Reputation-Based Virtual IP Scheduling for DDoS Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud-based DDoS attack defense services and cloud firewalls often disrupt legitimate user access and degrade service quality when handling attacks, as they redirect all traffic to alternative network security devices, affecting the experience of legitimate users.
Innovation Solution
A service resource scheduling method that selects virtual IP addresses based on terminal reputation values and IP reputation values, ensuring that legitimate users are not switched to alternative devices during attacks, thereby maintaining service quality by routing only malicious traffic through other devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all traffic is redirected to alternative network security devices when attacks are detected, then attack defense capability is improved, but service quality for legitimate users deteriorates
Solution Approach 1:
The patent applies local quality by differentiating traffic handling based on user reputation. Legitimate users (with good reputation) have their traffic routed directly to service servers without redirection, while suspected malicious users (with poor reputation) have their traffic redirected to alternative network security devices. This localized differentiation maintains service quality for legitimate users while preserving attack defense capability for malicious traffic.
2Reliability
If traffic is switched to alternative devices during attacks, then service availability is improved, but user access experience deteriorates
Solution Approach 1:
The system applies local quality by providing different routing paths based on user reputation. High-reputation users experience direct access to service servers with optimal performance, while low-reputation users are routed through alternative network security devices. This ensures service availability is maintained for all users while preserving optimal access experience for legitimate users.
3Reliability
If DNS resolution is used to redirect traffic to alternative IP addresses, then attack mitigation is improved, but network resource waste increases
Solution Approach 1:
The patent applies local quality by implementing reputation-based selective routing. Only traffic from users with poor reputation scores is redirected through alternative network security devices via DNS resolution, while traffic from high-reputation users flows directly to service servers. This localized approach maintains attack mitigation effectiveness while minimizing network resource waste by avoiding unnecessary redirection of legitimate traffic.
Data Source
AI summary
This application discloses a service resource scheduling method and apparatus, and relates to the field of information security technologies, to resolve a problem that a legitimate user in attack traffic cannot normally use a service of a tenant or an access speed becomes slow when a hacker attack occurs. The method includes: receiving, by a domain name system server, a domain name resolution request sent by a first terminal, where the domain name resolution request includes a domain name; selecting, based on a terminal reputation value of the first terminal and an IP reputation value of each virtual IP address in an IP address resource pool, a virtual IP address from at least two virtual IP addresses included in the IP address resource pool; and sending a domain name resolution response to the first terminal, where the domain name resolution response carries the selected virtual IP address.


