Upstream Network Traffic Filter Deployment for DoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Defending large network-based services against network attacks, such as Denial-of-Service (DoS) attacks, is challenging due to the complexity of managing security measures across numerous computing resources and network devices, which can lead to overwhelming of existing network traffic filters and disruption of service.
Innovation Solution
A mechanism for dynamically deploying upstream network traffic filters closer to the entry point of attack traffic, allowing for filtering of malicious traffic before it reaches downstream resources, by determining the entry point and selecting a location with sufficient capacity to handle the attack volume, and deploying rules from existing network traffic filters to filter the traffic effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network traffic filters are deployed at downstream locations to protect computing resources, then the computing resources are protected from attack traffic, but the filters become overwhelmed and unable to handle the attack volume
Solution Approach 1:
The patent introduces a new spatial dimension for filter deployment by placing filters at upstream network locations closer to the entry point of attack traffic. This dimensional shift in filter placement allows the system to intercept malicious traffic before it reaches downstream computing resources, thereby maintaining filtering effectiveness without overwhelming existing downstream filters.
Solution Approach 2:
The patent implements preliminary action by deploying additional network traffic filters upstream before attack traffic reaches the vulnerable computing resources. This proactive placement of filters at strategic upstream locations enables the system to preemptively block or mitigate attack traffic, preventing the downstream filters from becoming overwhelmed in the first place.
2Reliability
If multiple security measures are deployed across a large network to protect against attacks, then network security is improved, but the complexity of managing these security measures increases significantly
Solution Approach 1:
The patent changes the parameter of filter location from fixed downstream positions to dynamic upstream positions based on attack detection. By automatically adjusting where filters are deployed in the network based on real-time threat assessment, the system enhances security without requiring manual configuration of multiple static security measures, thereby reducing management complexity.
Solution Approach 2:
The patent implements dynamic filter deployment where the location and configuration of network traffic filters are automatically adjusted based on detected attack patterns. This dynamic approach allows the security system to adapt to changing threats without manual intervention, improving network security while avoiding the complexity of managing numerous fixed security configurations.
3Productivity
If network traffic filters are placed closer to the entry point of attack traffic, then the burden on downstream resources is reduced, but the filters must handle higher attack volumes requiring sufficient capacity
Solution Approach 1:
The patent segments the network into multiple zones with strategically placed filters at different upstream locations. By dividing the filtering function across multiple segments rather than relying on a single filter, the system can distribute the burden of handling high attack volumes while still protecting downstream resources effectively.
Solution Approach 2:
The patent introduces intermediary filters at upstream network locations that act as mediators between the external attack traffic and the internal computing resources. These intermediary filters handle the initial burden of high-volume attack traffic, preventing it from overwhelming downstream resources while maintaining the ability to protect the network.
Data Source
AI summary
Functionality is disclosed herein for dynamically deploying an upstream network traffic filter in a network. The upstream network filter is dynamically deployed in a location that is closer to an entry point of an attack such that attack traffic reaches the upstream network filter before reaching a network traffic filter that is configured to perform network traffic filtering for a computing resource that is under attack. The upstream network traffic filter includes rules that are based on at least a portion of the rules that are applied by the network traffic filter.


