Network Attack Protection via Gateway Traffic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network attack protection methods primarily focus on cleaning service requests at victim hosts after a DDOS attack has already blocked upstream networks, wasting bandwidth and resources.

Innovation Solution

A method and system that identify and block attackers by sending control messages to gateways corresponding to attack sources and controllers, preventing traffic from reaching victim hosts and conserving network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a DDOS cleaning device is used to clean service requests at victim hosts, then the victim hosts are protected from attacks, but the upstream network becomes blocked and network bandwidth is wasted

Engineering Contradiction:
Improvevictim host protectionVSAvoidnetwork bandwidth waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by proactively detecting attack sources and controllers before attacks reach victim hosts, and preemptively blocking their traffic through gateways. The system identifies attackers and controllers, obtains their gateway address information, and sends control messages to block traffic before the attacks can consume network bandwidth and block upstream networks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses gateways as intermediary devices to block attacker and controller traffic. Instead of allowing attacks to reach victim hosts directly, the system sends control messages to gateways corresponding to attack sources and controllers, which then intercept and block the malicious traffic at the network perimeter, preventing bandwidth waste while maintaining victim host protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If traffic control messages are sent to gateways corresponding to attackers, then upstream network blockage is prevented, but additional system complexity is introduced

Engineering Contradiction:
Improvenetwork bandwidth conservationVSAvoidsystem architecture complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent applies universality by using existing gateway devices to perform multiple functions: their original network routing functions plus the additional function of blocking attacker and controller traffic. The gateways receive control messages from the protection system and implement traffic blocking, eliminating the need for separate blocking devices and reducing overall system complexity while conserving network bandwidth.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9088607B2Method, device, and system for network attack protection
Publication Date: 2015.07.21 CHENGDU HUAWEI TECH CO LTD
  • US9088607B2 patent drawing
  • US9088607B2 patent drawing
  • US9088607B2 patent drawing

AI summary

The present invention discloses a method for network attack protection, a device, and a system thereof. The method includes: receiving information about attack source, in which the information about the attack source carries address information about an attacker; obtaining address information about a gateway corresponding to the attacker according to the address information about the attacker and a preset mapping relationship between the attacker and the gateway corresponding to the attacker; and sending a first control message to the gateway corresponding to the attacker according to the address information about the gateway corresponding to the attacker, wherein the first control message instructs the gateway corresponding to the attacker to control traffic of the attacker. The present invention may be used on a communications network to prevent the attacker from attacking victim hosts on the network from the root, avoid blockage on the upstream network of the victim hosts.