Local-Global Network Device Configuration for Rapid DoS/DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network configurations are difficult and time-consuming to manage due to differences among networking devices from various vendors, and conventional mitigation solutions for DOS and DDOS attacks are slow, often failing to react in time to prevent service disruptions.

Innovation Solution

A method and system that utilize a local and global layer architecture to rapidly configure networking devices by storing configuration changes in a database, generating device-specific updates, and applying them to mitigate attacks, with features like blacklisting and profile updates to manage traffic effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If conventional mitigation solutions are used to respond to DOS attacks, then the response time is reduced to around 30 seconds, but this delay still exceeds the duration of many attacks making mitigation fruitless

Engineering Contradiction:
Improveresponse speedVSAvoidmitigation effectiveness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-configuring networking devices with mitigation capabilities and maintaining ready-to-apply configuration templates. When an attack is detected, pre-prepared configuration changes are immediately deployed without requiring time-consuming analysis or device-specific customization, enabling response within seconds rather than minutes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the network into multiple independently configurable networking devices that can be rapidly reconfigured individually. Each device can be updated with specific mitigation rules without affecting others, allowing parallel configuration deployment across the network infrastructure, which dramatically accelerates the overall response time.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple networking devices from different vendors are reconfigured to mitigate attacks, then network security is improved, but the complexity and time required for configuration increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a universal configuration management platform that can generate and deploy configurations across multiple networking devices from different vendors. By using standardized configuration templates and abstraction layers, the system achieves multi-vendor compatibility without requiring device-specific customization, thereby reducing configuration complexity while maintaining broad security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses configuration templates that can be copied and adapted across different networking devices. Instead of manually configuring each device individually, pre-defined configuration patterns are replicated and customized minimally for each device type, dramatically reducing the time and complexity of configuring multiple devices while ensuring consistent security policies across the network.

Inventive Principle:
Principle #26Copying

3Reliability

If configuration changes are applied to networking devices to block malicious traffic, then service availability is protected, but the time required to implement these changes increases

Engineering Contradiction:
Improveservice availabilityVSAvoidconfiguration implementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring networking devices with mitigation capabilities and maintaining ready-to-apply configuration templates. When an attack is detected, pre-prepared configuration changes are immediately deployed without requiring time-consuming analysis or device-specific customization, enabling response within seconds rather than minutes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system rushes through the configuration deployment process by using prevalidated templates and automated push mechanisms that bypass manual review and iterative testing steps. Configuration changes are pushed to devices in a single coordinated operation, skipping traditional lengthy configuration cycles and achieving rapid service protection.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS12407570B2Systems and methods for configuring networking devices
Publication Date: 2025.09.02 OVH
  • US12407570B2 patent drawing
  • US12407570B2 patent drawing
  • US12407570B2 patent drawing

AI summary

A method and system for configuring networking devices in a network having a local layer and a global layer. An indication of a network attack is received at the local layer. A configuration change corresponding to the attack is stored in a database of the local layer. The configuration change is sent to a device in the global layer. The device in the global layer stores the configuration change in a database of the global layer. Configuration changes are generated for the networking devices and sent to the networking devices. The configuration changes applied to the networking devices are stored in the global layer.