Real-time Filtering Policy Server for DoS Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting and mitigating Denial of Service (DoS) IP attacks in IP networks are inefficient, often resulting in substantial network and application outages due to the manual generation of filtering policies, which can be slow to implement.
Innovation Solution
A Real-time Filtering Policy (RFP) server dynamically collects data on DoS IP attacks, generates anti-attack packets, and shares filter criteria with nodes in the network to automatically block malicious traffic, improving detection and response times across the multicast network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual filtering policies are used to block DoS attacks, then network security is improved, but response time and operational efficiency deteriorate
Solution Approach 1:
The system enables self-service automation where the network infrastructure automatically detects DoS attacks, generates filtering policies, and distributes them to relevant nodes without requiring manual administrator intervention. The automated policy generation system continuously monitors network traffic, identifies attack patterns, and responds in real-time, eliminating the time loss associated with manual detection and policy creation while maintaining security effectiveness
Solution Approach 2:
The system performs preliminary actions by pre-configuring automated detection mechanisms and policy generation templates before attacks occur. When a DoS attack is detected, the system has pre-established workflows and algorithms ready to immediately generate and distribute filtering policies, significantly reducing response time compared to manual processes while maintaining security reliability
2Reliability
If manual filtering policies are created and pushed, then attack mitigation is achieved, but productivity and operational efficiency deteriorate
Solution Approach 1:
The automated policy generation system performs self-service by autonomously detecting DoS attacks, analyzing traffic patterns, generating appropriate filtering policies, and distributing them to network nodes. This eliminates the need for manual administrator intervention in policy creation and deployment, dramatically improving operational efficiency while maintaining effective attack mitigation through continuous automated monitoring and response
Solution Approach 2:
The system implements dynamics by continuously adapting filtering policies based on real-time network conditions and attack patterns. The automated generation system dynamically adjusts policy parameters, distribution targets, and filtering criteria according to current threats, enabling rapid response to evolving DoS attacks while maintaining high operational efficiency through automated decision-making processes
3Productivity
If real-time automated filtering is implemented, then response speed and productivity are improved, but device complexity increases
Solution Approach 1:
The automated policy generation system is segmented into distinct functional modules: traffic monitoring components, attack detection algorithms, policy generation engines, and distribution mechanisms. Each module performs a specific function independently, allowing the system to achieve high response speed through specialized processing while managing complexity through modular architecture that enables independent development, testing, and maintenance of each component
Solution Approach 2:
The system implements universality by designing multi-functional components that can handle various types of DoS attacks and network conditions using the same core infrastructure. The automated policy generation system provides universal response capabilities across different attack scenarios, reducing overall system complexity by avoiding the need for separate specialized systems for each attack type while maintaining fast response speeds through unified processing
4Productivity
If automated policy generation is deployed, then operational efficiency and response time are improved, but ease of operation deteriorates due to automation management
Solution Approach 1:
The automated policy generation system performs self-service by autonomously executing the complete workflow from attack detection to policy distribution without requiring manual administrator intervention. This maintains high operational efficiency through continuous automated operation while simplifying ease of operation by eliminating complex manual automation management tasks, as the system manages itself through pre-configured automated workflows and decision-making algorithms
Data Source
AI summary
This disclosure describes techniques that facilitate dynamic filtering and blocking of Denial of Service (DoS) Internet Protocol (IP) attacks via a Real-time Filtering policy (RFP) Server. The RFP server may transmit an anti-attack packet towards a source IP address that has been identified as initiating a DoS IP attack. The anti-attack packet may include an Explicit Congestion Notification (ECN) value that echoes congestion to the source IP address, thereby alerting the source IP address that the RFP server is aware of the intended DoS IP attack. Further, the RFP server may generate, modify, and share filter criteria with one or more MGM node(s) of a multicast network, thereby improving DoS IP attack detection capabilities across the multicast network. Filter criteria may include, but is not limited to, source IP address, destination IP address, file size of IP packets, and a frequency by which IP packets are delivered.


