Flowspec Rule Validation via RPKI for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures fail to effectively validate and implement flow specification (Flowspec) rules across autonomous systems, limiting their ability to trust and distribute rules for mitigating distributed denial-of-service (DDoS) attacks outside their autonomous system.

Innovation Solution

The implementation of a modified Resource Public Key Infrastructure (RPKI) validation using a published valid route origin authorization (ROA) to validate and advertise Flowspec rules, allowing neighboring autonomous systems to trust and implement these rules to mitigate DDoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Flowspec rules are advertised outside the issuing Autonomous System, then DDoS attack mitigation capability is improved, but trust validity of the rules deteriorates because other Autonomous Systems cannot verify the rules

Engineering Contradiction:
ImproveDDoS attack mitigation capabilityVSAvoidRule validation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces Route Origin Authorization (ROA) as an intermediary mechanism that mediates between the Flowspec rule issuer and receiving Autonomous Systems. The ROA serves as a trusted certificate that proves the issuing AS has authorization to originate the IP prefix, allowing receiving systems to validate rules without complex verification processes. This intermediary resolves the trust validity issue by providing a standardized verification mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary validation of Flowspec rules using ROA verification before the rules are implemented in forwarding planes. By performing validation in advance and only implementing validated rules, the system ensures trustworthiness while simplifying the overall process. This preliminary action prevents untrusted rules from being deployed, resolving the contradiction between broad dissemination and trust verification.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If Flowspec rules are implemented at the edge of the attacked Autonomous System, then rule implementation simplicity is improved, but network-wide mitigation effectiveness deteriorates

Engineering Contradiction:
ImproveRule implementation simplicityVSAvoidNetwork-wide mitigation effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent makes Flowspec rules universal by enabling their implementation across multiple Autonomous Systems, not just at the edge of the attacked system. The ROA validation mechanism ensures that the same rule can be safely implemented by any AS that validates it, transforming the rule from a localized edge-filtering mechanism to a network-wide mitigation tool while maintaining implementation simplicity through standardized validation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If ROA validation is performed for all received Flowspec rules, then rule trust validity is improved, but processing time and computational overhead increase

Engineering Contradiction:
ImproveRule trust validityVSAvoidRule validation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements selective validation where ROA verification is performed on the essential origin authorization aspect of Flowspec rules. Rather than performing exhaustive validation on all possible rule attributes, the system focuses validation on the critical trust element (route origin authorization), achieving sufficient trust validity with reduced processing time and computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11930037B2Validation and implementation of flow specification (Flowspec) rules
Publication Date: 2024.03.12 CHARTER COMM OPERATING LLC
  • US11930037B2 patent drawing
  • US11930037B2 patent drawing
  • US11930037B2 patent drawing

AI summary

A valid route origin authorization (ROA) for a specified IP address is published and a distributed denial-of-service (DDoS) attack to a given IP address is detected. A flowspec rule is advertised from a given autonomous system network to one or more neighboring autonomous system networks in response to the detection of the distributed denial-of-service (DDoS) attack. A modified Resource Public Key Infrastructure (RPKI) validation is performed using the published valid route origin authorization (ROA) in response to the advertisement of the flowspec rule. The flowspec rule is implemented to mitigate the distributed denial-of-service (DDoS) attack in response to the validation of the flowspec rule.