GAN-Based DDoS Mitigation for Edge Computing Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Edge computing systems, which provide low-latency services to client devices, are vulnerable to distributed denial-of-service (DDoS) attacks due to stringent latency demands, and existing DDoS mitigation infrastructures are limited in scalability, costly, and ineffective against higher-layer attacks.
Innovation Solution
A cloud computing network with a gateway that manages network traffic by determining illegitimate traffic using a generative adversarial net (GAN) framework to select and deploy hardware-based filters, reducing the amplification factor of cyberattacks while minimizing impact on low-latency services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated DDoS mitigation infrastructures are deployed to monitor and filter network traffic, then illegitimate traffic can be identified and removed, but the infrastructure can only absorb limited volumes of illegitimate traffic and does not scale with attack size
Solution Approach 1:
The patent segments the DDoS mitigation function into two parts: a scalable cloud-based GAN framework that handles traffic analysis and filter selection, and local hardware filters at the gateway that execute the filtering. This segmentation allows the system to scale with attack size by distributing the computational burden while maintaining mitigation effectiveness.
Solution Approach 2:
The patent introduces a Generative Adversarial Network (GAN) framework as an intermediary between network traffic and filtering mechanisms. The GAN framework analyzes traffic patterns, selects appropriate filters, and dynamically adjusts filtering strategies, enabling the system to adapt to varying attack scales without requiring proportional increases in infrastructure capacity.
2Reliability
If dedicated DDoS mitigation infrastructures are deployed to detect and defend against attacks, then illegitimate traffic can be scrubbed and filtered, but deployment costs are expensive
Solution Approach 1:
The patent implements a self-service DDoS mitigation system using a GAN framework that automatically analyzes network traffic, identifies attack patterns, selects appropriate filters, and deploys filtering rules without human intervention. This automation eliminates the need for expensive manual operation and management of dedicated mitigation infrastructure, reducing deployment and operational costs.
Solution Approach 2:
The GAN framework serves multiple functions: traffic analysis, attack detection, filter selection, and dynamic rule deployment. By consolidating these functions into a single multi-functional system rather than requiring separate dedicated infrastructure for each function, the patent reduces overall deployment costs while maintaining comprehensive DDoS defense capability.
3Reliability
If dedicated DDoS mitigation infrastructures are used to filter network traffic, then illegitimate traffic can be removed, but the infrastructures lack ability to defend against higher layer attacks
Solution Approach 1:
The patent employs a dynamic filtering system where the GAN framework continuously analyzes traffic patterns and adapts filter selection based on the specific characteristics of ongoing attacks. The system dynamically adjusts filtering strategies to defend against different attack types including higher-layer attacks, rather than relying on static filtering rules that cannot adapt to evolving threat vectors.
Solution Approach 2:
The GAN framework changes filtering parameters dynamically based on attack characteristics. It analyzes traffic at multiple layers and adjusts filter depth, selection criteria, and rule priorities according to the specific attack type detected, enabling effective defense against higher-layer attacks by modifying filtering parameters rather than relying on fixed infrastructure capabilities.
4Reliability
If filters are deployed to block illegitimate network traffic, then cyberattacks can be thwarted, but low-latency services provided by edge computing systems may be impacted
Solution Approach 1:
The patent applies partial filtering by selectively blocking only the portions of network traffic that are identified as illegitimate through GAN analysis. The system applies filtering actions proportional to the detected attack intensity rather than blanket blocking, thereby mitigating cyberattacks while minimizing unnecessary impact on legitimate low-latency services and maintaining optimal response times for authorized traffic.
Data Source
AI summary
Systems and methods for mitigating cyberattacks are described herein. A computing system can detect illegitimate network traffic associated with a cyberattack in network traffic. The computing system can determine an amplification factor of the cyberattack based in part on a probability distribution of the illegitimate network traffic. The computing system can determine a filter to demotivate a generation of the illegitimate network traffic. The determined filter can reduce the amplification factor of the cyberattack. The computing system can implement the determined filter to block the illegitimate network traffic.


