Network Traffic Traceability via Direct Interconnect and Almanac
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In high-capacity communications networks, determining the traceability of network traffic in real-time is challenging due to the difficulty in authenticating source addresses, leading to issues with payload amplification attacks and network congestion, particularly with stateless transport protocols like DNS, where attackers exploit amplifiers to launch DDoS attacks.
Innovation Solution
A system is implemented that provides a direct interconnect between servers and predefined sources with a private service interface, along with a public service interface, where pairing data is stored as a network traffic almanac to differentiate between legitimate and illegitimate traffic, allowing for dynamic prioritization of request processing based on the interface used.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If stateless transport protocols are used for efficient network communication, then network efficiency is improved, but traceability of network traffic deteriorates
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that operates between the stateless transport layer and the application layer. This intermediary verifies source address authenticity without disrupting the efficiency of stateless protocols, thereby maintaining both network efficiency and traceability.
Solution Approach 2:
The patent implements preliminary authentication of source addresses before traffic processing. By pre-validating source addresses and establishing trust relationships in advance, the system maintains traceability while allowing efficient stateless transport of authenticated traffic.
2Reliability
If source address authentication is performed to ensure traceability, then traceability is improved, but processing time increases
Solution Approach 1:
The patent performs source address authentication in advance by establishing trust relationships and validating addresses before traffic processing. This preliminary action ensures traceability is established upfront, allowing subsequent traffic to be processed without repeated authentication delays.
Solution Approach 2:
The patent changes the parameter of authentication from per-packet verification to pre-established trust relationships. By transforming the authentication mechanism from a time-intensive per-packet process to a pre-configured parameter validation, traceability is maintained while processing time is reduced.
3Device complexity
If all network traffic is processed equally, then network simplicity is maintained, but resource strain increases during attacks
Solution Approach 1:
The patent applies local quality by treating authenticated and unauthenticated traffic differently. Authenticated traffic receives standard processing while unauthenticated traffic is subjected to additional verification or rate limiting, allowing the network to maintain simplicity for legitimate traffic while protecting resources from attacks.
Solution Approach 2:
The patent implements partial action by applying enhanced processing only to suspicious or unauthenticated traffic rather than all traffic. This selective approach maintains network simplicity for the majority of legitimate traffic while dedicating additional resources to identify and mitigate attack traffic.
4Reliability
If amplification is restricted to constrained clients, then security is improved, but service availability deteriorates
Solution Approach 1:
The patent implements dynamic amplification restrictions that adapt based on authentication status and traffic patterns. Rather than statically constraining all amplification, the system dynamically allows authenticated clients to use amplification while restricting unauthenticated traffic, thereby maintaining both security and service availability.
Solution Approach 2:
The patent changes the parameter of amplification from a static restriction to a dynamic permission based on authentication. By transforming amplification from a universally constrained feature to an authenticated capability, the system improves security while maintaining service availability for legitimate users.
Data Source
AI summary
A system and method for determining the traceability of network request traffic over a communications network for reducing strain in traffic processing resources, which includes: provisioning a direct interconnect on the communications network between the server and a predefined source, the direct interconnect providing a private service interface, a defined pairings data of the predefined source with the direct interconnect stored as a network traffic almanac; provisioning a public service interface on the communications network; receiving a request traffic having an address of the predefined source via the public service interface; consulting the defined pairing data with the address to determine the request traffic matches the predefined source; and de-prioritizing the processing of the request traffic based on the request traffic being received on the public service interface rather than on the direct interconnect by dynamically applying a prioritize criterion to the second request traffic before generating a response traffic.


