Techniques for detecting advanced application layer flood attack tools
Patent Information
- Application Number
- EP2022966422
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-11-23
- Publication Date
- 2025-10-01
AI Technical Summary
Current solutions fail to accurately and efficiently detect HTTP flood DDoS attacks, as they struggle to differentiate between legitimate and malicious traffic, especially with advanced attack tools generating 'legitimate-looking' requests that evade simple filtering methods, leading to high false positive and false negative rates.
A method and system that process application-layer transactions to detect rate-based and rate-invariant anomalies using continuously updated baselines of Application Attributes (AppAttributes), distinguishing between legitimate and malicious traffic by modeling the applicative behavior of protected entities.
Enables fast and accurate detection of HTTP flood DDoS attacks while allowing proper operation during flash crowd events, reducing false positives and negatives, and effectively differentiating between legitimate and malicious traffic.
Smart Images

Figure 1.1