SDN Controller DDoS Defense via Peer Quality Measurement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions are inadequate in detecting and defending against Distributed Denial of Service (DDoS) attacks, particularly due to the complexity and overwhelming nature of these attacks, which traditional on-premise solutions struggle to address effectively, leading to system delays, outages, and potential shutdowns, especially affecting small to medium-sized businesses.

Innovation Solution

The implementation of a Software Defined Networking (SDN) controller associated with Autonomous Systems (AS) that uses peering points to detect malicious traffic, calculates a peer quality measurement incorporating Bandwidth Amplification Factor (BAF) information, and communicates this data across connected SDN controllers to converge back to a nominal level, facilitating the identification and mitigation of DDoS attacks through a distributed defense approach.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional on-premise solutions are used to block IP addresses, then simple attack patterns can be addressed, but complex DDoS attacks with hundreds to thousands of sources cannot be effectively defended against

Engineering Contradiction:
Improvedefense effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the defense architecture into multiple components: SDN controllers deployed across different Autonomous Systems, peering point monitors, and coordinated response mechanisms. This distributed segmentation enables the system to handle complex DDoS attacks from multiple sources by dividing the monitoring and response functions across many nodes rather than relying on a single on-premise solution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The SDN controller is designed with multi-functionality, serving as both a network management device and a DDoS detection/defense system. It combines peer quality measurement, malicious traffic detection, bandwidth amplification factor analysis, and coordinated mitigation capabilities in a single platform, enabling effective defense against complex attacks while maintaining system manageability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If peer quality measurement is distributed across Autonomous Systems, then the necessary scale to protect the Internet is achieved, but the complexity of coordination between multiple SDN controllers increases

Engineering Contradiction:
Improvenetwork protection scaleVSAvoidcoordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where SDN controllers exchange peer quality measurements and malicious traffic information across Autonomous System boundaries. This feedback loop enables coordinated response to DDoS attacks, with each controller adjusting its filtering rules based on measurements from peer systems, thereby achieving Internet-scale protection through structured information exchange rather than chaotic coordination.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The peering point monitor serves as an intermediary between different Autonomous Systems, collecting traffic measurements at the boundary and relaying information to the appropriate SDN controllers. This intermediary role simplifies the coordination complexity by providing a standardized interface for inter-AS communication and reducing the direct coordination burden between multiple controllers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If bandwidth amplification factor information is incorporated into peer quality measurement, then accurate identification of DDoS attacks is achieved, but the difficulty of detecting and measuring malicious traffic increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidtraffic analysis complexity
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent transforms the detection approach by changing the measured parameter from simple traffic volume to bandwidth amplification factor (BAF). Instead of merely measuring total traffic, the system calculates BAF by comparing reflected traffic volume to request traffic volume, which fundamentally changes the measurement parameter to one that directly indicates DDoS attack presence and intensity, thereby improving detection accuracy while providing a clear metric for automated response.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9838421B2Systems and methods utilizing peer measurements to detect and defend against distributed denial of service attacks
Publication Date: 2017.12.05 CIENA CORP
  • US9838421B2 patent drawing
  • US9838421B2 patent drawing
  • US9838421B2 patent drawing

AI summary

A method, operated by a Software Defined Networking (SDN) controller associated with an Autonomous System (AS) with one or more peering points, each peering point with an associated router communicatively coupled to the SDN controller, the method for detecting and defending against Distributed Denial of Service (DDoS) attacks, and the method includes receiving data from the one or more peering points; detecting malicious traffic at the one or more peering points; determining a peer quality measurement for the one or more peering points; and communicating the peer quality measurement and other data associated with the malicious traffic to one or more other SDN controllers, associated with Autonomous Systems connected through the one or more peering points, to facilitate convergence of the peer quality measurement back to a nominal level.