Lightweight Tuned DDoS Protection via Container Hypervisor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DDoS mitigation solutions, such as physical boxes and virtual machines, are inefficient in resource allocation, prone to failure, and slow to adapt to evolving attack methods, leading to potential system overload and resource mismanagement.

Innovation Solution

Implementing a lightweight container hypervisor with protection and forensic containers on a server, which directs queries through protection containers to filter malicious traffic and sends forensic information to external threat intelligence for analysis, allowing for timely updates and efficient resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional physical boxes or virtual machines are used for DDoS mitigation, then system protection is provided, but resource allocation efficiency deteriorates and system reliability worsens due to potential failure points

Engineering Contradiction:
Improvesystem protection reliabilityVSAvoidresource allocation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments DDoS protection into multiple independent container instances, each handling specific protection tasks. This segmentation allows individual containers to fail without compromising the entire system, improving reliability while maintaining manageable complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network intermediary component that sits between the network and the server, handling DDoS mitigation tasks. This intermediary layer protects the core system while enabling efficient resource allocation through centralized control and container orchestration

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional DDoS mitigation systems are deployed, then basic protection is achieved, but adaptability to evolving attack methods deteriorates due to slow update mechanisms

Engineering Contradiction:
Improveadaptability to evolving attacksVSAvoidtime for protection updates
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system employs dynamic container instances that can be rapidly created, modified, and destroyed based on real-time threat intelligence. This dynamic architecture enables quick adaptation to new attack vectors without requiring system-wide reconfiguration, reducing update time while maintaining high adaptability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback loops where container instances continuously monitor attack patterns and automatically adjust protection strategies. This real-time feedback mechanism enables rapid adaptation to evolving threats without manual intervention, eliminating update delays

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive DDoS protection is implemented, then security is improved, but system performance deteriorates due to processing overhead

Engineering Contradiction:
ImproveDDoS protection effectivenessVSAvoidsystem processing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies partial protection actions by deploying container instances selectively based on threat levels and resource availability. Rather than always applying maximum protection, the system adjusts the degree of protection dynamically, maintaining effective DDoS mitigation while minimizing processing overhead on legitimate traffic

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20220394059A1Lightweight tuned DDOS protection
Publication Date: 2022.12.08 LEVEL 3 COMMUNICATIONS LLC
  • US20220394059A1 patent drawing
  • US20220394059A1 patent drawing
  • US20220394059A1 patent drawing

AI summary

Systems and methods for improved DDoS mitigation by utilizing lightweight and tuned mitigation techniques are provided. A lightweight, tuned DDoS system provides protection from DDoS attacks by hosting a container hypervisor on a server that is isolated from other server processes. The container hypervisor may include protection containers and forensic containers. Traffic received at the server is directed through the protection containers to filter out malicious traffic prior to valid traffic being sent to other system processes. The protection containers may be specifically tuned to the service provided by the server. Additionally, malicious traffic may be directed from the protection containers to the forensics containers for extraction of forensic information to be directed to external threat intelligence systems for analysis. As threats change, the threat intelligence system may periodically send modification information to the server to modify the protection schemes of the protection containers in the container hypervisor.