SDN Controller DDoS Defense via Peer Quality Measurement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions are inadequate in detecting and defending against Distributed Denial of Service (DDoS) attacks, particularly due to the complexity and overwhelming nature of these attacks, which traditional on-premise solutions struggle to address effectively, leading to system delays, outages, and potential shutdowns, especially affecting small to medium-sized businesses.
Innovation Solution
The implementation of a Software Defined Networking (SDN) controller associated with Autonomous Systems (AS) that uses peering points to detect malicious traffic, calculates a peer quality measurement incorporating Bandwidth Amplification Factor (BAF) information, and communicates this data across connected SDN controllers to converge back to a nominal level, facilitating the identification and mitigation of DDoS attacks through a distributed defense approach.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional on-premise solutions are used to block IP addresses, then simple attack patterns can be addressed, but complex DDoS attacks with hundreds to thousands of sources cannot be effectively defended against
Solution Approach 1:
The patent segments the defense architecture into multiple components: SDN controllers deployed across different Autonomous Systems, peering point monitors, and coordinated response mechanisms. This distributed segmentation enables the system to handle complex DDoS attacks from multiple sources by dividing the monitoring and response functions across many nodes rather than relying on a single on-premise solution.
Solution Approach 2:
The SDN controller is designed with multi-functionality, serving as both a network management device and a DDoS detection/defense system. It combines peer quality measurement, malicious traffic detection, bandwidth amplification factor analysis, and coordinated mitigation capabilities in a single platform, enabling effective defense against complex attacks while maintaining system manageability.
2Reliability
If peer quality measurement is distributed across Autonomous Systems, then the necessary scale to protect the Internet is achieved, but the complexity of coordination between multiple SDN controllers increases
Solution Approach 1:
The patent implements feedback mechanisms where SDN controllers exchange peer quality measurements and malicious traffic information across Autonomous System boundaries. This feedback loop enables coordinated response to DDoS attacks, with each controller adjusting its filtering rules based on measurements from peer systems, thereby achieving Internet-scale protection through structured information exchange rather than chaotic coordination.
Solution Approach 2:
The peering point monitor serves as an intermediary between different Autonomous Systems, collecting traffic measurements at the boundary and relaying information to the appropriate SDN controllers. This intermediary role simplifies the coordination complexity by providing a standardized interface for inter-AS communication and reducing the direct coordination burden between multiple controllers.
3Measurement precision
If bandwidth amplification factor information is incorporated into peer quality measurement, then accurate identification of DDoS attacks is achieved, but the difficulty of detecting and measuring malicious traffic increases
Solution Approach 1:
The patent transforms the detection approach by changing the measured parameter from simple traffic volume to bandwidth amplification factor (BAF). Instead of merely measuring total traffic, the system calculates BAF by comparing reflected traffic volume to request traffic volume, which fundamentally changes the measurement parameter to one that directly indicates DDoS attack presence and intensity, thereby improving detection accuracy while providing a clear metric for automated response.
Data Source
AI summary
A method, operated by a Software Defined Networking (SDN) controller associated with an Autonomous System (AS) with one or more peering points, each peering point with an associated router communicatively coupled to the SDN controller, the method for detecting and defending against Distributed Denial of Service (DDoS) attacks, and the method includes receiving data from the one or more peering points; detecting malicious traffic at the one or more peering points; determining a peer quality measurement for the one or more peering points; and communicating the peer quality measurement and other data associated with the malicious traffic to one or more other SDN controllers, associated with Autonomous Systems connected through the one or more peering points, to facilitate convergence of the peer quality measurement back to a nominal level.


