Selective Black-Holing for DDoS Mitigation in IP Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for defending against Distributed Denial of Service (DDoS) attacks often result in legitimate users being denied access due to the flooding of attack traffic, as all traffic to the affected system is black-holed, including valid traffic, which is inefficient and disrupts service.
Innovation Solution
Implementing a selective black-holing technique using Border Gateway Protocol (BGP) and community-based route filtering to divert only attack traffic through specific routers, allowing valid traffic to continue reaching the system while identifying the origin of the attack.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If all traffic to the affected system is black-holed, then attack traffic is blocked, but legitimate users are denied access
Solution Approach 1:
The patent segments the black-holing approach by dividing routers into two sets: first set routers that black-hole attack traffic and second set routers that allow legitimate traffic. This segmentation enables selective blocking based on router identity rather than uniform blocking of all traffic, resolving the contradiction between blocking attacks and maintaining legitimate service.
Solution Approach 2:
Different routers within the ISP network are assigned different behaviors (local quality differentiation). First set routers implement black-holing for attack traffic, while second set routers maintain normal routing. This local differentiation allows the system to block harmful traffic at specific locations while preserving legitimate traffic flow through other routers.
2Reliability
If selective black-holing is implemented, then legitimate traffic flow is maintained, but system complexity increases
Solution Approach 1:
The patent introduces a controller as an intermediary component that manages the complexity of selective black-holing. The controller receives attack traffic analysis, determines which routers should black-hole traffic, and configures the routing accordingly. This intermediary abstracts the complexity from individual routers and centralizes the decision-making logic.
Solution Approach 2:
The system dynamically adjusts routing configurations based on real-time attack analysis. The controller can modify which routers are designated as first set or second set based on the characteristics and origin of detected attacks, allowing flexible adaptation to different attack scenarios without manual reconfiguration of each router.
3Loss of time
If real-time adjustment of black-holing strategies is enabled, then response time to attacks is reduced, but control complexity increases
Solution Approach 1:
The system implements feedback mechanisms where the controller continuously monitors attack traffic characteristics and adjusts routing decisions accordingly. Analysis of attack patterns provides feedback that triggers dynamic reconfiguration of router sets, enabling rapid response to evolving attacks while automating the control logic to reduce manual intervention complexity.
Data Source
AI summary
In an IP network during a DDoS attack on a website or other internet entity having an IP address, selective black-holing of attack traffic is performed such that some of the traffic destined for the IP address under attack continues to go to the IP address under attack while other traffic, destined for the same IP address is, rerouted via BGP sessions to a black-hole router. Such a selective black-holing scheme can be used to allow some traffic to continue in route to the IP address under attack, while other traffic is diverted.


