SDN Controller BGP Routing for DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security technologies face challenges in effectively mitigating distributed denial of service (DDoS) attacks, which overwhelm systems with excessive traffic, leading to bandwidth congestion and resource depletion, and existing solutions are complex, costly, and inefficient in blocking and managing such attacks.
Innovation Solution
A traffic attack protection method and system that establishes neighbor relationships between controllers and border routers, allowing for the generation and dissemination of routing information to redirect or block malicious traffic, utilizing Software-Defined Networking (SDN) controllers and Border Gateway Protocol (BGP) for efficient traffic management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional traffic cleaning systems are used to mitigate DDoS attacks, then attack protection is provided, but the system complexity increases and CPU load increases
Solution Approach 1:
The patent extracts the traffic cleaning function from the border router and implements it separately using BGP routing information. The controller generates specific routing information that redirects malicious traffic through cleaning systems, while the border router only needs to forward routing updates. This separation reduces the border router's CPU load and system complexity while maintaining effective attack protection.
Solution Approach 2:
The patent introduces a controller as an intermediary between the intrusion detection system and the border router. The controller receives attack detection information, generates appropriate BGP routing information, and distributes it to relevant border routers. This intermediary approach simplifies the overall system architecture by centralizing the decision-making logic and reducing direct complexity at the border router level.
2Reliability
If traditional traffic blocking methods are used, then malicious traffic is blocked, but the response time is slow (seconds level)
Solution Approach 1:
The patent implements preliminary action by pre-establishing BGP neighbor relationships and having the controller ready to generate routing information immediately upon receiving attack detection. The BGP protocol's inherent fast convergence capabilities allow routing information to be propagated quickly across the network, reducing response time from seconds to milliseconds while maintaining effective traffic protection.
3Measurement precision
If comprehensive traffic monitoring and protection is implemented across multiple traffic entrances, then attack detection capability improves, but the device complexity and operational complexity increase
Solution Approach 1:
The patent implements a universal controller that can manage multiple border routers across different traffic entrances through a single BGP peer relationship. The controller generates routing information that can be applied consistently across multiple entry points, and the BGP protocol automatically propagates this information to all relevant routers. This multi-functional approach improves attack detection capability without proportionally increasing device complexity.
4Manufacturing precision
If manual configuration of traffic protection rules is used, then precise control is achieved, but the operational complexity and cost increase
Solution Approach 1:
The patent implements self-service by enabling the system to automatically generate and distribute traffic protection routing information based on intrusion detection system inputs. The controller autonomously analyzes attack patterns, generates appropriate BGP routing information, and distributes it to relevant border routers without manual intervention. This automation maintains precise traffic control while significantly reducing operational complexity and costs.
Data Source
AI summary
A method for protection against cyberattack includes: establishing neighbor relationships with border routers at a plurality of traffic entrances; and receiving an attack protection request from an intrusion detection system at a first traffic entrance. The first traffic entrance is any one of the plurality of traffic entrances. The attack protection request carries a target network address that has been attacked. The method also includes: generating routing information based on the attack protection request, and sending the routing information to a first border router based on the neighbor relationships. The routing information includes the target network address and routing address information. The first border router performs, based on the routing address information, protection processing on traffic that corresponds to the target network address. The first border router is a border router at the first traffic entrance at which the intrusion detection system that sends the attack protection request is located.


