SDN Controller BGP Routing for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies face challenges in effectively mitigating distributed denial of service (DDoS) attacks, which overwhelm systems with excessive traffic, leading to bandwidth congestion and resource depletion, and existing solutions are complex, costly, and inefficient in blocking and managing such attacks.

Innovation Solution

A traffic attack protection method and system that establishes neighbor relationships between controllers and border routers, allowing for the generation and dissemination of routing information to redirect or block malicious traffic, utilizing Software-Defined Networking (SDN) controllers and Border Gateway Protocol (BGP) for efficient traffic management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional traffic cleaning systems are used to mitigate DDoS attacks, then attack protection is provided, but the system complexity increases and CPU load increases

Engineering Contradiction:
Improveattack protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the traffic cleaning function from the border router and implements it separately using BGP routing information. The controller generates specific routing information that redirects malicious traffic through cleaning systems, while the border router only needs to forward routing updates. This separation reduces the border router's CPU load and system complexity while maintaining effective attack protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a controller as an intermediary between the intrusion detection system and the border router. The controller receives attack detection information, generates appropriate BGP routing information, and distributes it to relevant border routers. This intermediary approach simplifies the overall system architecture by centralizing the decision-making logic and reducing direct complexity at the border router level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional traffic blocking methods are used, then malicious traffic is blocked, but the response time is slow (seconds level)

Engineering Contradiction:
Improvetraffic protection success rateVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing BGP neighbor relationships and having the controller ready to generate routing information immediately upon receiving attack detection. The BGP protocol's inherent fast convergence capabilities allow routing information to be propagated quickly across the network, reducing response time from seconds to milliseconds while maintaining effective traffic protection.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive traffic monitoring and protection is implemented across multiple traffic entrances, then attack detection capability improves, but the device complexity and operational complexity increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal controller that can manage multiple border routers across different traffic entrances through a single BGP peer relationship. The controller generates routing information that can be applied consistently across multiple entry points, and the BGP protocol automatically propagates this information to all relevant routers. This multi-functional approach improves attack detection capability without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Manufacturing precision

If manual configuration of traffic protection rules is used, then precise control is achieved, but the operational complexity and cost increase

Engineering Contradiction:
Improvetraffic control precisionVSAvoidoperational complexity
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the system to automatically generate and distribute traffic protection routing information based on intrusion detection system inputs. The controller autonomously analyzes attack patterns, generates appropriate BGP routing information, and distributes it to relevant border routers without manual intervention. This automation maintains precise traffic control while significantly reducing operational complexity and costs.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10951640B2Traffic attack protection method and system, controller, router, and storage medium
Publication Date: 2021.03.16 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US10951640B2 patent drawing
  • US10951640B2 patent drawing
  • US10951640B2 patent drawing

AI summary

A method for protection against cyberattack includes: establishing neighbor relationships with border routers at a plurality of traffic entrances; and receiving an attack protection request from an intrusion detection system at a first traffic entrance. The first traffic entrance is any one of the plurality of traffic entrances. The attack protection request carries a target network address that has been attacked. The method also includes: generating routing information based on the attack protection request, and sending the routing information to a first border router based on the neighbor relationships. The routing information includes the target network address and routing address information. The first border router performs, based on the routing address information, protection processing on traffic that corresponds to the target network address. The first border router is a border router at the first traffic entrance at which the intrusion detection system that sends the attack protection request is located.