Reputation-Based Virtual IP Scheduling for DDoS Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud-based DDoS attack defense services and cloud firewalls often disrupt legitimate user access and degrade service quality when handling attacks, as they redirect all traffic to alternative network security devices, affecting the experience of legitimate users.

Innovation Solution

A service resource scheduling method that selects virtual IP addresses based on terminal reputation values and IP reputation values, ensuring that legitimate users are not switched to alternative devices during attacks, thereby maintaining service quality by routing only malicious traffic through other devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all traffic is redirected to alternative network security devices when attacks are detected, then attack defense capability is improved, but service quality for legitimate users deteriorates

Engineering Contradiction:
Improveattack defense capabilityVSAvoidservice quality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating traffic handling based on user reputation. Legitimate users (with good reputation) have their traffic routed directly to service servers without redirection, while suspected malicious users (with poor reputation) have their traffic redirected to alternative network security devices. This localized differentiation maintains service quality for legitimate users while preserving attack defense capability for malicious traffic.

Inventive Principle:
Principle #3Local quality

2Reliability

If traffic is switched to alternative devices during attacks, then service availability is improved, but user access experience deteriorates

Engineering Contradiction:
Improveservice availabilityVSAvoiduser access experience
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies local quality by providing different routing paths based on user reputation. High-reputation users experience direct access to service servers with optimal performance, while low-reputation users are routed through alternative network security devices. This ensures service availability is maintained for all users while preserving optimal access experience for legitimate users.

Inventive Principle:
Principle #3Local quality

3Reliability

If DNS resolution is used to redirect traffic to alternative IP addresses, then attack mitigation is improved, but network resource waste increases

Engineering Contradiction:
Improveattack mitigationVSAvoidnetwork resource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by implementing reputation-based selective routing. Only traffic from users with poor reputation scores is redirected through alternative network security devices via DNS resolution, while traffic from high-reputation users flows directly to service servers. This localized approach maintains attack mitigation effectiveness while minimizing network resource waste by avoiding unnecessary redirection of legitimate traffic.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11671402B2Service resource scheduling method and apparatus
Publication Date: 2023.06.06 HUAWEI TECH CO LTD
  • US11671402B2 patent drawing
  • US11671402B2 patent drawing
  • US11671402B2 patent drawing

AI summary

This application discloses a service resource scheduling method and apparatus, and relates to the field of information security technologies, to resolve a problem that a legitimate user in attack traffic cannot normally use a service of a tenant or an access speed becomes slow when a hacker attack occurs. The method includes: receiving, by a domain name system server, a domain name resolution request sent by a first terminal, where the domain name resolution request includes a domain name; selecting, based on a terminal reputation value of the first terminal and an IP reputation value of each virtual IP address in an IP address resource pool, a virtual IP address from at least two virtual IP addresses included in the IP address resource pool; and sending a domain name resolution response to the first terminal, where the domain name resolution response carries the selected virtual IP address.