Router Community-Based Traffic Categorization for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers and their customers are vulnerable to Distributed Denial of Service (DDoS) attacks due to the any-to-any architecture of the Internet, which can cause service disruptions and network resource exhaustion, necessitating a method to selectively treat traffic and mitigate these attacks.

Innovation Solution

A system and method that categorizes data packets based on their source addresses into predefined communities, allowing customers to apply selective treatments such as priority, rate-limiting, or dropping of traffic, using a router with a receiving module, routing table, and selection module to manage network traffic and identify potential DDoS sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the any-to-any architecture of the Internet is used, then network connectivity and service accessibility are improved, but vulnerability to DDoS attacks increases

Engineering Contradiction:
Improvenetwork connectivityVSAvoidvulnerability to DDoS attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a service provider network as an intermediary between offensive devices and customer networks. This intermediary implements community-based traffic categorization and selective treatment, filtering malicious traffic before it reaches customer systems while allowing legitimate traffic to pass through. The service provider acts as a mediator that protects customers without eliminating Internet connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments network traffic into different communities based on source addresses, destination addresses, or other criteria. By categorizing traffic into distinct communities, the system can apply different treatments (allow, drop, rate-limit) to different groups of packets. This segmentation enables selective protection against DDoS attacks while maintaining normal traffic flow.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If traffic filtering and selective treatment are implemented, then protection against DDoS attacks is improved, but network traffic management complexity increases

Engineering Contradiction:
Improveprotection against DDoS attacksVSAvoidtraffic management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent creates a universal community-based classification mechanism that can handle multiple types of traffic differentiation needs. The same infrastructure (community categorization and selective treatment) serves both DDoS protection and legitimate traffic prioritization functions. This multi-functionality reduces the need for separate complex filtering systems for different purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows customers to self-configure their traffic treatment preferences by defining which communities should be allowed, dropped, or rate-limited. The service provider implements these preferences automatically without requiring manual intervention for each traffic flow. This self-service approach simplifies management while maintaining flexible protection.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If multiple offensive devices coordinate attacks, then the aggressiveness and impact of the attack are improved, but the ability to identify and mitigate the attack becomes more difficult

Engineering Contradiction:
Improveattack aggressivenessVSAvoidattack detection difficulty
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments incoming traffic into communities based on source addresses, allowing the system to handle multiple offensive devices individually. Even when many devices coordinate an attack, each device's traffic can be categorized into the same or different communities and treated accordingly. This segmentation makes it easier to identify attack patterns and apply mitigation strategies to entire communities rather than tracking each device separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback mechanisms where traffic patterns are continuously monitored and analyzed. When coordinated attacks are detected through abnormal traffic patterns from multiple sources, the system can dynamically adjust community definitions and treatments. This feedback loop enables the system to adapt to evolving attack patterns and improve detection accuracy over time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8225399B1System and method for avoiding and mitigating a DDoS attack
Publication Date: 2012.07.17 AT&T INTELLECTUAL PROPERTY II LP
  • US8225399B1 patent drawing
  • US8225399B1 patent drawing
  • US8225399B1 patent drawing

AI summary

A system and method for receiving a data packet including a destination address and a source address, categorizing the data packet into a community based on the source address, wherein the community is predefined by a user corresponding to the destination address and selecting a treatment for the data packet based on the community. The method may be implemented on a router to avoid and/or mitigate the harmful effects of a Distributed Denial of Service (“DDoS”) attack on a computer system or network.