Upstream Network Traffic Filter Deployment for DoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Defending large network-based services against network attacks, such as Denial-of-Service (DoS) attacks, is challenging due to the complexity of managing security measures across numerous computing resources and network devices, which can lead to overwhelming of existing network traffic filters and disruption of service.

Innovation Solution

A mechanism for dynamically deploying upstream network traffic filters closer to the entry point of attack traffic, allowing for filtering of malicious traffic before it reaches downstream resources, by determining the entry point and selecting a location with sufficient capacity to handle the attack volume, and deploying rules from existing network traffic filters to filter the traffic effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network traffic filters are deployed at downstream locations to protect computing resources, then the computing resources are protected from attack traffic, but the filters become overwhelmed and unable to handle the attack volume

Engineering Contradiction:
Improveprotection of computing resourcesVSAvoidfiltering capacity of existing filters
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a new spatial dimension for filter deployment by placing filters at upstream network locations closer to the entry point of attack traffic. This dimensional shift in filter placement allows the system to intercept malicious traffic before it reaches downstream computing resources, thereby maintaining filtering effectiveness without overwhelming existing downstream filters.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent implements preliminary action by deploying additional network traffic filters upstream before attack traffic reaches the vulnerable computing resources. This proactive placement of filters at strategic upstream locations enables the system to preemptively block or mitigate attack traffic, preventing the downstream filters from becoming overwhelmed in the first place.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple security measures are deployed across a large network to protect against attacks, then network security is improved, but the complexity of managing these security measures increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidmanagement complexity of security measures
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter of filter location from fixed downstream positions to dynamic upstream positions based on attack detection. By automatically adjusting where filters are deployed in the network based on real-time threat assessment, the system enhances security without requiring manual configuration of multiple static security measures, thereby reducing management complexity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamic filter deployment where the location and configuration of network traffic filters are automatically adjusted based on detected attack patterns. This dynamic approach allows the security system to adapt to changing threats without manual intervention, improving network security while avoiding the complexity of managing numerous fixed security configurations.

Inventive Principle:
Principle #15Dynamics

3Productivity

If network traffic filters are placed closer to the entry point of attack traffic, then the burden on downstream resources is reduced, but the filters must handle higher attack volumes requiring sufficient capacity

Engineering Contradiction:
Improveburden reduction on downstream resourcesVSAvoidattack traffic volume to be filtered
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent segments the network into multiple zones with strategically placed filters at different upstream locations. By dividing the filtering function across multiple segments rather than relying on a single filter, the system can distribute the burden of handling high attack volumes while still protecting downstream resources effectively.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary filters at upstream network locations that act as mediators between the external attack traffic and the internal computing resources. These intermediary filters handle the initial burden of high-volume attack traffic, preventing it from overwhelming downstream resources while maintaining the ability to protect the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9774611B1Dynamically deploying a network traffic filter
Publication Date: 2017.09.26 AMAZON TECH INC
  • US9774611B1 patent drawing
  • US9774611B1 patent drawing
  • US9774611B1 patent drawing

AI summary

Functionality is disclosed herein for dynamically deploying an upstream network traffic filter in a network. The upstream network filter is dynamically deployed in a location that is closer to an entry point of an attack such that attack traffic reaches the upstream network filter before reaching a network traffic filter that is configured to perform network traffic filtering for a computing resource that is under attack. The upstream network traffic filter includes rules that are based on at least a portion of the rules that are applied by the network traffic filter.