SmartNIC Offloading SYN Cookie Computation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anti-DDoS solutions, such as SYN cookies, require significant CPU resources for crypto hash calculations, which can lead to inefficiencies and increased load on target servers during SYN flood attacks.
Innovation Solution
The system employs a SmartNIC with steering capability to compute and verify SYN cookie values without relying on target server CPU resources, thereby offloading the computational burden and reducing the load on the server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SYN cookies are implemented to thwart SYN flood attacks, then the server can protect against DDoS attacks, but the CPU resources are significantly consumed for crypto hash calculations
Solution Approach 1:
The patent introduces a network device (such as a firewall or load balancer) as an intermediary between the attacker and the target server. This intermediary device performs the SYN cookie generation and verification processes, including the computationally intensive crypto hash calculations, thereby protecting the target server from CPU resource exhaustion while maintaining DDoS attack mitigation capabilities
Solution Approach 2:
The patent extracts the SYN cookie processing functionality from the target server and relocates it to a separate network device. This separation removes the computational burden from the server, allowing it to focus on handling legitimate traffic while the intermediary device handles the resource-intensive security operations
2Reliability
If traditional anti-DDoS solutions are used, then the server can detect and respond to attacks, but the response time is delayed due to CPU load
Solution Approach 1:
The patent implements preliminary action by having the intermediary network device pre-process and filter malicious traffic before it reaches the target server. The intermediary device maintains connection state information and performs initial validation, so that when attacks occur, the server can respond immediately without being burdened by real-time crypto hash calculations
Data Source
AI summary
A system for efficiently thwarting syn flood DDoS attacks on a target server including a CPU, the system comprising: network controller hardware having steering capability; and a software application to create and to configure initial steering object/s which define a steering configuration of the network controller and monitor at least one opened connection to the server, including updating the steering configuration responsive to establishment of at least one connection to the server, wherein the network controller hardware's steering capability is used to provide a SYN cookie value used for said thwarting, and to send at least one packet, modified, to the packet's source.

