Terminal Uplink Packet Filtering for DDoS Traffic Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for controlling terminal behavior during DDoS attacks result in high user-plane traffic overheads, as tens of thousands of terminals with abnormal behavior overwhelm network resources, leading to inefficient traffic management and resource wastage.
Innovation Solution
Implementing traffic control at the terminal level by blocking uplink data packets matching specific packet filters, reducing the load on user plane network elements and signaling overheads, through the use of packet filters and QoS flow identifiers, allowing terminals to discard packets marked with specific QFIs, thereby reducing traffic exchanged between the terminal and the user plane network element.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the user plane network element performs matching on uplink data packets according to control policy and discards matching packets, then terminal attack behavior is prevented, but user-plane traffic overhead becomes extremely high when tens of thousands of terminals exhibit abnormal behavior
Solution Approach 1:
The patent extracts the traffic control function from the user plane network element and relocates it to the terminal device. The terminal receives packet filters from the policy control network element and independently performs packet filtering on uplink data packets, removing the burden of processing all terminal traffic from the user plane network element during DDoS attacks
Solution Approach 2:
The patent introduces packet filters as an intermediary mechanism between the policy control network element and the terminal traffic flow. These packet filters serve as the mediating rule set that enables the terminal to autonomously identify and discard abnormal traffic without requiring continuous user plane intervention
2Reliability
If the network side delivers control policies to user plane network elements for individual terminal control, then attack behavior can be prevented, but signaling overhead becomes extremely high when controlling tens of thousands of terminals
Solution Approach 1:
The patent merges the control approach by delivering packet filters through broadcast or group messaging mechanisms rather than individual unicast messages to each terminal. This consolidation reduces signaling overhead while maintaining the ability to control large numbers of terminals simultaneously during DDoS attacks
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
This application provides a method for controlling a connection between a terminal and a network, and an apparatus. The method includes: receiving, by a terminal, a packet filter; and discarding, by the terminal, an uplink data packet matching the packet filter. Based on this solution, a connection can be blocked near a source (that is, the connection is blocked from the terminal), to reduce traffic exchanged between the terminal and a user plane network element. Compared with an existing technical solution, the terminal implements traffic control to reduce a quantity of uplink data packets sent to the user plane network element, thereby reducing load of the user plane network element.