Techniques for detecting advanced application layer flood attack tools

EP4623545A1Pending Publication Date: 2025-10-01RADWARE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2022966422
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-11-23
Publication Date
2025-10-01

AI Technical Summary

Technical Problem

Current solutions fail to accurately and efficiently detect HTTP flood DDoS attacks, as they struggle to differentiate between legitimate and malicious traffic, especially with advanced attack tools generating 'legitimate-looking' requests that evade simple filtering methods, leading to high false positive and false negative rates.

Method used

A method and system that process application-layer transactions to detect rate-based and rate-invariant anomalies using continuously updated baselines of Application Attributes (AppAttributes), distinguishing between legitimate and malicious traffic by modeling the applicative behavior of protected entities.

Benefits of technology

Enables fast and accurate detection of HTTP flood DDoS attacks while allowing proper operation during flash crowd events, reducing false positives and negatives, and effectively differentiating between legitimate and malicious traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

A method and system for detecting application layer flood denial-of-service (DDoS) attacks carried by attackers utilizing advanced application layer flood attack tools are provided. The method processing application-layer transactions received during a current time window to detect a rate-based anomaly in a traffic directed to a protected entity; processing the received application-layer transactions to determine rate-invariant anomaly based on a plurality of Application Attributes (AppAttributes) observed in the application-layer transactions received during the current time window, wherein the rate-invariant anomaly is determined based on a continuously updated baseline of AppAttributes, wherein AppAttributes represent the applicative behavior of the protected entity modeled based on the application-layer transactions; determining based on a detected rate-based anomaly and a detected rate-invariant anomaly if an application layer flood DDoS is present in the current time window; and causing a mitigation action when the application layer flood DDoS is present.
Need to check novelty before this filing date? Find Prior Art