Network Traffic Lane Segmentation for Targeted DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for mitigating DDoS attacks often inadvertently affect non-malicious traffic, leading to inefficient service disruptions and resource wastage, as they rely on coarse criteria for identifying and filtering malicious network traffic.

Innovation Solution

Network traffic is divided into multiple lanes based on granular criteria, allowing for individual analysis and targeted remedial actions on suspicious lanes, thereby isolating DDoS attacks and conserving resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If third-party providers use coarse criteria to filter malicious traffic, then DDoS protection is achieved, but non-malicious traffic is inadvertently affected

Engineering Contradiction:
ImproveDDoS protectionVSAvoidunintentional denial of service to non-malicious traffic
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments network traffic into multiple lanes based on granular criteria such as source IP address, destination IP address, port numbers, and protocol types. This segmentation allows the system to apply different filtering rules to different traffic lanes, enabling precise identification of malicious traffic while preserving legitimate traffic. The segmentation principle directly resolves the contradiction by replacing coarse filtering with fine-grained classification, so that DDoS protection is applied only to specific lanes exhibiting attack patterns rather than all traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different characteristics and filtering behaviors to different traffic lanes. Each lane is evaluated independently based on its specific traffic patterns, allowing the system to identify and block malicious lanes while maintaining normal service for legitimate lanes. This localized approach enables the system to respond differently to different traffic sources, resolving the contradiction between providing broad DDoS protection and avoiding unintended denial of service.

Inventive Principle:
Principle #3Local quality

2Reliability

If all traffic is filtered using coarse criteria, then system resources are protected, but legitimate traffic is blocked

Engineering Contradiction:
Improvesystem protectionVSAvoidlegitimate traffic processing
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By dividing traffic into multiple lanes based on granular criteria, the system can apply protective measures only to lanes that exhibit malicious patterns rather than filtering all traffic. This segmentation enables selective protection that preserves system resources while maintaining productivity for legitimate traffic lanes that do not require intervention.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by filtering only the portion of traffic that is suspected of being malicious, rather than applying blanket filtering to all traffic. The system identifies specific lanes with abnormal traffic patterns and applies filtering only to those lanes, allowing legitimate traffic to continue uninterrupted. This partial approach resolves the contradiction by providing sufficient protection without excessive impact on overall productivity.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If granular criteria are used to identify malicious traffic, then precision of identification is improved, but system complexity increases

Engineering Contradiction:
Improvetraffic identification precisionVSAvoidtraffic analysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent manages complexity through segmentation by organizing traffic analysis into discrete lanes, each governed by specific granular criteria. This modular approach breaks down the complex task of analyzing all traffic into manageable segments, making the system more scalable and easier to maintain. Each lane can be independently monitored and filtered based on its characteristics, reducing the overall complexity compared to a monolithic filtering system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces traffic lanes as intermediary structures between the raw network traffic and the filtering decisions. These lanes serve as mediators that organize and pre-classify traffic before final filtering occurs, simplifying the decision-making process. By using lanes as intermediaries, the system can apply granular criteria systematically without overwhelming complexity, as the lane structure provides a ready-made framework for analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If third-party monitoring is used, then DDoS detection capability is improved, but dependency on external services increases

Engineering Contradiction:
ImproveDDoS detection capabilityVSAvoidindependence from third-party providers
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent enables self-service by implementing traffic lane analysis and filtering capabilities within the service provider's own infrastructure. The system uses locally available data and processing resources to identify and respond to DDoS attacks without requiring continuous external monitoring services. This self-service approach maintains high detection capability while reducing dependency on third-party providers, allowing the system to operate autonomously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent eliminates the need for third-party intermediaries by using internal traffic lanes as the monitoring and analysis mechanism. The traffic lanes serve as self-contained units that can detect and respond to attacks using locally stored data and processing capabilities. This removes the dependency on external services while maintaining the ability to detect and mitigate DDoS attacks effectively.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250337774A1Systems and methods for identifying and addressing malicious network traffic based on network traffic lane activity
Publication Date: 2025.10.30 STRIPE LLC
  • US20250337774A1 patent drawing
  • US20250337774A1 patent drawing
  • US20250337774A1 patent drawing

AI summary

Disclosed herein are systems and methods for identifying and addressing malicious network traffic based on network traffic lane activity. An example method includes receiving data associated with a plurality of messages transmitted via a network, determining a first network traffic lane associated with a first set of messages of the plurality of messages and a second network traffic lane associated with a second set of messages of the plurality of messages, and determining that the first set of messages is associated with an increased probability of being involved in a distributed denial of service (DDoS) attack. In examples, the method includes causing at least one remedial action to be performed for at least a portion of messages associated with the first network traffic lane. Non-transitory machine-readable mediums are also disclosed.