IP Device Automatic DoS Protection via Rate-Based Policing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current media gateway architectures lack automatic denial of service protection, making them vulnerable to traffic floods that can impair or disable the system, as they require manual intervention to block malicious sources.

Innovation Solution

Implementing a rate-based policing policy within an IP device that identifies and blocks excessive traffic sources by adding source information to an access control list, preventing packets from being forwarded to the processor if they exceed the threshold, thus preventing resource overload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual intervention is used to block malicious sources, then system security can be improved, but system productivity deteriorates due to requiring operator involvement

Engineering Contradiction:
Improvesystem securityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system automatically monitors traffic rates, detects DoS attacks, updates ACLs, and blocks malicious sources without requiring operator intervention. The media gateway performs these security functions autonomously, eliminating the need for manual security management while maintaining continuous protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors traffic rates from source IP addresses and uses this feedback to automatically update ACLs when threshold violations are detected. This closed-loop feedback mechanism enables real-time adaptation to emerging threats without manual intervention.

Inventive Principle:
Principle #23Feedback

2Reliability

If rate-based policing is implemented to detect DoS attacks, then system reliability improves, but device complexity increases

Engineering Contradiction:
Improveautomatic DoS protectionVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network interface is designed to perform multiple functions: standard packet forwarding, traffic rate monitoring, ACL management, and automatic DoS protection. By making the network interface multi-functional, the patent avoids adding separate dedicated hardware components for each function, thereby limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines traffic monitoring, rate threshold evaluation, ACL update logic, and packet filtering functions into a unified system within the media gateway. This merging of functions reduces overall system complexity compared to having separate independent systems for each security function.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7725708B2Methods and systems for automatic denial of service protection in an IP device
Publication Date: 2010.05.25 GENBAND US LLC
  • US7725708B2 patent drawing
  • US7725708B2 patent drawing
  • US7725708B2 patent drawing

AI summary

Methods and systems for automatic denial of service protection in an IP device are disclosed. Packets are received at a network interface of an IP device, the packets being addressed to a network address of the network interface. The packets addressed to the network interface of the IP device are forwarded to a processor in the IP device. The processor determines whether the packets violate a rate-based policing policy of the IP device. In response to determining that the packets violate the rate-based policing policy, source identifying information associated with the packets is added to an access control list in the IP device. Packets matching criteria in the access control list are prevented from being forwarded to the processor in the IP device.