Information Processor Interrupt Control for DoS Over-Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems face challenges in distinguishing between DoS attack-suspect packets and significant packets, leading to system overload and potential downtime due to the burden of processing during high traffic states, especially in low-performance information processors.
Innovation Solution
An information processor with a communication block, data processing block, and interrupt controlling block that determines traffic states, shutting off interrupt requests during over-traffic conditions to prevent system overload and allow continued control over connected equipment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If receive processing is performed for all packets including DoS attack-suspect packets, then communication reliability is maintained, but information processor performance degrades and system downtime occurs
Solution Approach 1:
The patent applies partial action by selectively processing only significant packets while discarding DoS attack-suspect packets. The determination block evaluates each packet against criteria (packet size, source address, destination address) and processes only those meeting the criteria, avoiding full processing of all packets including malicious ones.
Solution Approach 2:
The patent segments the packet processing function into two distinct paths: one for significant packets that undergo full processing, and another for DoS attack-suspect packets that are discarded. This segmentation is implemented through the determination block that routes packets to different processing paths based on evaluation results.
2Productivity
If receive processing is restricted to only significant packets by discriminating DoS attack-suspect packets, then information processor performance is maintained, but processing burden increases due to discrimination requirements
Solution Approach 1:
The patent applies preliminary action by evaluating packet characteristics (size, source address, destination address) before full processing occurs. The determination block performs this preliminary evaluation to identify significant packets ahead of time, preventing unnecessary processing of DoS attack-suspect packets and reducing overall processing burden.
Solution Approach 2:
The patent changes evaluation parameters by using multiple criteria (packet size threshold, source address matching, destination address matching) to identify significant packets. This multi-parameter approach improves discrimination accuracy while maintaining manageable processing complexity through clear, rule-based evaluation.
3Quantity of substance
If bandwidth restriction is implemented to limit received data amount, then network congestion is reduced, but receive processing continues causing system overload
Solution Approach 1:
The patent extracts and removes DoS attack-suspect packets from the processing stream before they can consume communication processing resources. By taking out malicious packets through the determination block's discarding function, the system prevents system overload while maintaining necessary receive processing for legitimate packets.
Data Source
AI summary
An information processor disclosed herein prevents adverse impacts on higher priority processing due to extremely frequent receive processing when inbound traffic from a network is over-traffic state (under a DoS attack). The information processor attached to a network collects information about traffic state and, if it is determined that over-traffic state is present, deactivates the communication processing function without passing an interrupt request due to communication to the data processing block. In this state, the information processor continues to collect information about traffic state and, when it is determined that over-traffic state has terminated, starts to transfer an interrupt request to the data processing block and makes the communication processing function recover.


