Anonymous Network Flow Tracing in Autonomous Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for tracing network flows in Autonomous Systems are computationally intensive and resource-heavy, particularly when dealing with Denial of Service (DoS) attacks, and are ineffective in identifying the source of Distributed Denial of Service (DDoS) attacks, often requiring extensive network resources and Public Key Infrastructures.
Innovation Solution
A method and apparatus that involves assigning unique Router Labels and External Interface Labels to routers within an Autonomous System, allowing the Director to track flows by marking packets with these labels only when necessary, minimizing network disruption and computational overhead, and enabling automated tracing of packet flow sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If hash-based or iTrace methods are used for IP trace back, then trace back capability is improved, but computational overhead and memory requirements increase significantly
Solution Approach 1:
The patent extracts only the essential marking information (router ID and interface identifier) from full packet inspection, placing minimal markers in packet headers. This selective extraction approach enables trace back capability while avoiding the computational overhead of hash-based methods that require processing and storing hashed values of every packet.
Solution Approach 2:
The patent uses simple, lightweight packet markers that can be easily created and discarded, rather than maintaining complex data structures. Each router adds a small marker to packets, and these markers are processed and discarded after trace back, avoiding the need for extensive memory resources required by prior art methods.
2Measurement precision
If marking mechanisms are always turned on to enable trace back, then trace back accuracy is improved, but network resource consumption increases
Solution Approach 1:
The patent implements periodic or on-demand marking rather than continuous marking. Routers mark packets only when trace back is actually needed (e.g., when suspicious traffic is detected or upon request), rather than continuously marking all packets. This periodic action maintains trace back accuracy when needed while significantly reducing network resource consumption during normal operation.
3Reliability
If extensive network resources are allocated for trace back infrastructure, then trace back effectiveness is improved, but system complexity and cost increase
Solution Approach 1:
The patent designs the marking mechanism to be universally applicable across all routers in the network using standard IP header fields. The same marking infrastructure serves both normal trace back operations and security monitoring functions. This multi-functionality approach improves trace back effectiveness without requiring separate specialized infrastructure, thereby reducing overall system complexity.
4Measurement precision
If manual hop-by-hop trace back is performed, then trace back detail is improved, but time consumption and operational complexity increase
Solution Approach 1:
The patent performs preliminary marking at each router hop as packets traverse the network. Each router预先 (in advance) inserts its identifier marker into packets before forwarding them. This preliminary action ensures that when trace back is needed, all routing information is already captured in the packet markers, eliminating the need for time-consuming manual hop-by-hop investigation and enabling automated rapid trace back.
Data Source
AI summary
A system and method of tracing network flows in an autonomous communications system are described. The Autonomous System may be formed of multiple subgroups depending on size and application. Each subgroup contains multiple, interconnected routers which participate in transporting data flow across the Autonomous System (AS). A Director within the AS has a full and complete vision of the network topology. When it is desired to trace a particular flow because of an identified attack, selected routers in key locations—through which that particular flow travels—mark packets with labels which enable the tracing of the path. These labels permit the source of the attack, at least in so far as it travels through the AS, to be identified. If the number of entry (or key) points to the AS is larger than the number of available labels, the AS will be divided into subgroups, the flow is traced from subgroup to subgroup.

