FlowSpec Gateway Malformed Announcement Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malformed FlowSpec announcements can degrade network performance by interfering with legitimate traffic, as they may be incorrectly distributed during distributed denial of service (DDOS) attacks, leading to the dropping of legitimate traffic.

Innovation Solution

A system and method that includes a FlowSpec gateway to intercept and inspect FlowSpec announcements before forwarding them to routers, applying an acceptability test to ensure only valid announcements are distributed, thereby preventing malformed announcements from causing network degradation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If FlowSpec announcements are distributed to routers during DDOS attacks, then DDOS attack mitigation is improved, but malformed announcements may degrade network performance by interfering with legitimate traffic

Engineering Contradiction:
ImproveDDOS attack mitigation effectivenessVSAvoidnetwork performance degradation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by implementing an acceptability test that evaluates FlowSpec announcements before they are distributed to routers. The gateway performs syntax validation, semantics validation, and policy validation on incoming announcements to ensure they are well-formed and compliant with network policies before forwarding them to routers. This pre-distribution validation prevents malformed announcements from degrading network performance while still allowing legitimate mitigation announcements to be distributed effectively during DDOS attacks.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If FlowSpec announcements are forwarded to routers, then traffic filtering capability is improved, but malformed announcements cause legitimate traffic to be dropped

Engineering Contradiction:
Improvetraffic filtering capabilityVSAvoidlegitimate traffic delivery
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements an intermediary approach by introducing a FlowSpec gateway that acts as a mediator between the source of FlowSpec announcements and the routers. The gateway performs syntax validation, semantics validation, and policy validation to ensure announcements are well-formed and compliant before forwarding them to routers. This intermediary validation layer ensures that only legitimate, well-formed announcements reach the routers, maintaining both traffic filtering capability and legitimate traffic delivery reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250097254A1Flowspec gateway
Publication Date: 2025.03.20 LEVEL 3 COMMUNICATIONS LLC
  • US20250097254A1 patent drawing
  • US20250097254A1 patent drawing
  • US20250097254A1 patent drawing

AI summary

FlowSpec is a mechanism for distributing rules to routers in a network. Such rules may be used, for example, to drop traffic associated with a distributed denial of service attack. However, a malformed or incorrect FlowSpec announcement may, if distributed in the network, cause legitimate traffic to be dropped, degrading the service experienced by legitimate users. As such, systems and methods for avoiding the distribution of malformed FlowSpec announcements are provided.