Origin-Controlled Attack Protection in Distributed Content Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current distributed platforms for content delivery do not effectively integrate origin servers in attack detection and protection, leading to inadequate defense against attacks, especially for dynamic or uncacheable content, as they rely solely on distributed platform-level thresholds and do not account for origin server loads, resulting in a security burden shift back to the origin.
Innovation Solution
Implementing origin-controlled attack protections that allow origins to detect attacks independently and invoke distributed platform protections, enabling the use of proprietary detection methods and criteria without duplicating existing security measures, thereby extending security controls from the distributed platform to the origin servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the distributed platform implements attack protections based on platform-level thresholds, then the platform can provide centralized security control, but the origin servers become overwhelmed with excessive loads during attacks
Solution Approach 1:
The origin server pre-configures attack protection thresholds and criteria before attacks occur. When an attack is detected, the origin server immediately invokes pre-prepared protection rules, avoiding the delay of real-time threshold negotiation and enabling faster response to protect against overwhelming loads
Solution Approach 2:
The origin server continuously monitors its own load conditions and attack patterns, using this feedback to dynamically adjust protection thresholds and invoke appropriate protection mechanisms. This closed-loop feedback enables the origin to adapt to changing attack conditions while maintaining manageable load levels
2Adaptability or versatility
If the origin implements its own attack protections independently, then the origin can use proprietary detection methods, but this duplicates functionality already available at the distributed platform level
Solution Approach 1:
The distributed platform provides universal attack protection capabilities that can be invoked by any origin server. Instead of each origin implementing separate protection systems, the platform offers a unified protection service that works across all origins, reducing overall system complexity while maintaining adaptability through configurable protection rules
Solution Approach 2:
The distributed platform acts as an intermediary between the origin server and the attack traffic. The origin server communicates its protection needs to the platform, which then implements the protection measures, eliminating the need for the origin to directly handle complex protection implementation while still allowing proprietary detection criteria
3Productivity
If the distributed platform forwards all requests to origin servers, then dynamic or uncacheable content can be delivered, but the platform cannot detect attacks that overwhelm the origin
Solution Approach 1:
The origin server pre-configures attack detection criteria and thresholds before attacks occur. When forwarding requests for dynamic content, the origin's pre-established protection rules are immediately applied, enabling the platform to detect and respond to attacks before they overwhelm the origin, while still allowing legitimate dynamic content delivery
Data Source
AI summary
Some embodiments provide an origin whose content is distributed by a third party content distributor control over invoking attack protections from the third party content distributor. The origin independently monitors requests and messaging the content distributor passes to the origin as a result of the content distributor needing to retrieve content from the origin before redistribution or because requested content is dynamic or uncacheable. Upon detection of an attack, the origin signals the content distributor to perform one of several attack protections on its behalf. In this manner, the origin leverages the content distributor distributed platform architecture to shield itself from attack. Based on the origin signaling, the content distributor rate limits, blocks, redirects, or performs other attack protections to reduce the load on the origin server.


