Scalable Inline DDoS Mitigation via Stacked Processing Components
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing inline DDoS attack mitigation appliances face throughput limitations due to their processing power, which is insufficient to handle high-rate DDoS attacks, necessitating a scalable solution to effectively mitigate such attacks.
Innovation Solution
The solution involves stacking multiple processing components with a switch to distribute traffic and a controlling host that aggregates packet rates and counts to set adaptive thresholds, enabling higher throughput and effective mitigation of DDoS attacks by allowing or dropping packets based on behavioral policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple mitigation components are stacked together to increase throughput capacity, then the ability to handle large-scale DDoS attacks is improved, but the complexity of aggregating packet rates and counts across components increases
Solution Approach 1:
The system divides the DDoS mitigation function into multiple independent processing components, each capable of handling a portion of the traffic. This segmentation allows the system to scale throughput by adding more components while maintaining manageable complexity through standardized interfaces for packet rate aggregation.
Solution Approach 2:
The patent combines multiple mitigation components into a coordinated system where packet rate information from each component is aggregated at a central controller. This merging enables the system to achieve high throughput capacity while maintaining unified control through the aggregation of behavioral data across all components.
2Ease of operation
If a single inline appliance is used for DDoS mitigation, then the system is simple to manage, but the processing power is insufficient to handle high-rate DDoS attacks
Solution Approach 1:
Instead of relying on a single appliance, the system segments the mitigation function across multiple components. Each component handles a portion of the traffic, collectively providing the processing power needed for high-rate attacks while maintaining centralized management through a controlling host that coordinates all components.
Solution Approach 2:
The patent transitions from a single-dimension solution (one appliance) to a multi-dimensional architecture where multiple components work in parallel. This dimensional expansion provides the necessary processing power while the controlling host maintains ease of operation through unified management interfaces.
Data Source
AI summary
Methods and systems for a scalable solution to behavioral Distributed Denial of Service (DDoS) attacks targeting a network are provided. According to one embodiment, a method to determine the scaling treatment is provided for various granular layer parameters of the Open System Interconnection (OSI) model for communication systems. A hardware-based apparatus helps identify packet rates and determine packet rate thresholds through continuous and adaptive learning with multiple DDoS attack mitigation components. The system can be scaled up by stacking multiple DDoS attack mitigation components to provide protection against large scale DDoS attacks by distributing load across these stacked components.


