Router Community-Based Traffic Categorization for DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service providers and their customers are vulnerable to Distributed Denial of Service (DDoS) attacks due to the any-to-any architecture of the Internet, which can cause service disruptions and network resource exhaustion, necessitating a method to selectively treat traffic and mitigate these attacks.
Innovation Solution
A system and method that categorizes data packets based on their source addresses into predefined communities, allowing customers to apply selective treatments such as priority, rate-limiting, or dropping of traffic, using a router with a receiving module, routing table, and selection module to manage network traffic and identify potential DDoS sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the any-to-any architecture of the Internet is used, then network connectivity and service accessibility are improved, but vulnerability to DDoS attacks increases
Solution Approach 1:
The patent introduces a service provider network as an intermediary between offensive devices and customer networks. This intermediary implements community-based traffic categorization and selective treatment, filtering malicious traffic before it reaches customer systems while allowing legitimate traffic to pass through. The service provider acts as a mediator that protects customers without eliminating Internet connectivity.
Solution Approach 2:
The patent segments network traffic into different communities based on source addresses, destination addresses, or other criteria. By categorizing traffic into distinct communities, the system can apply different treatments (allow, drop, rate-limit) to different groups of packets. This segmentation enables selective protection against DDoS attacks while maintaining normal traffic flow.
2Object-affected harmful factors
If traffic filtering and selective treatment are implemented, then protection against DDoS attacks is improved, but network traffic management complexity increases
Solution Approach 1:
The patent creates a universal community-based classification mechanism that can handle multiple types of traffic differentiation needs. The same infrastructure (community categorization and selective treatment) serves both DDoS protection and legitimate traffic prioritization functions. This multi-functionality reduces the need for separate complex filtering systems for different purposes.
Solution Approach 2:
The system allows customers to self-configure their traffic treatment preferences by defining which communities should be allowed, dropped, or rate-limited. The service provider implements these preferences automatically without requiring manual intervention for each traffic flow. This self-service approach simplifies management while maintaining flexible protection.
3Object-affected harmful factors
If multiple offensive devices coordinate attacks, then the aggressiveness and impact of the attack are improved, but the ability to identify and mitigate the attack becomes more difficult
Solution Approach 1:
The patent segments incoming traffic into communities based on source addresses, allowing the system to handle multiple offensive devices individually. Even when many devices coordinate an attack, each device's traffic can be categorized into the same or different communities and treated accordingly. This segmentation makes it easier to identify attack patterns and apply mitigation strategies to entire communities rather than tracking each device separately.
Solution Approach 2:
The system implements feedback mechanisms where traffic patterns are continuously monitored and analyzed. When coordinated attacks are detected through abnormal traffic patterns from multiple sources, the system can dynamically adjust community definitions and treatments. This feedback loop enables the system to adapt to evolving attack patterns and improve detection accuracy over time.
Data Source
AI summary
A system and method for receiving a data packet including a destination address and a source address, categorizing the data packet into a community based on the source address, wherein the community is predefined by a user corresponding to the destination address and selecting a treatment for the data packet based on the community. The method may be implemented on a router to avoid and/or mitigate the harmful effects of a Distributed Denial of Service (“DDoS”) attack on a computer system or network.


