Network Traffic Lane Segmentation for Targeted DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for mitigating DDoS attacks often inadvertently affect non-malicious traffic, leading to inefficient service disruptions and resource wastage, as they rely on coarse criteria for identifying and filtering malicious network traffic.
Innovation Solution
Network traffic is divided into multiple lanes based on granular criteria, allowing for individual analysis and targeted remedial actions on suspicious lanes, thereby isolating DDoS attacks and conserving resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party providers use coarse criteria to filter malicious traffic, then DDoS protection is achieved, but non-malicious traffic is inadvertently affected
Solution Approach 1:
The patent segments network traffic into multiple lanes based on granular criteria such as source IP address, destination IP address, port numbers, and protocol types. This segmentation allows the system to apply different filtering rules to different traffic lanes, enabling precise identification of malicious traffic while preserving legitimate traffic. The segmentation principle directly resolves the contradiction by replacing coarse filtering with fine-grained classification, so that DDoS protection is applied only to specific lanes exhibiting attack patterns rather than all traffic.
Solution Approach 2:
The patent applies local quality by assigning different characteristics and filtering behaviors to different traffic lanes. Each lane is evaluated independently based on its specific traffic patterns, allowing the system to identify and block malicious lanes while maintaining normal service for legitimate lanes. This localized approach enables the system to respond differently to different traffic sources, resolving the contradiction between providing broad DDoS protection and avoiding unintended denial of service.
2Reliability
If all traffic is filtered using coarse criteria, then system resources are protected, but legitimate traffic is blocked
Solution Approach 1:
By dividing traffic into multiple lanes based on granular criteria, the system can apply protective measures only to lanes that exhibit malicious patterns rather than filtering all traffic. This segmentation enables selective protection that preserves system resources while maintaining productivity for legitimate traffic lanes that do not require intervention.
Solution Approach 2:
The patent applies partial action by filtering only the portion of traffic that is suspected of being malicious, rather than applying blanket filtering to all traffic. The system identifies specific lanes with abnormal traffic patterns and applies filtering only to those lanes, allowing legitimate traffic to continue uninterrupted. This partial approach resolves the contradiction by providing sufficient protection without excessive impact on overall productivity.
3Measurement precision
If granular criteria are used to identify malicious traffic, then precision of identification is improved, but system complexity increases
Solution Approach 1:
The patent manages complexity through segmentation by organizing traffic analysis into discrete lanes, each governed by specific granular criteria. This modular approach breaks down the complex task of analyzing all traffic into manageable segments, making the system more scalable and easier to maintain. Each lane can be independently monitored and filtered based on its characteristics, reducing the overall complexity compared to a monolithic filtering system.
Solution Approach 2:
The patent introduces traffic lanes as intermediary structures between the raw network traffic and the filtering decisions. These lanes serve as mediators that organize and pre-classify traffic before final filtering occurs, simplifying the decision-making process. By using lanes as intermediaries, the system can apply granular criteria systematically without overwhelming complexity, as the lane structure provides a ready-made framework for analysis.
4Reliability
If third-party monitoring is used, then DDoS detection capability is improved, but dependency on external services increases
Solution Approach 1:
The patent enables self-service by implementing traffic lane analysis and filtering capabilities within the service provider's own infrastructure. The system uses locally available data and processing resources to identify and respond to DDoS attacks without requiring continuous external monitoring services. This self-service approach maintains high detection capability while reducing dependency on third-party providers, allowing the system to operate autonomously.
Solution Approach 2:
The patent eliminates the need for third-party intermediaries by using internal traffic lanes as the monitoring and analysis mechanism. The traffic lanes serve as self-contained units that can detect and respond to attacks using locally stored data and processing capabilities. This removes the dependency on external services while maintaining the ability to detect and mitigate DDoS attacks effectively.
Data Source
AI summary
Disclosed herein are systems and methods for identifying and addressing malicious network traffic based on network traffic lane activity. An example method includes receiving data associated with a plurality of messages transmitted via a network, determining a first network traffic lane associated with a first set of messages of the plurality of messages and a second network traffic lane associated with a second set of messages of the plurality of messages, and determining that the first set of messages is associated with an increased probability of being involved in a distributed denial of service (DDoS) attack. In examples, the method includes causing at least one remedial action to be performed for at least a portion of messages associated with the first network traffic lane. Non-transitory machine-readable mediums are also disclosed.


