generated Flowspec message is transmitted to the customer network detected to be under network attack for implementation by the customer network for mitigation of the detected network attack.


