IP Reflection Routers for DDoS Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DDoS defense services are inadequate in effectively detecting and mitigating distributed denial of service attacks, particularly in routing and filtering network traffic.

Innovation Solution

The implementation of IP reflection technology, combined with anycast, to route clean network traffic without a backbone connection, facilitating a robust defense mechanism by translating public to private IP addresses and vice versa, ensuring uninterrupted service and enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current DDoS defense services are used, then network traffic filtering is provided, but the services are inadequate in effectively detecting and mitigating DDoS attacks

Engineering Contradiction:
Improveeffectiveness of DDoS attack detection and mitigationVSAvoidcomplexity of routing and filtering network traffic
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces IP reflection routers as intermediary components that mediate between the protected server and the network. These routers reflect IP addresses to route traffic through the protected network without requiring direct backbone connections, thereby improving DDoS mitigation effectiveness while managing complexity through standardized routing protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network into protected and non-protected portions, with IP reflection routers strategically placed at boundaries. This segmentation allows focused filtering and detection resources to be concentrated on the protected network segment, improving effectiveness without proportionally increasing overall system complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If IP reflection technology is implemented to route clean traffic without backbone connection, then service integrity is maintained, but device complexity increases

Engineering Contradiction:
Improveservice integrityVSAvoidcomplexity of IP reflection routers
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The IP reflection routers are designed to perform multiple functions: traffic filtering, IP address translation, route reflection, and protocol translation. By consolidating these functions into single multi-functional devices, the system maintains service integrity through comprehensive protection while reducing the number of separate components needed

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If public to private IP address translation is performed, then enhanced security is achieved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time for IP address translation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary IP address translation and routing decisions before traffic enters the protected network. By pre-establishing translation mappings and routing paths, the actual translation processing occurs in advance, reducing real-time processing delays while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The IP reflection system dynamically adjusts translation mappings and routing paths based on current network conditions and threat levels. This dynamic behavior allows the system to optimize processing time by adapting translation complexity to actual security requirements, rather than always performing full translations

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9674144B1IP reflection
Publication Date: 2017.06.06 F5 NETWORKS INC
  • US9674144B1 patent drawing
  • US9674144B1 patent drawing
  • US9674144B1 patent drawing

AI summary

IP reflection comprising double static NAT (network address translation) is disclosed. In some embodiments, a packet having a public IP address is received at a protecting network. The public IP address of the packet is translated to a corresponding protected IP address associated with a protected network, and the packet is forwarded to the protected network for servicing. The protected IP address of a response to the packet from the protected network is translated back to the public IP address at the protected network before sending.