Virtual Front End Systems for DDoS Traffic Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer devices and networks are vulnerable to disruptions and resource exhaustion due to distributed denial of service (DDOS) attacks, which can consume computational resources and disrupt legitimate user access.

Innovation Solution

The implementation of virtual front end systems in a cloud center, configured based on customer specifications, to redirect and manage traffic during DDOS events, using Infrastructure-as-a-service (IaaS), Platform-as-a-service (PaaS), or Software-as-a-service (SaaS) models, with load balancing and monitoring to ensure resource sufficiency and automatic scaling as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic is redirected to virtual front end systems during DDOS events, then resource exhaustion is prevented, but system complexity increases

Engineering Contradiction:
Improveservice availabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces virtual front end systems as intermediary components between the DDOS mitigation system and the customer's front end system. These virtual systems absorb and filter malicious traffic before it reaches the actual front end system, preventing resource exhaustion while maintaining service availability for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments traffic handling by creating multiple virtual front end system instances that can independently process traffic. This segmentation allows the system to distribute DDOS attack traffic across multiple virtual instances, preventing any single system from becoming overwhelmed while maintaining overall service availability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If virtual front end systems are generated in cloud center, then DDOS mitigation is achieved, but manufacturing complexity increases

Engineering Contradiction:
ImproveDDOS protectionVSAvoidsystem deployment
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The virtual front end systems are designed with universal functionality that can be deployed across multiple cloud centers and configured for different customers through standardized profiles. This multi-functionality allows the same virtual system architecture to serve multiple purposes and customers, reducing deployment complexity despite the added DDOS protection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary configuration by storing customer profile information including operating system types, server software types, and software modules in advance. When a DDOS event occurs, virtual front end systems can be rapidly instantiated using these pre-configured profiles, significantly reducing deployment time and complexity.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If customer profile specifications are stored and used, then virtual system configuration is simplified, but information storage requirements increase

Engineering Contradiction:
Improvevirtual system configurationVSAvoiddata storage
Core Design Contradiction:
Ease of manufactureVSQuantity of substance

Solution Approach 1:

Instead of storing complete virtual system configurations, the patent stores compressed profile specifications that define the essential characteristics (operating system type, server software type, software modules). These compact profiles are then used to generate or copy the actual virtual system configurations when needed, reducing storage requirements while maintaining configuration simplicity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9100432B2Cloud-based distributed denial of service mitigation
Publication Date: 2015.08.04 VERIZON PATENT & LICENSING INC
  • US9100432B2 patent drawing
  • US9100432B2 patent drawing
  • US9100432B2 patent drawing

AI summary

A method, performed by a computer device, may include receiving an indication of a distributed denial of service event at a front end system associated with a customer; generating one or more virtual front end systems for the customer, in response to receiving the indication of the distributed denial of service event; and redirecting traffic intended for the customer's front end system to the generated one or more virtual front end systems. The method may further include determining whether resource capacity of the generated one or more virtual front end systems has been reached; and generating an additional one or more virtual front end systems for the customer, in response to determining that the resource capacity of the generated one or more virtual front end systems has been reached.