Network Service Isolation Against DDoS Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network function virtualization (NFV) based communication networks face limitations in providing effective security measures, particularly in mitigating distributed denial of service (DDoS) attacks, which can disrupt network services and impact performance.
Innovation Solution
A system and method for isolating services in a communication network by detecting DDoS attacks and migrating affected network services to different cloud environments or replicating them to maintain service continuity, thereby minimizing the attack's impact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network services are deployed on generic hardware platforms with virtualization, then network flexibility and dynamicity are improved, but security against DDoS attacks deteriorates
Solution Approach 1:
The patent segments the network service into multiple isolated instances deployed across different hardware platforms. When a DDoS attack targets a service instance, only that specific instance is affected while other instances continue to operate independently, preventing complete service failure and enhancing overall security resilience.
Solution Approach 2:
The patent introduces an intermediary layer of virtualization and service chaining that mediates between the attack source and the core network functions. This intermediary layer can detect, filter, and mitigate DDoS attacks before they reach the critical network services, protecting the system while maintaining flexibility.
2Reliability
If network services are isolated in response to DDoS attacks by migrating to different cloud environments, then service continuity is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal service isolation mechanism that can migrate network services to any available cloud environment or hardware platform. The service chaining framework provides multi-functional capabilities to detect attacks, select target environments, migrate services, and restore operations, managing complexity through standardized procedures.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring multiple target cloud environments and establishing service chaining relationships in advance. When a DDoS attack is detected, the system can immediately migrate services to pre-prepared environments without complex real-time decision-making, reducing operational complexity during crisis response.
Data Source
AI summary
A system, method, and computer program product are provided for isolating services of a communication network in response to a distributed denial of service attack. In use, an indication of a detection of a distributed denial of service (DDoS) attack directed at one or more resources of a communication network is received. Additionally, at least one first network service associated with the communication network that is subject to the DDoS attack is identified. Further, the at least one first network service associated with the communication network that is subject to the DDoS attack is isolated.


