Null Address Routing for Malware Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network service providers face significant challenges in mitigating the manipulation of network-based computing resources by malware code distribution nodes, which can lead to coordinated attacks like DDOS, causing congestion and disrupting network services.

Innovation Solution

The implementation of a monitoring and mitigation service that utilizes null address routing to detect and characterize malware code distribution nodes, and subsequently applies network mitigation techniques to prevent further manipulation of network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network devices are monitored and null address routing is applied to mitigate malware distribution, then network service integrity is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvenetwork service integrityVSAvoidmonitoring and mitigation service complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by proactively monitoring network devices for malware code installation before compromised devices can be utilized for coordinated attacks. The monitoring service detects malware code distribution in advance and applies null address routing mitigation preemptively, preventing potential network service disruptions before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring and mitigation service acts as an intermediary between network devices and the external network environment. It intercepts and analyzes network traffic to detect malware distribution, then applies null address routing as a mediating mechanism to block communication between compromised devices and malware distribution sites, thereby protecting network service integrity without requiring changes to individual network devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive monitoring of network devices is implemented to detect malware code installation, then detection precision is improved, but loss of time and processing overhead increase

Engineering Contradiction:
Improvemalware detection precisionVSAvoidmonitoring and response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The monitoring service extracts and isolates specific indicators of malware code installation from general network traffic. By focusing on distinctive characteristics of malware distribution patterns rather than analyzing all network communications equally, the system achieves high detection precision while minimizing processing time and avoiding unnecessary analysis of benign traffic.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes monitoring parameters dynamically based on detected threats. When malware distribution is detected, the monitoring service adjusts its focus and intensity for specific network devices and traffic patterns, rather than maintaining uniform monitoring across all devices. This parameter adaptation enables precise detection of malware while reducing overall processing overhead by concentrating resources on suspicious activities.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12341805B1Mitigation of malware code-distribution sites
Publication Date: 2025.06.24 AMAZON TECH INC
  • US12341805B1 patent drawing
  • US12341805B1 patent drawing
  • US12341805B1 patent drawing

AI summary

The present disclosure generally relates to systems and methods for utilization of network mitigation techniques in the form of null address routing to mitigate coordinated DDOS attacks. One or more computing devices can install malware code into a network device after exploiting a vulnerability of the network device. A monitoring and mitigation service can monitor network devices and detect malware code installed on the network-based service. The monitoring and mitigation service can identify the internet protocol (IP) address or any routing information regarding the computing devices that sent the malware code. Based on the identified information, the monitoring and mitigation service can identify and implement the network mitigation information in the form of null routing addresses that will cause network communications associated with the identified computing device to be terminated or otherwise not delivered to the intended network-based resources.