Network Node Whitelist Enforcement for IoT DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The widespread disruption caused by Distributed Denial of Service (DDoS) attacks, where infected Internet of Things (IoT) devices can send unwanted data to unauthorized destinations, consuming network resources and compromising security, is a significant challenge due to limited configurability and control over these devices.
Innovation Solution
A method and system that restricts data packet transmission by updating a whitelist at a network node, allowing data packets to be sent only to verified destination addresses based on criteria such as MAC addresses, IP addresses, and maximum data transmission rates, with user or administrator approval, and resetting the whitelist as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IoT devices are deployed in a network, then network functionality and device connectivity are improved, but security risks and vulnerability to DDoS attacks increase
Solution Approach 1:
The system performs preliminary actions by monitoring data packets during a first time period to learn and build a whitelist of allowed destination addresses before the whitelist is enforced. This preparatory phase allows the network node to establish security rules in advance, enabling it to block malicious traffic while permitting legitimate communications once the whitelist is populated.
Solution Approach 2:
The network node acts as an intermediary between IoT devices and external destinations by intercepting and inspecting data packets. It maintains a whitelist of approved destination addresses and filters traffic accordingly, mediating between the untrusted IoT devices and external networks to prevent unauthorized communications and DDoS attacks.
2Reliability
If a whitelist is enforced to restrict data transmission, then security and control over IoT devices are improved, but network traffic and device configurability are reduced
Solution Approach 1:
The system implements self-service by allowing the network node to automatically monitor, learn, and populate the whitelist with allowed destination addresses without requiring manual configuration of each IoT device. The network node autonomously builds security rules based on observed legitimate traffic patterns, eliminating the need for complex device-by-device configuration while maintaining security control.
Solution Approach 2:
The system performs preliminary learning during a first time period to populate the whitelist before enforcement begins. This advance preparation allows the system to establish security rules based on observed legitimate traffic patterns, reducing the need for manual configuration and making the system easier to deploy while maintaining strong security control.
3Measurement precision
If data packet monitoring and whitelist updates are performed continuously, then security detection accuracy is improved, but network resource consumption and processing time increase
Solution Approach 1:
The system implements periodic action by monitoring and learning during a first time period, then switching to enforcement mode using the established whitelist. This periodic approach alternates between a learning phase for building security rules and an enforcement phase for filtering traffic, reducing continuous processing overhead while maintaining detection accuracy through structured monitoring cycles.
Solution Approach 2:
The system applies partial action by monitoring and learning only during a specific first time period rather than continuously, and by focusing enforcement on the specific whitelist of learned destination addresses. This selective approach reduces overall processing requirements compared to continuous full-spectrum monitoring while maintaining security effectiveness for identified threats.
Data Source
AI summary
A method and a system of restricting data packet transmission of an apparatus at a network node. The network node, during a first time period, updates a whitelist and does not restrict data packet transmission according to the whitelist. After the first time period, the network node determines corresponding destination address of each of the data packets and allows the data packets to be sent to the corresponding destination address if a criteria is satisfactory. The network node does not allow the data packets to be sent to the corresponding destination address if the criteria is not satisfactory. The whitelist is comprised of at least one destination address. The criteria is based on the at least one destination address. The whitelist list is stored in non-transitory computer readable storage medium in the network node.


