Traffic Flow Migration for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Client-server architectures are vulnerable to cyber-attacks, particularly low-volume Distributed Denial of Service (DDoS) attacks, which can cause resource overload and degrade or deny access to servers, impacting user performance.

Innovation Solution

A system that monitors traffic flows in a protected computing environment, instantiates utility processing resources or containers to manage traffic, and configures the environment to route data traffic to these resources, allowing for live migration of traffic and separation of suspicious flows, thereby mitigating the impact of attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single processing resource handles all traffic, then device complexity is low, but reliability deteriorates under attack conditions

Engineering Contradiction:
Improveservice availabilityVSAvoidprocessing resource architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the processing resource into multiple virtual processing resources (containers) that can independently handle different traffic flows. This allows the system to distribute attack traffic across multiple isolated containers while legitimate traffic continues to be handled by the original processing resource, thereby maintaining service availability without requiring a completely complex distributed architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network firewall as an intermediary component that monitors and controls traffic flows between external networks and processing resources. The firewall detects suspicious traffic patterns and dynamically routes them to isolated utility processing resources, protecting the main service from direct attack while maintaining normal operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traffic monitoring and migration capabilities are added, then reliability improves, but device complexity increases

Engineering Contradiction:
Improveattack resistanceVSAvoidtraffic management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically detects suspicious traffic patterns, dynamically creates isolated utility processing resources, and routes attack traffic without human intervention. The monitoring and migration capabilities are integrated into the existing infrastructure, allowing the system to protect itself while minimizing additional complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent makes existing processing resources multi-functional by enabling them to simultaneously handle legitimate traffic and isolated attack traffic through dynamic container creation and traffic routing. The same infrastructure components serve both normal service operations and attack mitigation functions, reducing the need for separate dedicated systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If suspicious traffic is isolated to utility processing resources, then harmful factors are contained, but loss of time occurs during traffic migration

Engineering Contradiction:
Improveattack impactVSAvoidtraffic migration time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-configuring utility processing resources and establishing traffic routing rules before attacks occur. The system maintains a pool of ready-to-use isolated containers and pre-defined routing policies, enabling rapid response to detected attacks without the time penalty of creating resources and configuring routes during the attack itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic traffic migration where the system continuously monitors traffic patterns and adapts routing decisions in real-time. When suspicious traffic is detected, the system dynamically creates isolated containers and routes traffic to them, while maintaining flexibility to switch back to normal routing once the threat is mitigated, minimizing overall migration time.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12081573B2Migration of traffic flows
Publication Date: 2024.09.03 PERATON LABS INC
  • US12081573B2 patent drawing
  • US12081573B2 patent drawing
  • US12081573B2 patent drawing

AI summary

There is set forth herein obtaining data traffic monitoring data, the data traffic monitoring data being in dependence on monitoring of traffic received by a container of a protected computing environment; obtaining data traffic monitoring data, the data traffic monitoring data being in dependence on monitoring of traffic received by a processing resource of a computing environment; obtaining a state of the processing resource and provisioning a utility processing resource to include the state of the processing resource; and configuring the computing environment to route data traffic to the utility processing resource.