Virtual Front End Systems for DDoS Traffic Redirection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer devices and networks are vulnerable to disruptions and resource exhaustion due to distributed denial of service (DDOS) attacks, which can consume computational resources and disrupt legitimate user access.
Innovation Solution
The implementation of virtual front end systems in a cloud center, configured based on customer specifications, to redirect and manage traffic during DDOS events, using Infrastructure-as-a-service (IaaS), Platform-as-a-service (PaaS), or Software-as-a-service (SaaS) models, with load balancing and monitoring to ensure resource sufficiency and automatic scaling as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic is redirected to virtual front end systems during DDOS events, then resource exhaustion is prevented, but system complexity increases
Solution Approach 1:
The patent introduces virtual front end systems as intermediary components between the DDOS mitigation system and the customer's front end system. These virtual systems absorb and filter malicious traffic before it reaches the actual front end system, preventing resource exhaustion while maintaining service availability for legitimate users.
Solution Approach 2:
The system segments traffic handling by creating multiple virtual front end system instances that can independently process traffic. This segmentation allows the system to distribute DDOS attack traffic across multiple virtual instances, preventing any single system from becoming overwhelmed while maintaining overall service availability.
2Reliability
If virtual front end systems are generated in cloud center, then DDOS mitigation is achieved, but manufacturing complexity increases
Solution Approach 1:
The virtual front end systems are designed with universal functionality that can be deployed across multiple cloud centers and configured for different customers through standardized profiles. This multi-functionality allows the same virtual system architecture to serve multiple purposes and customers, reducing deployment complexity despite the added DDOS protection capability.
Solution Approach 2:
The system performs preliminary configuration by storing customer profile information including operating system types, server software types, and software modules in advance. When a DDOS event occurs, virtual front end systems can be rapidly instantiated using these pre-configured profiles, significantly reducing deployment time and complexity.
3Ease of manufacture
If customer profile specifications are stored and used, then virtual system configuration is simplified, but information storage requirements increase
Solution Approach 1:
Instead of storing complete virtual system configurations, the patent stores compressed profile specifications that define the essential characteristics (operating system type, server software type, software modules). These compact profiles are then used to generate or copy the actual virtual system configurations when needed, reducing storage requirements while maintaining configuration simplicity.
Data Source
AI summary
A method, performed by a computer device, may include receiving an indication of a distributed denial of service event at a front end system associated with a customer; generating one or more virtual front end systems for the customer, in response to receiving the indication of the distributed denial of service event; and redirecting traffic intended for the customer's front end system to the generated one or more virtual front end systems. The method may further include determining whether resource capacity of the generated one or more virtual front end systems has been reached; and generating an additional one or more virtual front end systems for the customer, in response to determining that the resource capacity of the generated one or more virtual front end systems has been reached.


