Global Traffic Manager for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods are inadequate in preventing distributed denial of service (DDoS) attacks, particularly as they can overwhelm DNS infrastructure, and existing solutions are resource-intensive and costly to implement effectively.

Innovation Solution

A global traffic manager computing device that obtains network information, assigns a rating based on various parameters, and takes action based on a threshold rating to mitigate potential DDoS attacks by managing traffic and reducing resource consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNSSec is used to sign responses, then security is improved, but resource consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements rate limiting and scoring mechanisms in advance before the DDoS attack fully impacts the system. By pre-establishing thresholds and evaluation criteria for request patterns, the system can quickly identify and block malicious traffic without consuming excessive resources during an actual attack. This preliminary preparation allows DNSSec to be applied selectively only to legitimate requests.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional DDoS prevention methods are implemented, then security is improved, but cost and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service approach where the DNS system automatically evaluates incoming requests using predefined scoring criteria and rate limiting mechanisms. The system autonomously identifies suspicious patterns, applies appropriate filtering actions, and adjusts to attack patterns without requiring complex external monitoring infrastructure or manual intervention, thereby reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

3Difficulty of detecting and measuring

If monitoring resources are increased, then detection capability is improved, but cost increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidmonitoring resources
Core Design Contradiction:
Difficulty of detecting and measuringVSQuantity of substance

Solution Approach 1:

The patent replaces traditional mechanical monitoring approaches with an automated scoring and evaluation system that processes requests through predefined criteria. Instead of requiring extensive human monitoring resources or complex monitoring infrastructure, the system uses algorithmic evaluation of request patterns, source reputation, and behavioral metrics to automatically detect and respond to DDoS attacks, significantly reducing the need for additional monitoring resources.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9609017B1Methods for preventing a distributed denial service attack and devices thereof
Publication Date: 2017.03.28 F5 NETWORKS INC
  • US9609017B1 patent drawing
  • US9609017B1 patent drawing
  • US9609017B1 patent drawing

AI summary

A method, non-transitory computer readable medium and global traffic manager computing device for preventing distributed denial of service attack comprising machine executable code which when executed by at least one processor, causes the processor to perform steps including obtaining network information relating to a request in response to receiving the request. A rating is determined for the obtained network information based on one or more network parameters. An action to be taken for the received request is determined based on a comparison of the determined rating and a threshold rating. The determined action is executed for the received request.