Distributed Network Overload Protection via Traffic Diversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current distributed data networks lack effective solutions to protect against distributed denial of service (DDoS) attacks, which overwhelm network nodes with fake requests, causing disruptions and access blockages.
Innovation Solution
The method involves diverting traffic destined for a victim node to a secondary set of network elements for filtering and rerouting, using techniques like Policy Based Routing, WCCP, and BGP announcements, to redirect traffic paths and filter out malicious requests, while maintaining network stability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic is diverted to a secondary set of network elements for filtering, then protection against DDoS attacks is improved, but device complexity increases
Solution Approach 1:
The patent introduces a secondary set of network elements (intermediaries) between the victim node and the malicious traffic sources. These intermediaries perform filtering and rerouting functions, acting as mediators that protect the victim without requiring the victim itself to handle the complex filtering logic. This resolves the contradiction by externalizing the complexity to dedicated intermediary components.
Solution Approach 2:
The network is segmented into multiple functional components: the victim node, the primary network path, and the secondary filtering path with network elements. This segmentation allows the filtering and protection functions to be separated from the victim node, improving reliability while concentrating complexity in dedicated filtering components rather than分散 throughout the network.
2Reliability
If traffic paths are redirected through additional network elements, then filtering capability is improved, but loss of time increases
Solution Approach 1:
The secondary network elements are pre-configured with filtering rules and routing information before attacks occur. When malicious traffic is detected, the diversion to pre-prepared filtering paths can be activated immediately, reducing the time penalty. The filtering infrastructure is built in advance, so when needed, traffic can be rapidly redirected without extensive setup time.
3Reliability
If a secondary filtering path is implemented, then protection effectiveness is improved, but ease of operation deteriorates
Solution Approach 1:
The system incorporates automated detection and response mechanisms where the network elements can autonomously identify malicious traffic patterns and activate filtering paths without manual intervention. This self-service capability maintains high protection effectiveness while reducing the operational burden on network administrators, as the system automatically manages the complexity of coordinating multiple filtering elements.
Data Source
AI summary
Methods and apparatus for protecting against and/or responding to an overload condition at a node (“victim”) in a distributed network divert traffic otherwise destined for the victim to one or more other nodes, which can filter the diverted traffic, passing a portion of it to the victim, and/or effect processing of one or more of the diverted packets on behalf of the victim. Diversion can be performed by one or more nodes (collectively, a “first set” of nodes) external to the victim. Filtering and/or effecting traffic processing can be performed by one or more nodes (collectively, a “second set” of nodes) also external to the victim. Those first and second sets can have zero, one or more nodes in common—or, put another way, they may wholly, partially or not overlap. The methods and apparatus have application in protecting nodes in a distributed network, such as the Internet, against distributed denial of service (DDoS) attacks.


