Global Traffic Manager for DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods are inadequate in preventing distributed denial of service (DDoS) attacks, particularly as they can overwhelm DNS infrastructure, and existing solutions are resource-intensive and costly to implement effectively.
Innovation Solution
A global traffic manager computing device that obtains network information, assigns a rating based on various parameters, and takes action based on a threshold rating to mitigate potential DDoS attacks by managing traffic and reducing resource consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DNSSec is used to sign responses, then security is improved, but resource consumption increases
Solution Approach 1:
The patent implements rate limiting and scoring mechanisms in advance before the DDoS attack fully impacts the system. By pre-establishing thresholds and evaluation criteria for request patterns, the system can quickly identify and block malicious traffic without consuming excessive resources during an actual attack. This preliminary preparation allows DNSSec to be applied selectively only to legitimate requests.
2Reliability
If traditional DDoS prevention methods are implemented, then security is improved, but cost and complexity increase
Solution Approach 1:
The patent implements a self-service approach where the DNS system automatically evaluates incoming requests using predefined scoring criteria and rate limiting mechanisms. The system autonomously identifies suspicious patterns, applies appropriate filtering actions, and adjusts to attack patterns without requiring complex external monitoring infrastructure or manual intervention, thereby reducing overall system complexity while maintaining security.
3Difficulty of detecting and measuring
If monitoring resources are increased, then detection capability is improved, but cost increases
Solution Approach 1:
The patent replaces traditional mechanical monitoring approaches with an automated scoring and evaluation system that processes requests through predefined criteria. Instead of requiring extensive human monitoring resources or complex monitoring infrastructure, the system uses algorithmic evaluation of request patterns, source reputation, and behavioral metrics to automatically detect and respond to DDoS attacks, significantly reducing the need for additional monitoring resources.
Data Source
AI summary
A method, non-transitory computer readable medium and global traffic manager computing device for preventing distributed denial of service attack comprising machine executable code which when executed by at least one processor, causes the processor to perform steps including obtaining network information relating to a request in response to receiving the request. A rating is determined for the obtained network information based on one or more network parameters. An action to be taken for the received request is determined based on a comparison of the determined rating and a threshold rating. The determined action is executed for the received request.


