SmartNIC Offloading SYN Cookie Computation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-DDoS solutions, such as SYN cookies, require significant CPU resources for crypto hash calculations, which can lead to inefficiencies and increased load on target servers during SYN flood attacks.

Innovation Solution

The system employs a SmartNIC with steering capability to compute and verify SYN cookie values without relying on target server CPU resources, thereby offloading the computational burden and reducing the load on the server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SYN cookies are implemented to thwart SYN flood attacks, then the server can protect against DDoS attacks, but the CPU resources are significantly consumed for crypto hash calculations

Engineering Contradiction:
Improveprotection against SYN flood attacksVSAvoidCPU resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a network device (such as a firewall or load balancer) as an intermediary between the attacker and the target server. This intermediary device performs the SYN cookie generation and verification processes, including the computationally intensive crypto hash calculations, thereby protecting the target server from CPU resource exhaustion while maintaining DDoS attack mitigation capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the SYN cookie processing functionality from the target server and relocates it to a separate network device. This separation removes the computational burden from the server, allowing it to focus on handling legitimate traffic while the intermediary device handles the resource-intensive security operations

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If traditional anti-DDoS solutions are used, then the server can detect and respond to attacks, but the response time is delayed due to CPU load

Engineering Contradiction:
Improveattack detection and response capabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the intermediary network device pre-process and filter malicious traffic before it reaches the target server. The intermediary device maintains connection state information and performs initial validation, so that when attacks occur, the server can respond immediately without being burdened by real-time crypto hash calculations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12323458B2Thwarting SYN flood DDoS attacks
Publication Date: 2025.06.03 MELLANOX TECHNOLOGIES LTD(IL)
  • US12323458B2 patent drawing
  • US12323458B2 patent drawing

AI summary

A system for efficiently thwarting syn flood DDoS attacks on a target server including a CPU, the system comprising: network controller hardware having steering capability; and a software application to create and to configure initial steering object/s which define a steering configuration of the network controller and monitor at least one opened connection to the server, including updating the steering configuration responsive to establishment of at least one connection to the server, wherein the network controller hardware's steering capability is used to provide a SYN cookie value used for said thwarting, and to send at least one packet, modified, to the packet's source.