Mitigation Server Request Routing via DADI Registry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DDOS mitigation systems face challenges in identifying and coordinating effective mitigation actions across client domains, particularly due to issues with authorization and resource capabilities of mitigation servers, leading to unanswered attack management requests.
Innovation Solution
A method is proposed where a first attack mitigation server identifies and obtains information about a second authorized mitigation server using client domain identifiers, ensuring that attack management requests are not left unanswered by routing them to capable servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a DOTS server refuses to process signaling messages from a DOTS client due to inability to process the request, then the server avoids processing errors or conflicts, but the mitigation request remains unanswered and no protection is provided to the client domain
Solution Approach 1:
The patent introduces a DADI registry as an intermediary component that mediates between DOTS servers and client domains. When a DOTS server cannot process a mitigation request, it queries the DADI registry to obtain the appropriate DADI identifier, which then routes the request to the correct authorized server. This intermediary mechanism ensures requests are not refused but properly directed, maintaining both reliability and responsiveness.
Solution Approach 2:
The patent implements preliminary action by pre-registering DADI identifiers in the DADI registry before mitigation requests are made. The registry maintains advance knowledge of which servers are authorized to protect which client domains, allowing for immediate proper routing when a request is received, rather than having to determine server capability at the moment of request processing.
2Adaptability or versatility
If multiple DOTS servers are deployed to provide DDOS protection services to different client domains, then service coverage and protection capability are improved, but coordination difficulties arise and requests may be processed by unauthorized servers
Solution Approach 1:
The patent creates a universal DADI registry that serves all DOTS servers and client domains within a DOTS service infrastructure. This single registry performs multiple functions: storing DADI identifiers, enabling server authorization verification, and facilitating request routing. This universal component allows multiple servers to operate independently while maintaining coordinated protection across different client domains, increasing service coverage without proportionally increasing coordination complexity.
3Ease of operation
If a DOTS server processes requests from any client domain, then request responsiveness is improved, but unauthorized processing occurs and mitigation actions may conflict with client domain policies
Solution Approach 1:
The patent implements a feedback mechanism where DOTS servers query the DADI registry to verify authorization before processing mitigation requests. The registry provides feedback information (the DADI identifier) that confirms whether a server is authorized to protect a specific client domain. This feedback loop ensures that only authorized servers process requests, maintaining reliability while keeping processing available through proper routing.
Data Source
AI summary
Services for detecting and mitigating computer attacks are proposed by some access providers to their customers. However, sometimes a message to request support for the management of attacks issued by a node of a client domain under computer attack is sent to a mitigation server that is unable to process it. Such a request will be systematically rejected and no mitigation action will be implemented. The present solution makes it possible to ensure that no request message issued by a node goes unanswered, even if it is transmitted to a mitigation server that is unable to process it. To this end, when a mitigation server determines that it is unable to process a request message, instead of rejecting this request, it will seek to identify at least one other mitigation server that would be able to process this request message.


