Device for protecting server processors from attacks

RU2865323C1Active Publication Date: 2026-07-01FEDERALNOE GOSUDARSTVENNOE BYUDZHETNOE OBRAZOVATELNOE UCHREZHDENIE VYSSHEGO OBRAZOVANIYA POVOLZHSKIJ GOSUDARSTVENNYJ UNIV TELEKOMMUNIKATSIJ I INFORMATIKI
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
RU · RU
Patent Type
Patents
Current Assignee / Owner
FEDERALNOE GOSUDARSTVENNOE BYUDZHETNOE OBRAZOVATELNOE UCHREZHDENIE VYSSHEGO OBRAZOVANIYA POVOLZHSKIJ GOSUDARSTVENNYJ UNIV TELEKOMMUNIKATSIJ I INFORMATIKI
Filing Date
2026-03-05
Publication Date
2026-07-01

AI Technical Summary

Technical Problem

Existing methods struggle to detect and counter application-layer DDoS attacks that utilize minimal bandwidth but maintain a high number of connections, exhausting server resources over time, as they resemble normal user traffic and evade standard rate-based and IP filtering detection.

Method used

A device that monitors server processor load using a reversible accumulator based on the Leaky bucket algorithm, analyzing processor load factors to detect potential attacks by comparing them against permissible thresholds, preventing false positives from short-term legitimate loads.

Benefits of technology

Effectively identifies and mitigates application-layer DDoS attacks by detecting persistent processor overloads, reducing false alarms, and protecting server resources from gradual exhaustion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000001_ABST
    Figure 00000001_ABST
Patent Text Reader

Abstract

FIELD: field of information security.SUBSTANCE: invention can be used to detect information attacks by intruders on servers. The device for detecting attacks on a server comprises an adapter connected to the protected server, a normalization device, a synchronization generator that synchronizes the operation of all devices, an analyser, a generator of codes for the permissible average processor load, and a reversible accumulating adder, wherein the adapter sends requests to the server and receives response codes from the server about the processor load factor, the received codes after normalization are fed to the summing input of the reversible accumulating adder, to the subtracting input of which codes from the generator of codes for the permissible average processor load are received, and the sum of the reversible accumulating adder is compared in the analyser with its maximum permissible value, reaching the maximum value indicates the presence of an attack on the server.EFFECT: ability to identify information attacks on the server.1 cl, 1 dwg
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to the field of information security and can be used to protect Internet server processors from information attacks by intruders.

[0002] DDoS attacks on corporate servers are among the most serious cyber threats today. The presence of such attacks is typically detected based on an increase in the intensity of traffic flows that overload the server's communication channels.

[0003] However, recently, a significant number of attacks have emerged whose traffic does not load the server's transmission channels [1, 3, 4]. These attacks are specifically designed to use a minimal amount of bandwidth but maintain a maximum number of connections or threads on the server for a long time, gradually exhausting its resources [5]. Their traffic is virtually indistinguishable from normal user behavior, making them extremely difficult to detect using standard rate-based detection methods [5]. Application-layer attacks at the very top level of the model are particularly difficult to counter [2, 3]. They aim to exhaust the resources of the application itself on the server, such as a web server, database, or API application [3]. Attacks of this type, such as HTTP GET / POST floods, send a huge number of apparently legitimate requests that require significant computing resources to process.A key feature of these attacks is computational asymmetry: the effort expended by the client to send a request is negligible compared to the resources the server must expend to process it [3]. Furthermore, traffic from a botnet performing an L7 attack is virtually indistinguishable from that of real users, as it does not contain spoofed IP addresses and appears to be normal traffic [3]. This renders standard IP filtering methods useless. Such attacks lead to a sharp increase in server CPU utilization.

[0004] The essence of the proposed device is that it determines the presence of information attacks directly based on data on the server processor load factor.

[0005] The technical result of the proposed invention consists in the possibility of taking measures to protect against overload of server processors when it develops.

[0006] The device chosen as a prototype is implemented according to patent No. 2851315 – Method for protecting servers [7]. The prototype method is based on the analysis of the numbers of various MAC addresses stored in a buffer. The proposed device, unlike the prototype, does not use a buffer, but an accumulator, whose summing input receives the server processor load factors. Here, the load factor is understood as the proportion of time during which the processor is loaded, relative to the specified analysis cycle time. Operating systems of modern computers usually have built-in applications that provide monitoring of various parameters of processor groups. Such an application is available, for example, in Windows (basic monitoring). The application displays a real-time graph showing the overall CPU load as a percentage.

[0007] If there is no such program on the server, then when connecting a control device to it, it can be installed automatically.

[0008] The proposed device operates as follows (Fig. 1).

[0009] Fig. 1 shows the following elements:

[0010] 1 – protected server, 2 – protection device, 3 – processor load monitoring program, 4 – processors, 5 – input adapter, 6 – normalization device, 7 – processor load factor codes, 8 – reversible accumulator (Leaky bucket algorithm), 9 – analyzer, 10 – generator of acceptable average processor load codes, 11 – synchronization generator.

[0011] The protected server-1, connected to the network (not shown in Fig. 1) is polled by the adapter-5 of the proposed device-2 and sends to the device-2 responses generated by the program-3 and containing information about the load of the processor(s)-4. The information about the load of the processor is normalized in the normalizer-6, and the codes-7 of the load factor are fed to the summing input of the reversible accumulating adder-8, which operates on the “Leaky bucket” principle [6].

[0012] The constant set codes of the permissible average processor load – R are sent to the subtracting input of the reversible adder-8 from the generator-10 of codes of the permissible average processor load.

[0013] The S content codes of the reversible accumulator-8 can only have positive values. If a negative value is received, the accumulator's contents are reset. The S content codes are transmitted to the input of analyzer-9, which compares the current S level value with the set maximum permissible value Sm. Reaching the maximum value indicates a possible attack causing a persistent processor overload. The entire system is synchronized by C signals received from clock generator-11.

[0014] Unlike the conventional "Leaky Bucket" algorithm, which uses a bidirectional pulse counter, this algorithm uses a bidirectional accumulator, whose inputs are fed with processor(s) load factor codes. The use of a bidirectional accumulator prevents false positives during short-term legitimate increases in processor load.

[0015] LITERATURE

[0016] How to DDoS | DoS and DDoS attack tools – Cloudflare. – URL: https: / / www.cloudflare.com / learning / ddos / ddos-attack-tools / how-to-ddos / (accessed: 05.12.2025).

[0017] How to prevent DDoS attacks | Methods and tools – Cloudflare. – URL: https: / / www.cloudflare.com / learning / ddos / how-to-prevent-ddos-attacks / (access date: 12 / 05 / 2025).

[0018] Application layer DDoS attack – Cloudflare. – URL: https: / / www.cloudflare.com / learning / ddos / application-layer-ddos-attack / (accessed: 05.12.2025).

[0019] What is DDoS mitigation? – Cloudflare. – URL: https: / / www.cloudflare.com / learning / ddos / ddos-mitigation / (accessed: 05.12.2025).

[0020] What is a low and slow attack? Low and slow DDoS attack – Cloudflare. – URL: https: / / www.cloudflare.com / learning / ddos / ddos-low-and-slow-attack / (access date: 12 / 05 / 2025).

[0021] Leaky_bucket. – URL: https: / / en.wikipedia.org / wiki / Leaky_bucket.

[0022] Patent for invention RU 2851315 C1.

Claims

A device for detecting attacks on a server, characterized in that it contains an adapter connected to a protected server, a normalization device, a synchronization generator that synchronizes the operation of all devices, an analyzer, a generator of codes for the permissible average processor load, and a reversible accumulating adder, wherein the adapter sends requests to the server and receives response codes from the server regarding the processor load factor, the received codes, after normalization, are sent to the summing input of the reversible accumulating adder, to the subtracting input of which codes from the generator of codes for the permissible average processor load are received, and the sum of the reversible accumulating adder is compared in the analyzer with its maximum permissible value, reaching the maximum value indicates the presence of an attack on the server.