FlowSpec Gateway Malformed Announcement Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malformed FlowSpec announcements can degrade network performance by interfering with legitimate traffic, as they may be incorrectly distributed during distributed denial of service (DDOS) attacks, leading to the dropping of legitimate traffic.
Innovation Solution
A system and method that includes a FlowSpec gateway to intercept and inspect FlowSpec announcements before forwarding them to routers, applying an acceptability test to ensure only valid announcements are distributed, thereby preventing malformed announcements from causing network degradation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If FlowSpec announcements are distributed to routers during DDOS attacks, then DDOS attack mitigation is improved, but malformed announcements may degrade network performance by interfering with legitimate traffic
Solution Approach 1:
The patent applies preliminary action by implementing an acceptability test that evaluates FlowSpec announcements before they are distributed to routers. The gateway performs syntax validation, semantics validation, and policy validation on incoming announcements to ensure they are well-formed and compliant with network policies before forwarding them to routers. This pre-distribution validation prevents malformed announcements from degrading network performance while still allowing legitimate mitigation announcements to be distributed effectively during DDOS attacks.
2Productivity
If FlowSpec announcements are forwarded to routers, then traffic filtering capability is improved, but malformed announcements cause legitimate traffic to be dropped
Solution Approach 1:
The patent implements an intermediary approach by introducing a FlowSpec gateway that acts as a mediator between the source of FlowSpec announcements and the routers. The gateway performs syntax validation, semantics validation, and policy validation to ensure announcements are well-formed and compliant before forwarding them to routers. This intermediary validation layer ensures that only legitimate, well-formed announcements reach the routers, maintaining both traffic filtering capability and legitimate traffic delivery reliability.
Data Source
AI summary
FlowSpec is a mechanism for distributing rules to routers in a network. Such rules may be used, for example, to drop traffic associated with a distributed denial of service attack. However, a malformed or incorrect FlowSpec announcement may, if distributed in the network, cause legitimate traffic to be dropped, degrading the service experienced by legitimate users. As such, systems and methods for avoiding the distribution of malformed FlowSpec announcements are provided.


