Intelligent DDoS Traffic Routing for Scrubbing Challenge Responses
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DDoS attack mitigation systems face challenges in ensuring that responses to legitimacy challenges for source IP addresses are routed back to the same scrubbing device that issued the challenge, particularly in networks with multiple scrubbing devices and routers, leading to improper filtering of legitimate traffic.
Innovation Solution
A traffic management system that receives mirrored traffic from scrubbing devices, detects challenges issued to source IP addresses, and temporarily updates routing policies to ensure that all traffic with a specific source and destination IP address pair is routed to the scrubbing device that initiated the challenge, allowing for accurate legitimacy verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple scrubbing devices are used in a network, then DDoS mitigation capability is improved, but routing complexity increases and responses to legitimacy challenges may be routed to incorrect scrubbing devices
Solution Approach 1:
A traffic management system is introduced as an intermediary component that receives mirrored traffic from multiple scrubbing devices, analyzes flow information to identify challenge-response pairs, and coordinates routing policies to ensure responses are correctly routed back to the originating scrubbing device, thereby resolving the routing complexity issue while maintaining multi-device mitigation capability
Solution Approach 2:
The system implements feedback mechanisms by analyzing mirrored traffic flows to detect when a scrubbing device sends challenges to source IP addresses and when responses are received. This feedback loop enables the traffic management system to dynamically update routing policies to ensure responses are routed back to the correct scrubbing device, improving reliability in multi-device environments
2Measurement precision
If routing policies are dynamically updated to ensure correct response routing, then legitimacy verification accuracy is improved, but system response time increases
Solution Approach 1:
The traffic management system performs preliminary analysis of mirrored traffic flows to identify challenge-response pairs before routing decisions are needed. By pre-analyzing flow information and proactively updating routing policies, the system reduces the time required for legitimacy verification while maintaining high accuracy in identifying spoofed IP addresses
Solution Approach 2:
The system dynamically adjusts routing policies based on real-time flow information analysis. When a scrubbing device sends challenges to source IP addresses, the traffic management system analyzes the flow and dynamically updates routing tables to ensure responses are routed back to the correct device, optimizing both accuracy and response time through adaptive control
Data Source
AI summary
Systems and methods for improved intelligent manipulation of distributed-denial-of-service (DDoS) attack traffic are provided. In implementations, a method may include receiving, at a traffic management system, a mirrored first stream of packets from a router on a first link and a mirrored second stream of packets from the router on a second link. The method may further include determining flow information about the first stream. In examples, the flow information may indicate that a challenge to a particular source IP address has been issued to test the legitimacy of the source IP address. The method may further include sending, by the traffic management system, a routing policy update based on the flow information.


