Network Node Whitelist Enforcement for IoT DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The widespread disruption caused by Distributed Denial of Service (DDoS) attacks, where infected Internet of Things (IoT) devices can send unwanted data to unauthorized destinations, consuming network resources and compromising security, is a significant challenge due to limited configurability and control over these devices.

Innovation Solution

A method and system that restricts data packet transmission by updating a whitelist at a network node, allowing data packets to be sent only to verified destination addresses based on criteria such as MAC addresses, IP addresses, and maximum data transmission rates, with user or administrator approval, and resetting the whitelist as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are deployed in a network, then network functionality and device connectivity are improved, but security risks and vulnerability to DDoS attacks increase

Engineering Contradiction:
Improvenetwork functionalityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by monitoring data packets during a first time period to learn and build a whitelist of allowed destination addresses before the whitelist is enforced. This preparatory phase allows the network node to establish security rules in advance, enabling it to block malicious traffic while permitting legitimate communications once the whitelist is populated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network node acts as an intermediary between IoT devices and external destinations by intercepting and inspecting data packets. It maintains a whitelist of approved destination addresses and filters traffic accordingly, mediating between the untrusted IoT devices and external networks to prevent unauthorized communications and DDoS attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a whitelist is enforced to restrict data transmission, then security and control over IoT devices are improved, but network traffic and device configurability are reduced

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice configurability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by allowing the network node to automatically monitor, learn, and populate the whitelist with allowed destination addresses without requiring manual configuration of each IoT device. The network node autonomously builds security rules based on observed legitimate traffic patterns, eliminating the need for complex device-by-device configuration while maintaining security control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary learning during a first time period to populate the whitelist before enforcement begins. This advance preparation allows the system to establish security rules based on observed legitimate traffic patterns, reducing the need for manual configuration and making the system easier to deploy while maintaining strong security control.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If data packet monitoring and whitelist updates are performed continuously, then security detection accuracy is improved, but network resource consumption and processing time increase

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidnetwork resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system implements periodic action by monitoring and learning during a first time period, then switching to enforcement mode using the established whitelist. This periodic approach alternates between a learning phase for building security rules and an enforcement phase for filtering traffic, reducing continuous processing overhead while maintaining detection accuracy through structured monitoring cycles.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system applies partial action by monitoring and learning only during a specific first time period rather than continuously, and by focusing enforcement on the specific whitelist of learned destination addresses. This selective approach reduces overall processing requirements compared to continuous full-spectrum monitoring while maintaining security effectiveness for identified threats.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11722458B2Method and system for restricting transmission of data traffic for devices with networking capabilities
Publication Date: 2023.08.08 PISMO LABS TECH
  • US11722458B2 patent drawing
  • US11722458B2 patent drawing
  • US11722458B2 patent drawing

AI summary

A method and a system of restricting data packet transmission of an apparatus at a network node. The network node, during a first time period, updates a whitelist and does not restrict data packet transmission according to the whitelist. After the first time period, the network node determines corresponding destination address of each of the data packets and allows the data packets to be sent to the corresponding destination address if a criteria is satisfactory. The network node does not allow the data packets to be sent to the corresponding destination address if the criteria is not satisfactory. The whitelist is comprised of at least one destination address. The criteria is based on the at least one destination address. The whitelist list is stored in non-transitory computer readable storage medium in the network node.