Distributed Network Overload Protection via Traffic Diversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current distributed data networks lack effective solutions to protect against distributed denial of service (DDoS) attacks, which overwhelm network nodes with fake requests, causing disruptions and access blockages.

Innovation Solution

The method involves diverting traffic destined for a victim node to a secondary set of network elements for filtering and rerouting, using techniques like Policy Based Routing, WCCP, and BGP announcements, to redirect traffic paths and filter out malicious requests, while maintaining network stability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic is diverted to a secondary set of network elements for filtering, then protection against DDoS attacks is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against DDoS attacksVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a secondary set of network elements (intermediaries) between the victim node and the malicious traffic sources. These intermediaries perform filtering and rerouting functions, acting as mediators that protect the victim without requiring the victim itself to handle the complex filtering logic. This resolves the contradiction by externalizing the complexity to dedicated intermediary components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network is segmented into multiple functional components: the victim node, the primary network path, and the secondary filtering path with network elements. This segmentation allows the filtering and protection functions to be separated from the victim node, improving reliability while concentrating complexity in dedicated filtering components rather than分散 throughout the network.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traffic paths are redirected through additional network elements, then filtering capability is improved, but loss of time increases

Engineering Contradiction:
Improvefiltering capabilityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The secondary network elements are pre-configured with filtering rules and routing information before attacks occur. When malicious traffic is detected, the diversion to pre-prepared filtering paths can be activated immediately, reducing the time penalty. The filtering infrastructure is built in advance, so when needed, traffic can be rapidly redirected without extensive setup time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a secondary filtering path is implemented, then protection effectiveness is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveprotection effectivenessVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system incorporates automated detection and response mechanisms where the network elements can autonomously identify malicious traffic patterns and activate filtering paths without manual intervention. This self-service capability maintains high protection effectiveness while reducing the operational burden on network administrators, as the system automatically manages the complexity of coordinating multiple filtering elements.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7707305B2Methods and apparatus for protecting against overload conditions on nodes of a distributed network
Publication Date: 2010.04.27 WANWALL
  • US7707305B2 patent drawing
  • US7707305B2 patent drawing
  • US7707305B2 patent drawing

AI summary

Methods and apparatus for protecting against and/or responding to an overload condition at a node (“victim”) in a distributed network divert traffic otherwise destined for the victim to one or more other nodes, which can filter the diverted traffic, passing a portion of it to the victim, and/or effect processing of one or more of the diverted packets on behalf of the victim. Diversion can be performed by one or more nodes (collectively, a “first set” of nodes) external to the victim. Filtering and/or effecting traffic processing can be performed by one or more nodes (collectively, a “second set” of nodes) also external to the victim. Those first and second sets can have zero, one or more nodes in common—or, put another way, they may wholly, partially or not overlap. The methods and apparatus have application in protecting nodes in a distributed network, such as the Internet, against distributed denial of service (DDoS) attacks.