GAN-Based DDoS Mitigation for Edge Computing Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Edge computing systems, which provide low-latency services to client devices, are vulnerable to distributed denial-of-service (DDoS) attacks due to stringent latency demands, and existing DDoS mitigation infrastructures are limited in scalability, costly, and ineffective against higher-layer attacks.

Innovation Solution

A cloud computing network with a gateway that manages network traffic by determining illegitimate traffic using a generative adversarial net (GAN) framework to select and deploy hardware-based filters, reducing the amplification factor of cyberattacks while minimizing impact on low-latency services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated DDoS mitigation infrastructures are deployed to monitor and filter network traffic, then illegitimate traffic can be identified and removed, but the infrastructure can only absorb limited volumes of illegitimate traffic and does not scale with attack size

Engineering Contradiction:
ImproveDDoS attack mitigation capabilityVSAvoidScalability with attack size
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the DDoS mitigation function into two parts: a scalable cloud-based GAN framework that handles traffic analysis and filter selection, and local hardware filters at the gateway that execute the filtering. This segmentation allows the system to scale with attack size by distributing the computational burden while maintaining mitigation effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a Generative Adversarial Network (GAN) framework as an intermediary between network traffic and filtering mechanisms. The GAN framework analyzes traffic patterns, selects appropriate filters, and dynamically adjusts filtering strategies, enabling the system to adapt to varying attack scales without requiring proportional increases in infrastructure capacity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated DDoS mitigation infrastructures are deployed to detect and defend against attacks, then illegitimate traffic can be scrubbed and filtered, but deployment costs are expensive

Engineering Contradiction:
ImproveDDoS attack defense capabilityVSAvoidDeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a self-service DDoS mitigation system using a GAN framework that automatically analyzes network traffic, identifies attack patterns, selects appropriate filters, and deploys filtering rules without human intervention. This automation eliminates the need for expensive manual operation and management of dedicated mitigation infrastructure, reducing deployment and operational costs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The GAN framework serves multiple functions: traffic analysis, attack detection, filter selection, and dynamic rule deployment. By consolidating these functions into a single multi-functional system rather than requiring separate dedicated infrastructure for each function, the patent reduces overall deployment costs while maintaining comprehensive DDoS defense capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dedicated DDoS mitigation infrastructures are used to filter network traffic, then illegitimate traffic can be removed, but the infrastructures lack ability to defend against higher layer attacks

Engineering Contradiction:
ImproveIllegitimate traffic filtering capabilityVSAvoidDefense against higher layer attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent employs a dynamic filtering system where the GAN framework continuously analyzes traffic patterns and adapts filter selection based on the specific characteristics of ongoing attacks. The system dynamically adjusts filtering strategies to defend against different attack types including higher-layer attacks, rather than relying on static filtering rules that cannot adapt to evolving threat vectors.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The GAN framework changes filtering parameters dynamically based on attack characteristics. It analyzes traffic at multiple layers and adjusts filter depth, selection criteria, and rule priorities according to the specific attack type detected, enabling effective defense against higher-layer attacks by modifying filtering parameters rather than relying on fixed infrastructure capabilities.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If filters are deployed to block illegitimate network traffic, then cyberattacks can be thwarted, but low-latency services provided by edge computing systems may be impacted

Engineering Contradiction:
ImproveCyberattack mitigationVSAvoidResponse time of low-latency services
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies partial filtering by selectively blocking only the portions of network traffic that are identified as illegitimate through GAN analysis. The system applies filtering actions proportional to the detected attack intensity rather than blanket blocking, thereby mitigating cyberattacks while minimizing unnecessary impact on legitimate low-latency services and maintaining optimal response times for authorized traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11770406B2Systems and methods for mitigating cyberattacks
Publication Date: 2023.09.26 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11770406B2 patent drawing
  • US11770406B2 patent drawing
  • US11770406B2 patent drawing

AI summary

Systems and methods for mitigating cyberattacks are described herein. A computing system can detect illegitimate network traffic associated with a cyberattack in network traffic. The computing system can determine an amplification factor of the cyberattack based in part on a probability distribution of the illegitimate network traffic. The computing system can determine a filter to demotivate a generation of the illegitimate network traffic. The determined filter can reduce the amplification factor of the cyberattack. The computing system can implement the determined filter to block the illegitimate network traffic.