Mitigation Gateways for Network Attack Diversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems are ineffective in mitigating denial-of-service (DoS) and distributed DoS (DDoS) attacks, as they fail to timely detect and respond to malicious network traffic, leading to resource depletion and performance degradation in computing networks.
Innovation Solution
The implementation of mitigation gateways co-located with internet service provider (ISP) and internet exchange point (IXP) gateways, which detect attacks, aggregate traffic information, and negotiate with network aggregation points to divert and filter malicious traffic, applying mitigation techniques such as blocking or rerouting to prevent attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional DoS attack mitigation systems are used, then network resources are depleted and performance degrades, but the systems fail to timely detect and respond to malicious traffic
Solution Approach 1:
The patent implements preliminary action by proactively monitoring network traffic patterns and establishing baseline behavior before attacks occur. The system pre-configures mitigation gateways at strategic network points (ISP gateways, IXP gateways) to enable immediate response when anomalies are detected, eliminating the detection-response delay that plagues conventional systems.
Solution Approach 2:
The patent introduces mitigation gateways as intermediary components between the network core and attack victims. These gateways act as mediators that can intercept, analyze, and neutralize malicious traffic before it reaches vulnerable systems, enabling timely response without depleting core network resources.
2Object-affected harmful factors
If mitigation gateways are deployed at network aggregation points, then malicious traffic can be filtered effectively, but system complexity increases
Solution Approach 1:
The patent applies universality by designing mitigation gateways with multi-functional capabilities that can operate at multiple network aggregation points (ISP gateways, IXP gateways, data center gateways). This single gateway design handles diverse attack types and can be deployed throughout the network infrastructure, reducing overall system complexity through standardization.
Solution Approach 2:
The patent implements self-service through automated traffic analysis and anomaly detection algorithms that enable the mitigation gateways to independently identify and respond to attacks without requiring constant human intervention or complex centralized control systems.
3Measurement precision
If traffic monitoring and analysis capabilities are enhanced, then attack detection accuracy improves, but processing overhead increases
Solution Approach 1:
The patent applies local quality by implementing distributed monitoring capabilities at specific network aggregation points rather than uniformly across the entire network. Each mitigation gateway focuses its sophisticated analysis capabilities on local traffic patterns, achieving high detection accuracy while minimizing overall processing overhead through localized intelligence.
Data Source
AI summary
Various techniques for mitigating computer network attacks are disclosed herein. In one embodiment, a method includes receiving indications of denial of service attacks from multiple target computing systems and determining one or more sources from which the denial of service attacks are deemed to originate in response to the received indications of denial of service attacks from the target computing systems. The method also includes negotiating with the network aggregation point for permission to divert network traffic originated from the one or more of the determined sources and destined to the target computing systems to the gateway.


