Multi-tiered Network Cyber-Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large-scale networks face challenges in protecting resources against sophisticated denial of service (DoS) and distributed denial of service (DDoS) attacks due to the static and non-scalable nature of current detection and mitigation systems, leading to underutilization of expensive resources and inefficiencies in managing dynamic network changes and cyber threats.
Innovation Solution
A method and system for dynamically controlling multi-tiered mitigation of cyber-attacks by monitoring availability and load of protection resources in a multi-tiered communication network, computing an aggregated load metric, and selecting appropriate resources to efficiently handle detected attacks based on capacity and security capabilities across different tiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If high capacity mitigation systems are deployed in edge networks to ensure mitigation capability, then security protection capability is improved, but resource underutilization and cost increase
Solution Approach 1:
The patent implements dynamic mitigation resource allocation where the security system continuously monitors attack patterns and network conditions, then dynamically assigns mitigation resources across the backbone network. Instead of static deployment at edge networks, resources are dynamically activated and positioned based on real-time threat assessment, ensuring both high reliability and optimal resource utilization.
Solution Approach 2:
The patent creates a shared mitigation resource pool in the backbone network that serves multiple edge networks simultaneously. A single high-capacity mitigation system can protect multiple customers and services across different edge networks, making the resource universal and eliminating the need for each edge network to deploy its own dedicated high-capacity system.
2Reliability
If static detection and mitigation systems are deployed in edge and backbone networks, then security coverage is improved, but scalability and adaptability to dynamic changes deteriorate
Solution Approach 1:
The patent replaces static detection and mitigation systems with dynamic architectures that continuously adapt to changing network conditions and attack patterns. The system monitors resource availability, load conditions, and threat intelligence in real-time, dynamically adjusting detection sensitivity and mitigation strategies to maintain effective security coverage while adapting to dynamic changes.
Solution Approach 2:
The patent implements feedback mechanisms where the security system continuously monitors attack patterns, resource utilization, and system performance. This feedback is used to dynamically adjust detection thresholds, allocate mitigation resources, and update security policies, enabling the system to adapt to changing threats and network conditions while maintaining comprehensive security coverage.
3Reliability
If high capacity mitigation systems are deployed to handle sophisticated DoS/DDoS attacks, then attack mitigation capability is improved, but cost and return on investment deteriorate
Solution Approach 1:
The patent merges multiple mitigation resources into a shared pool in the backbone network, combining the capabilities of what would otherwise be separate edge network systems. This consolidation allows high-capacity mitigation to handle sophisticated attacks while reducing total cost through resource sharing and elimination of redundant deployments.
Solution Approach 2:
The patent makes mitigation resources universal by enabling a single high-capacity system in the backbone network to serve multiple edge networks and customers. This multi-functionality reduces the total quantity of mitigation resources needed compared to deploying dedicated systems at each edge network, thereby reducing overall cost while maintaining attack mitigation capability.
Data Source
AI summary
A method and system for controlling multi-tiered mitigation of cyber-attacks. The method comprises monitoring at least availability and load of each protection resource in a multi-tiered communication network, wherein each tier in the multi-tiered communication network includes a plurality of protection resources having capacity and security capabilities set according to the respective tier; for each protection resource, computing a current aggregated load metric (ALM); determining based on at least one of the computed ALM and security capabilities of a respective protection resource, if the respective protection resource assigned to a protected entity can efficiently handle a detected cyber-attack against the protected entity; and selecting at least one new protection resource to secure the protected entity, upon determining the protection resource cannot efficiently handle the detected cyber-attack, wherein the selection is based on at least one of the computed ALM and a security capabilities of the at least one protection resource.


