Selective Black-Holing for DDoS Mitigation in IP Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for defending against Distributed Denial of Service (DDoS) attacks often result in legitimate users being denied access due to the flooding of attack traffic, as all traffic to the affected system is black-holed, including valid traffic, which is inefficient and disrupts service.

Innovation Solution

Implementing a selective black-holing technique using Border Gateway Protocol (BGP) and community-based route filtering to divert only attack traffic through specific routers, allowing valid traffic to continue reaching the system while identifying the origin of the attack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If all traffic to the affected system is black-holed, then attack traffic is blocked, but legitimate users are denied access

Engineering Contradiction:
Improveattack traffic blockingVSAvoidlegitimate user access
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent segments the black-holing approach by dividing routers into two sets: first set routers that black-hole attack traffic and second set routers that allow legitimate traffic. This segmentation enables selective blocking based on router identity rather than uniform blocking of all traffic, resolving the contradiction between blocking attacks and maintaining legitimate service.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different routers within the ISP network are assigned different behaviors (local quality differentiation). First set routers implement black-holing for attack traffic, while second set routers maintain normal routing. This local differentiation allows the system to block harmful traffic at specific locations while preserving legitimate traffic flow through other routers.

Inventive Principle:
Principle #3Local quality

2Reliability

If selective black-holing is implemented, then legitimate traffic flow is maintained, but system complexity increases

Engineering Contradiction:
Improvelegitimate traffic flowVSAvoidrouting configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a controller as an intermediary component that manages the complexity of selective black-holing. The controller receives attack traffic analysis, determines which routers should black-hole traffic, and configures the routing accordingly. This intermediary abstracts the complexity from individual routers and centralizes the decision-making logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts routing configurations based on real-time attack analysis. The controller can modify which routers are designated as first set or second set based on the characteristics and origin of detected attacks, allowing flexible adaptation to different attack scenarios without manual reconfiguration of each router.

Inventive Principle:
Principle #15Dynamics

3Loss of time

If real-time adjustment of black-holing strategies is enabled, then response time to attacks is reduced, but control complexity increases

Engineering Contradiction:
Improveresponse time to attacksVSAvoidcontrol mechanism complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where the controller continuously monitors attack traffic characteristics and adjusts routing decisions accordingly. Analysis of attack patterns provides feedback that triggers dynamic reconfiguration of router sets, enabling rapid response to evolving attacks while automating the control logic to reduce manual intervention complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7444417B2Distributed denial-of-service attack mitigation by selective black-holing in IP networks
Publication Date: 2008.10.28 AT&T INTELLECTUAL PROPERTY II LP
  • US7444417B2 patent drawing
  • US7444417B2 patent drawing
  • US7444417B2 patent drawing

AI summary

In an IP network during a DDoS attack on a website or other internet entity having an IP address, selective black-holing of attack traffic is performed such that some of the traffic destined for the IP address under attack continues to go to the IP address under attack while other traffic, destined for the same IP address is, rerouted via BGP sessions to a black-hole router. Such a selective black-holing scheme can be used to allow some traffic to continue in route to the IP address under attack, while other traffic is diverted.