Null Address Routing for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network-based computing resources are vulnerable to manipulation by command and control nodes, leading to disruptions and inefficiencies, particularly in coordinated attacks like DDOS, which affect both the targeted systems and the network service providers.

Innovation Solution

Implementing a monitoring and mitigation service that utilizes null address routing to identify and characterize command and control nodes, thereby disrupting their communication with network-based resources, using null routing addresses to terminate or block their communications and prevent further manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network-based computing resources are made available for public access, then network service productivity and resource utilization are improved, but vulnerability to manipulation and coordinated attacks increases

Engineering Contradiction:
Improvenetwork service productivityVSAvoidvulnerability to manipulation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a monitoring and mitigation service as an intermediary between network users and computing resources. This service acts as a mediator that monitors resource usage, identifies compromised resources through behavioral analysis, and implements mitigation techniques such as null routing to block attacks while allowing legitimate traffic to continue flowing to the resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary monitoring and characterization of computing resources to identify compromised status before attacks occur. By continuously monitoring resource behavior and comparing it against baseline patterns, the system detects anomalies indicating compromise in advance, enabling proactive mitigation rather than reactive response.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If monitoring and mitigation services are implemented to detect compromised resources, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring and mitigation service creates virtual copies or representations of computing resources to monitor their behavior without interfering with actual operations. By analyzing copies of resource data and communication patterns, the system can identify compromised resources and implement mitigation at the routing level without adding physical complexity to the underlying infrastructure.

Inventive Principle:
Principle #26Copying

3Object-generated harmful factors

If null routing is used to block command and control nodes, then attack disruption is improved, but routing information must be dynamically updated

Engineering Contradiction:
Improveattack disruptionVSAvoidrouting information management
Core Design Contradiction:
Object-generated harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements dynamic null routing where routing tables are automatically updated based on real-time identification of compromised resources. The system transitions from static routing configurations to dynamic routing that adapts to changing threat conditions, allowing null routes to be created, modified, or removed as resources are identified as compromised or recovered.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12155690B1Managing network mitigation techniques
Publication Date: 2024.11.26 AMAZON TECH INC
  • US12155690B1 patent drawing
  • US12155690B1 patent drawing
  • US12155690B1 patent drawing

AI summary

The present disclosure generally relates to systems and methods for utilization of network mitigation techniques in the form of null address routing to mitigate coordinated DDOS attacks. A monitoring and mitigation service can characterize a command and control node as compromised or otherwise manipulated for purposes of generating distributed attacks. The monitoring and mitigation service can then identify network mitigation information in the form of null routing addresses that will cause network communications associated with the identified command and control node to be terminated or otherwise not delivered to the intended network-based resources. The monitoring and mitigation service can propagate the null routing address to routing components. The network mitigation information can be associated with expiration criteria for the routing components that receive and implement the network mitigation technique.