EP1566947A1

Method for distributed denial-of-service attack mitigation by selective black-holing in MPLS VPNs

Abstract

A system and method for aiding the handling of DDoS attacks in which VPN traffic entering an ISP network (10) at some points will be black-holed (12), while VPN traffic entering the ISP network at other points will be routed, as it should be, to the system-under-attack (14). Thus, the system-under-attack (14) is made available to some of the user community and made unavailable to suspect portions of the user community. Furthermore, the number of entry points where black-holing of VPN traffic occurs can be selected and changed in real-time during a DDoS attack.

EP1566947A1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Projected expiry passed 15 February 2025, 1.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

19 claims: 10 independent, 9 dependent

  1. 1
    An internet service provider (ISP) VPN network comprising:a plurality of edge routers;a plurality of core routers adapted to allow communication between said plurality of edge routers;a VPN application in communication with a first one of said plurality of edge routers, said VPN application having a first IP address;and a black-hole router in communication with said core routers, said black-hole router adapted to inject a second IP address into said ISP VPN network, said second IP address comprising: the same address as the first IP address;a higher preference value than said first IP address;and a community value such that when said second IP address is injected, a selected first number of edge routers direct VPN traffic addressed for said first IP address to said VPN application and a selected second number of edge routers direct VPN traffic addressed for said first IP address to said black hole router.
  2. 5
    The ISP network of any preceding claim, wherein said ISP network utilizes dynamic routing protocols in combination with community-based route filtering to propagate the injected second IP address to said edge routers.
  3. 6
    The ISP network of any preceding claim, wherein when said second number of edge routers directs VPN traffic, addressed for said first IP address, to said black hole router, said black hole router is adapted to receive such traffic as black-holed-traffic, said black-hole router adapted to analyze said black-holed traffic in order to determine a ratio of attack traffic to legitimate traffic.
  4. 7
    The ISP network of any preceding claim, further comprising at least one route reflector, each one of said route reflectors being connected to a different set of edge routers from said plurality of edge routers, said route reflectors being adapted to update said edge routers with route instructions, such route instructions including said injected second address.
  5. 8
    An ISP network comprising:a plurality of edge routers;an application in direct or indirect electrical communication with a first one of said plurality of edge routers;said application having a first IP address such that VPN traffic addressed for said first IP address and entering said ISP network at any one of said plurality of edge routers, is routed to said application;a black-hole router;a router adapted to inject an instruction into said ISP network, such that select edge router(s) redirect VPN traffic, which is addressed to said first IP address, to said black-hole router.
  6. 12
    The ISP network of any one of claims 8 to 11, wherein said injected instruction is a Border Gateway Protocol (BGP) routing instruction.
  7. 13
    The ISP network of any one of claims 8 to 12, wherein said black-hole router is adapted to receive redirected traffic from said select edge router(s) and to determine a ratio of attack VPN traffic to legitimate VPN traffic found in said redirected traffic.
  8. 14
    The ISP network of any one of claims 8 to 13, wherein said router injects said instruction when said application is experiencing a DDoS attack.
  9. 15
    A method of managing a DDoS attack on an application within an ISP, said application having a first IP address, said method comprising:injecting a BGP routing instruction into said ISP when said DDoS attack is occurring;redirecting, at selected edge routers, VPN traffic addressed for said first IP address to a black-hole router;directing, at other edge routers, VPN traffic addressed for said first IP address to said application that is experiencing said DDoS attack.
  10. 19
    The method of any one of claims 15 to 18, wherein injecting said BGP routing instruction into said ISP is done by providing said BGP routing instruction to a route-reflector for disseminating said BGP routing instruction to other route reflectors within said ISP network.