Terminal Uplink Packet Filtering for DDoS Traffic Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for controlling terminal behavior during DDoS attacks result in high user-plane traffic overheads, as tens of thousands of terminals with abnormal behavior overwhelm network resources, leading to inefficient traffic management and resource wastage.

Innovation Solution

Implementing traffic control at the terminal level by blocking uplink data packets matching specific packet filters, reducing the load on user plane network elements and signaling overheads, through the use of packet filters and QoS flow identifiers, allowing terminals to discard packets marked with specific QFIs, thereby reducing traffic exchanged between the terminal and the user plane network element.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the user plane network element performs matching on uplink data packets according to control policy and discards matching packets, then terminal attack behavior is prevented, but user-plane traffic overhead becomes extremely high when tens of thousands of terminals exhibit abnormal behavior

Engineering Contradiction:
Improveattack prevention capabilityVSAvoiduser-plane traffic overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the traffic control function from the user plane network element and relocates it to the terminal device. The terminal receives packet filters from the policy control network element and independently performs packet filtering on uplink data packets, removing the burden of processing all terminal traffic from the user plane network element during DDoS attacks

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces packet filters as an intermediary mechanism between the policy control network element and the terminal traffic flow. These packet filters serve as the mediating rule set that enables the terminal to autonomously identify and discard abnormal traffic without requiring continuous user plane intervention

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the network side delivers control policies to user plane network elements for individual terminal control, then attack behavior can be prevented, but signaling overhead becomes extremely high when controlling tens of thousands of terminals

Engineering Contradiction:
Improveattack behavior controlVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges the control approach by delivering packet filters through broadcast or group messaging mechanisms rather than individual unicast messages to each terminal. This consolidation reduces signaling overhead while maintaining the ability to control large numbers of terminals simultaneously during DDoS attacks

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3866506B1Method and device for controlling terminal and network connection
Publication Date: 2024.09.18 HUAWEI TECH CO LTD
  • EP3866506B1 patent drawingFigure 1~2
  • EP3866506B1 patent drawingFigure 3
  • EP3866506B1 patent drawingFigure 4

AI summary

This application provides a method for controlling a connection between a terminal and a network, and an apparatus. The method includes: receiving, by a terminal, a packet filter; and discarding, by the terminal, an uplink data packet matching the packet filter. Based on this solution, a connection can be blocked near a source (that is, the connection is blocked from the terminal), to reduce traffic exchanged between the terminal and a user plane network element. Compared with an existing technical solution, the terminal implements traffic control to reduce a quantity of uplink data packets sent to the user plane network element, thereby reducing load of the user plane network element.