Mitigation Gateways for Network Attack Diversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems are ineffective in mitigating denial-of-service (DoS) and distributed DoS (DDoS) attacks, as they fail to timely detect and respond to malicious network traffic, leading to resource depletion and performance degradation in computing networks.

Innovation Solution

The implementation of mitigation gateways co-located with internet service provider (ISP) and internet exchange point (IXP) gateways, which detect attacks, aggregate traffic information, and negotiate with network aggregation points to divert and filter malicious traffic, applying mitigation techniques such as blocking or rerouting to prevent attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional DoS attack mitigation systems are used, then network resources are depleted and performance degrades, but the systems fail to timely detect and respond to malicious traffic

Engineering Contradiction:
Improvenetwork availabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by proactively monitoring network traffic patterns and establishing baseline behavior before attacks occur. The system pre-configures mitigation gateways at strategic network points (ISP gateways, IXP gateways) to enable immediate response when anomalies are detected, eliminating the detection-response delay that plagues conventional systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces mitigation gateways as intermediary components between the network core and attack victims. These gateways act as mediators that can intercept, analyze, and neutralize malicious traffic before it reaches vulnerable systems, enabling timely response without depleting core network resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If mitigation gateways are deployed at network aggregation points, then malicious traffic can be filtered effectively, but system complexity increases

Engineering Contradiction:
Improvemalicious traffic impactVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies universality by designing mitigation gateways with multi-functional capabilities that can operate at multiple network aggregation points (ISP gateways, IXP gateways, data center gateways). This single gateway design handles diverse attack types and can be deployed throughout the network infrastructure, reducing overall system complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service through automated traffic analysis and anomaly detection algorithms that enable the mitigation gateways to independently identify and respond to attacks without requiring constant human intervention or complex centralized control systems.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If traffic monitoring and analysis capabilities are enhanced, then attack detection accuracy improves, but processing overhead increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by implementing distributed monitoring capabilities at specific network aggregation points rather than uniformly across the entire network. Each mitigation gateway focuses its sophisticated analysis capabilities on local traffic patterns, achieving high detection accuracy while minimizing overall processing overhead through localized intelligence.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10187422B2Mitigation of computer network attacks
Publication Date: 2019.01.22 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10187422B2 patent drawing
  • US10187422B2 patent drawing
  • US10187422B2 patent drawing

AI summary

Various techniques for mitigating computer network attacks are disclosed herein. In one embodiment, a method includes receiving indications of denial of service attacks from multiple target computing systems and determining one or more sources from which the denial of service attacks are deemed to originate in response to the received indications of denial of service attacks from the target computing systems. The method also includes negotiating with the network aggregation point for permission to divert network traffic originated from the one or more of the determined sources and destined to the target computing systems to the gateway.