Intelligent DDoS Traffic Routing for Scrubbing Challenge Responses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DDoS attack mitigation systems face challenges in ensuring that responses to legitimacy challenges for source IP addresses are routed back to the same scrubbing device that issued the challenge, particularly in networks with multiple scrubbing devices and routers, leading to improper filtering of legitimate traffic.

Innovation Solution

A traffic management system that receives mirrored traffic from scrubbing devices, detects challenges issued to source IP addresses, and temporarily updates routing policies to ensure that all traffic with a specific source and destination IP address pair is routed to the scrubbing device that initiated the challenge, allowing for accurate legitimacy verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple scrubbing devices are used in a network, then DDoS mitigation capability is improved, but routing complexity increases and responses to legitimacy challenges may be routed to incorrect scrubbing devices

Engineering Contradiction:
ImproveDDoS mitigation capabilityVSAvoidrouting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A traffic management system is introduced as an intermediary component that receives mirrored traffic from multiple scrubbing devices, analyzes flow information to identify challenge-response pairs, and coordinates routing policies to ensure responses are correctly routed back to the originating scrubbing device, thereby resolving the routing complexity issue while maintaining multi-device mitigation capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by analyzing mirrored traffic flows to detect when a scrubbing device sends challenges to source IP addresses and when responses are received. This feedback loop enables the traffic management system to dynamically update routing policies to ensure responses are routed back to the correct scrubbing device, improving reliability in multi-device environments

Inventive Principle:
Principle #23Feedback

2Measurement precision

If routing policies are dynamically updated to ensure correct response routing, then legitimacy verification accuracy is improved, but system response time increases

Engineering Contradiction:
Improvelegitimacy verification accuracyVSAvoidsystem response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The traffic management system performs preliminary analysis of mirrored traffic flows to identify challenge-response pairs before routing decisions are needed. By pre-analyzing flow information and proactively updating routing policies, the system reduces the time required for legitimacy verification while maintaining high accuracy in identifying spoofed IP addresses

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts routing policies based on real-time flow information analysis. When a scrubbing device sends challenges to source IP addresses, the traffic management system analyzes the flow and dynamically updates routing tables to ensure responses are routed back to the correct device, optimizing both accuracy and response time through adaptive control

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12368750B2Intelligent manipulation of denial-of-service attack traffic
Publication Date: 2025.07.22 LEVEL 3 COMMUNICATIONS LLC
  • US12368750B2 patent drawing
  • US12368750B2 patent drawing
  • US12368750B2 patent drawing

AI summary

Systems and methods for improved intelligent manipulation of distributed-denial-of-service (DDoS) attack traffic are provided. In implementations, a method may include receiving, at a traffic management system, a mirrored first stream of packets from a router on a first link and a mirrored second stream of packets from the router on a second link. The method may further include determining flow information about the first stream. In examples, the flow information may indicate that a challenge to a particular source IP address has been issued to test the legitimacy of the source IP address. The method may further include sending, by the traffic management system, a routing policy update based on the flow information.