Precise Black Hole Traffic Filtering for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for mitigating distributed denial-of-service (DDoS) attacks often result in legitimate traffic being blocked along with malicious traffic, as they require direct relationships with network providers, leading to service disruptions and revenue loss for content providers.

Innovation Solution

Implementing precise black holes across multiple networks along the attack path, using a 'black hole as a service' (BAAS) to selectively discard only attack traffic, minimizing impact on legitimate users by identifying and engaging subscriber networks that can manage traffic mitigation without direct physical connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If conventional black hole methods are used to mitigate DDoS attacks, then attack traffic is blocked, but legitimate traffic is also lost

Engineering Contradiction:
Improveattack traffic blockingVSAvoidlegitimate traffic delivery
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements precise black holes that apply different traffic handling rules to different sources. Instead of a global black hole that blocks all traffic to a destination, the system creates source-specific black holes that only drop traffic from identified malicious sources while allowing legitimate traffic from other sources to pass through normally. This resolves the contradiction by making the black hole effect local to specific attack sources rather than affecting all traffic universally.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the black hole mechanism into multiple source-specific instances. Rather than implementing a single comprehensive black hole that blocks all traffic, the system divides the mitigation into multiple granular black holes, each targeting a specific malicious IP address or network range. This segmentation allows legitimate traffic from non-attacking sources to continue flowing while individually blocking only the harmful traffic streams.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If direct connection with network providers is required for traffic filtering, then attack mitigation is effective, but service availability is reduced

Engineering Contradiction:
Improveattack traffic filteringVSAvoidservice availability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent introduces a traffic management service as an intermediary between content providers and network providers. This service acts as a mediator that receives traffic filtering requests from content providers, identifies appropriate malicious sources, and coordinates with multiple network providers simultaneously to implement precise black holes. The intermediary enables content providers to mitigate attacks without requiring direct connections to network providers, maintaining service availability while achieving effective attack filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The traffic management service provides universal functionality that works across multiple network providers and content providers. The system is designed to engage with any network provider that carries attack traffic, regardless of direct connection requirements. This multi-functional approach allows the same traffic management service to effectively mitigate attacks across diverse network infrastructures without compromising service availability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If all traffic from an address is dropped, then attack traffic is blocked, but revenue is lost due to blocked legitimate traffic

Engineering Contradiction:
Improvemalicious traffic blockingVSAvoidrevenue loss
Core Design Contradiction:
Object-affected harmful factorsVSLoss of energy

Solution Approach 1:

The patent applies local quality by implementing black holes at the source address level rather than at the destination level. Instead of dropping all traffic to a targeted destination (which would block legitimate traffic), the system identifies and drops traffic only from specific malicious source addresses. This granular approach ensures that legitimate traffic from other sources to the same destination continues to flow, preventing revenue loss while effectively blocking attacks.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent extracts only the harmful portion of traffic by identifying and isolating malicious source addresses from the broader traffic flow. Rather than removing all traffic associated with an attack target, the system selectively extracts and drops only the traffic streams originating from confirmed malicious sources. This extraction approach maintains revenue-generating legitimate traffic while removing only the harmful attack components.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11968226B1Targeted traffic filtering
Publication Date: 2024.04.23 AMAZON TECH INC
  • US11968226B1 patent drawing
  • US11968226B1 patent drawing
  • US11968226B1 patent drawing

AI summary

Remote Triggered Black Holes (RTBHs) can be precisely placed on networks that are not directly physically connected to a target of an attack. A network source of a potential attack can be determined. A path between the network source and the target can be identified, and a determination can be made as to which networks along that path subscribe to an attack mitigation service. From multiple identified subscriber networks, a subscriber network can be identified that is determined to be appropriate for placement of a black hole to mitigate the attack. Once selected, the identified network can receive attack information and acknowledge placement of the black hole. The subscriber network can then begin discarding traffic for the attack target. A subscriber-owned list of network prefixes can be reviewed before allowing RTBH injection for a corresponding address space.