Stream Steering Rate Limiting for Multi-Tenant DoS Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are slow to identify and halt Denial of Service (DoS) attacks, which can significantly reduce communication bandwidth in computing environments, affecting multiple tenants.

Innovation Solution

Implementing stream steering hardware with an initial flow rate monitor, meters, and rate limiters to detect and manage data flows exceeding a threshold, preventing overwhelming of network interfaces by rate-limiting excessive data streams.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DoS attack detection and remediation methods are used, then the system can identify and halt attacks, but the response time is too slow allowing significant bandwidth reduction

Engineering Contradiction:
ImproveDoS attack protection effectivenessVSAvoidDoS attack identification and response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring rate limiters and flow monitors before attacks occur. The system establishes baseline traffic patterns and pre-sets rate limiting thresholds, enabling immediate enforcement when anomalies are detected without requiring real-time analysis and decision-making during the attack itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary rate limiting layer between network traffic sources and the computing system. This intermediary component (rate limiter) actively monitors and controls traffic flows, acting as a buffer that can immediately throttle malicious traffic before it overwhelms the system, thus reducing response time while maintaining protection effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If rate limiting is applied to all data flows, then DoS attacks are prevented, but legitimate traffic is also restricted reducing system productivity

Engineering Contradiction:
ImproveNetwork interface protection from overwhelmingVSAvoidData processing capacity for legitimate tenants
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing differentiated rate limiting policies for different data flows. Instead of uniform rate limiting across all traffic, the system monitors individual flow characteristics and applies rate limits only to specific flows that exceed thresholds, while allowing legitimate flows to pass through at full capacity. This localized approach protects the system from DoS attacks while preserving productivity for legitimate tenants.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent utilizes parameter changes by dynamically adjusting rate limiting thresholds based on traffic flow characteristics. The system monitors parameters such as packet rate, flow duration, and traffic patterns, and adjusts rate limiting parameters accordingly. This allows the system to maintain high productivity for legitimate traffic while effectively blocking DoS attacks that exhibit abnormal parameter patterns.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4657799A1Denial of service protection
Publication Date: 2025.12.03 MELLANOX TECHNOLOGIES LTD(IL)
  • EP4657799A1 patent drawingFigure 1
  • EP4657799A1 patent drawingFigure 2
  • EP4657799A1 patent drawingFigure 3

AI summary

Apparatuses, systems, and techniques to monitor incoming data flows from a plurality of network sources and identify a data flow from any of the plurality of sources that exceeds a threshold value. In at least one embodiment, the data flow from any of the plurality of sources that exceeds the threshold value are rate-limited while the data flow from any of the plurality of sources that do not exceed the threshold value are passed through without any rate limiting.