Selective Packet Load Shedding for Network Device Management Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current load shedding mechanisms, such as Random Early Discard, can adversely affect legitimate network traffic during Denial-of-Service (DoS) attacks, leading to system resource overload and difficulty in accessing network devices for management and monitoring.
Innovation Solution
Implementing a selective packet load shedding mechanism that intelligently discards packets based on host behavior and system resource availability, allowing network devices to maintain access and processing capabilities during high traffic events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Random Early Discard load shedding mechanism is used, then system resource overload is reduced, but legitimate network traffic is adversely affected
Solution Approach 1:
The patent applies local quality by differentiating packet discard behavior based on source host characteristics. Instead of uniform random early discard, the system analyzes packet arrival patterns and host behavior to apply selective discard policies - discarding packets from hosts exhibiting DoS characteristics while preserving legitimate traffic from hosts with normal patterns.
Solution Approach 2:
The system implements feedback mechanisms by monitoring packet arrival patterns, host behavior, and system resource consumption over time. This feedback data is used to dynamically adjust discard policies and identify legitimate versus malicious traffic, allowing the system to learn from observed patterns and adapt its load shedding strategy accordingly.
2Reliability
If packets are discarded during DoS attacks, then system resource overload is prevented, but access to network devices for management and monitoring is difficult
Solution Approach 1:
The patent applies local quality by differentiating packet discard behavior based on source host characteristics. Instead of uniform random early discard, the system analyzes packet arrival patterns and host behavior to apply selective discard policies - discarding packets from hosts exhibiting DoS characteristics while preserving legitimate traffic from hosts with normal patterns.
Solution Approach 2:
The system performs preliminary analysis of packet patterns and host behavior before implementing packet discard. By monitoring and characterizing traffic patterns in advance, the system can identify DoS attack signatures and prepare appropriate response actions, ensuring that management traffic is protected while malicious traffic is discarded.
3Use of energy by moving object
If load shedding is applied during high traffic events, then system resource consumption is reduced, but processing capabilities are compromised
Solution Approach 1:
The patent applies local quality by differentiating packet discard behavior based on source host characteristics. Instead of uniform random early discard, the system analyzes packet arrival patterns and host behavior to apply selective discard policies - discarding packets from hosts exhibiting DoS characteristics while preserving legitimate traffic from hosts with normal patterns.
Data Source
AI summary
Methods, apparatuses and systems directed to enhanced packet load shedding mechanisms implemented in various network devices. In one implementation, the present invention enables a selective load shedding mechanism that intelligently discards packets to allow or facilitate management access during DoS attacks or other high traffic events. In one implementation, the present invention is directed to a selective load shedding mechanism that, while shedding load necessary to allow a network device to operate appropriately, does not attempt to control traffic flows, which allows for other processes to process, classify, diagnose and/or monitor network traffic during high traffic volume periods. In another implementation, the present invention provides a packet load shedding mechanism that reduces the consumption of system resources during periods of high network traffic volume.


