Real-time Filtering Policy Server for DoS Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and mitigating Denial of Service (DoS) IP attacks in IP networks are inefficient, often resulting in substantial network and application outages due to the manual generation of filtering policies, which can be slow to implement.

Innovation Solution

A Real-time Filtering Policy (RFP) server dynamically collects data on DoS IP attacks, generates anti-attack packets, and shares filter criteria with nodes in the network to automatically block malicious traffic, improving detection and response times across the multicast network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual filtering policies are used to block DoS attacks, then network security is improved, but response time and operational efficiency deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the network infrastructure automatically detects DoS attacks, generates filtering policies, and distributes them to relevant nodes without requiring manual administrator intervention. The automated policy generation system continuously monitors network traffic, identifies attack patterns, and responds in real-time, eliminating the time loss associated with manual detection and policy creation while maintaining security effectiveness

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring automated detection mechanisms and policy generation templates before attacks occur. When a DoS attack is detected, the system has pre-established workflows and algorithms ready to immediately generate and distribute filtering policies, significantly reducing response time compared to manual processes while maintaining security reliability

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual filtering policies are created and pushed, then attack mitigation is achieved, but productivity and operational efficiency deteriorate

Engineering Contradiction:
Improveattack mitigationVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The automated policy generation system performs self-service by autonomously detecting DoS attacks, analyzing traffic patterns, generating appropriate filtering policies, and distributing them to network nodes. This eliminates the need for manual administrator intervention in policy creation and deployment, dramatically improving operational efficiency while maintaining effective attack mitigation through continuous automated monitoring and response

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements dynamics by continuously adapting filtering policies based on real-time network conditions and attack patterns. The automated generation system dynamically adjusts policy parameters, distribution targets, and filtering criteria according to current threats, enabling rapid response to evolving DoS attacks while maintaining high operational efficiency through automated decision-making processes

Inventive Principle:
Principle #15Dynamics

3Productivity

If real-time automated filtering is implemented, then response speed and productivity are improved, but device complexity increases

Engineering Contradiction:
Improveresponse speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The automated policy generation system is segmented into distinct functional modules: traffic monitoring components, attack detection algorithms, policy generation engines, and distribution mechanisms. Each module performs a specific function independently, allowing the system to achieve high response speed through specialized processing while managing complexity through modular architecture that enables independent development, testing, and maintenance of each component

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universality by designing multi-functional components that can handle various types of DoS attacks and network conditions using the same core infrastructure. The automated policy generation system provides universal response capabilities across different attack scenarios, reducing overall system complexity by avoiding the need for separate specialized systems for each attack type while maintaining fast response speeds through unified processing

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If automated policy generation is deployed, then operational efficiency and response time are improved, but ease of operation deteriorates due to automation management

Engineering Contradiction:
Improveoperational efficiencyVSAvoidautomation management
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The automated policy generation system performs self-service by autonomously executing the complete workflow from attack detection to policy distribution without requiring manual administrator intervention. This maintains high operational efficiency through continuous automated operation while simplifying ease of operation by eliminating complex manual automation management tasks, as the system manages itself through pre-configured automated workflows and decision-making algorithms

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10505976B2Real-time policy filtering of denial of service (DoS) internet protocol (IP) attacks and malicious traffic
Publication Date: 2019.12.10 T MOBILE US INC
  • US10505976B2 patent drawing
  • US10505976B2 patent drawing
  • US10505976B2 patent drawing

AI summary

This disclosure describes techniques that facilitate dynamic filtering and blocking of Denial of Service (DoS) Internet Protocol (IP) attacks via a Real-time Filtering policy (RFP) Server. The RFP server may transmit an anti-attack packet towards a source IP address that has been identified as initiating a DoS IP attack. The anti-attack packet may include an Explicit Congestion Notification (ECN) value that echoes congestion to the source IP address, thereby alerting the source IP address that the RFP server is aware of the intended DoS IP attack. Further, the RFP server may generate, modify, and share filter criteria with one or more MGM node(s) of a multicast network, thereby improving DoS IP attack detection capabilities across the multicast network. Filter criteria may include, but is not limited to, source IP address, destination IP address, file size of IP packets, and a frequency by which IP packets are delivered.