Flowspec Rule Validation via RPKI for DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures fail to effectively validate and implement flow specification (Flowspec) rules across autonomous systems, limiting their ability to trust and distribute rules for mitigating distributed denial-of-service (DDoS) attacks outside their autonomous system.
Innovation Solution
The implementation of a modified Resource Public Key Infrastructure (RPKI) validation using a published valid route origin authorization (ROA) to validate and advertise Flowspec rules, allowing neighboring autonomous systems to trust and implement these rules to mitigate DDoS attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Flowspec rules are advertised outside the issuing Autonomous System, then DDoS attack mitigation capability is improved, but trust validity of the rules deteriorates because other Autonomous Systems cannot verify the rules
Solution Approach 1:
The patent introduces Route Origin Authorization (ROA) as an intermediary mechanism that mediates between the Flowspec rule issuer and receiving Autonomous Systems. The ROA serves as a trusted certificate that proves the issuing AS has authorization to originate the IP prefix, allowing receiving systems to validate rules without complex verification processes. This intermediary resolves the trust validity issue by providing a standardized verification mechanism.
Solution Approach 2:
The patent implements preliminary validation of Flowspec rules using ROA verification before the rules are implemented in forwarding planes. By performing validation in advance and only implementing validated rules, the system ensures trustworthiness while simplifying the overall process. This preliminary action prevents untrusted rules from being deployed, resolving the contradiction between broad dissemination and trust verification.
2Ease of operation
If Flowspec rules are implemented at the edge of the attacked Autonomous System, then rule implementation simplicity is improved, but network-wide mitigation effectiveness deteriorates
Solution Approach 1:
The patent makes Flowspec rules universal by enabling their implementation across multiple Autonomous Systems, not just at the edge of the attacked system. The ROA validation mechanism ensures that the same rule can be safely implemented by any AS that validates it, transforming the rule from a localized edge-filtering mechanism to a network-wide mitigation tool while maintaining implementation simplicity through standardized validation.
3Reliability
If ROA validation is performed for all received Flowspec rules, then rule trust validity is improved, but processing time and computational overhead increase
Solution Approach 1:
The patent implements selective validation where ROA verification is performed on the essential origin authorization aspect of Flowspec rules. Rather than performing exhaustive validation on all possible rule attributes, the system focuses validation on the critical trust element (route origin authorization), achieving sufficient trust validity with reduced processing time and computational overhead.
Data Source
AI summary
A valid route origin authorization (ROA) for a specified IP address is published and a distributed denial-of-service (DDoS) attack to a given IP address is detected. A flowspec rule is advertised from a given autonomous system network to one or more neighboring autonomous system networks in response to the detection of the distributed denial-of-service (DDoS) attack. A modified Resource Public Key Infrastructure (RPKI) validation is performed using the published valid route origin authorization (ROA) in response to the advertisement of the flowspec rule. The flowspec rule is implemented to mitigate the distributed denial-of-service (DDoS) attack in response to the validation of the flowspec rule.


