IP Device Automatic DoS Protection via Rate-Based Policing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current media gateway architectures lack automatic denial of service protection, making them vulnerable to traffic floods that can impair or disable the system, as they require manual intervention to block malicious sources.
Innovation Solution
Implementing a rate-based policing policy within an IP device that identifies and blocks excessive traffic sources by adding source information to an access control list, preventing packets from being forwarded to the processor if they exceed the threshold, thus preventing resource overload.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual intervention is used to block malicious sources, then system security can be improved, but system productivity deteriorates due to requiring operator involvement
Solution Approach 1:
The system automatically monitors traffic rates, detects DoS attacks, updates ACLs, and blocks malicious sources without requiring operator intervention. The media gateway performs these security functions autonomously, eliminating the need for manual security management while maintaining continuous protection.
Solution Approach 2:
The system continuously monitors traffic rates from source IP addresses and uses this feedback to automatically update ACLs when threshold violations are detected. This closed-loop feedback mechanism enables real-time adaptation to emerging threats without manual intervention.
2Reliability
If rate-based policing is implemented to detect DoS attacks, then system reliability improves, but device complexity increases
Solution Approach 1:
The network interface is designed to perform multiple functions: standard packet forwarding, traffic rate monitoring, ACL management, and automatic DoS protection. By making the network interface multi-functional, the patent avoids adding separate dedicated hardware components for each function, thereby limiting the increase in device complexity.
Solution Approach 2:
The patent combines traffic monitoring, rate threshold evaluation, ACL update logic, and packet filtering functions into a unified system within the media gateway. This merging of functions reduces overall system complexity compared to having separate independent systems for each security function.
Data Source
AI summary
Methods and systems for automatic denial of service protection in an IP device are disclosed. Packets are received at a network interface of an IP device, the packets being addressed to a network address of the network interface. The packets addressed to the network interface of the IP device are forwarded to a processor in the IP device. The processor determines whether the packets violate a rate-based policing policy of the IP device. In response to determining that the packets violate the rate-based policing policy, source identifying information associated with the packets is added to an access control list in the IP device. Packets matching criteria in the access control list are prevented from being forwarded to the processor in the IP device.


