Network Service Isolation Against DDoS Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network function virtualization (NFV) based communication networks face limitations in providing effective security measures, particularly in mitigating distributed denial of service (DDoS) attacks, which can disrupt network services and impact performance.

Innovation Solution

A system and method for isolating services in a communication network by detecting DDoS attacks and migrating affected network services to different cloud environments or replicating them to maintain service continuity, thereby minimizing the attack's impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network services are deployed on generic hardware platforms with virtualization, then network flexibility and dynamicity are improved, but security against DDoS attacks deteriorates

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsecurity against DDoS attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the network service into multiple isolated instances deployed across different hardware platforms. When a DDoS attack targets a service instance, only that specific instance is affected while other instances continue to operate independently, preventing complete service failure and enhancing overall security resilience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer of virtualization and service chaining that mediates between the attack source and the core network functions. This intermediary layer can detect, filter, and mitigate DDoS attacks before they reach the critical network services, protecting the system while maintaining flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network services are isolated in response to DDoS attacks by migrating to different cloud environments, then service continuity is improved, but system complexity increases

Engineering Contradiction:
Improveservice continuityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal service isolation mechanism that can migrate network services to any available cloud environment or hardware platform. The service chaining framework provides multi-functional capabilities to detect attacks, select target environments, migrate services, and restore operations, managing complexity through standardized procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary actions by pre-configuring multiple target cloud environments and establishing service chaining relationships in advance. When a DDoS attack is detected, the system can immediately migrate services to pre-prepared environments without complex real-time decision-making, reducing operational complexity during crisis response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10764323B1System, method, and computer program for isolating services of a communication network in response to a distributed denial of service (DDoS) attack
Publication Date: 2020.09.01 AMDOCS DEV LTD
  • US10764323B1 patent drawing
  • US10764323B1 patent drawing
  • US10764323B1 patent drawing

AI summary

A system, method, and computer program product are provided for isolating services of a communication network in response to a distributed denial of service attack. In use, an indication of a detection of a distributed denial of service (DDoS) attack directed at one or more resources of a communication network is received. Additionally, at least one first network service associated with the communication network that is subject to the DDoS attack is identified. Further, the at least one first network service associated with the communication network that is subject to the DDoS attack is isolated.