Multi-Dimensional Anomaly Detection for Selective DDoS Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for detecting distributed denial-of-service (DDoS) attacks in cloud environments rely on single-dimensional traffic analysis and static rules, leading to inaccurate and unreliable protection, which can disrupt legitimate traffic and services.

Innovation Solution

Implement a multi-dimensional anomaly detection system that monitors system load metrics and performs multi-dimensional analysis of traffic data using security modules like tenant, IP, and connection trackers, generating adaptive anomaly scores to identify and isolate malicious traffic sources while allowing legitimate traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If single-dimensional traffic analysis with static rules is used, then device complexity is reduced, but measurement precision and reliability of anomaly detection deteriorate

Engineering Contradiction:
Improvecomplexity of detection systemVSAvoidprecision of anomaly detection
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent transitions from single-dimensional traffic analysis to multi-dimensional analysis by incorporating multiple traffic metrics (request rate, connection state, byte rate, packet rate) and analyzing them across multiple dimensions simultaneously. This dimensional expansion enables more precise anomaly detection without requiring excessive system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The detection system is segmented into multiple independent analysis modules, each responsible for specific traffic dimensions. This segmentation allows the complex multi-dimensional analysis to be broken down into manageable components, maintaining system simplicity while achieving high detection precision through coordinated module operation.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If static rules are used for anomaly detection, then ease of operation is improved, but adaptability to different attack patterns deteriorates

Engineering Contradiction:
Improveease of configuring detection systemVSAvoidadaptability to different DDOS attack patterns
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic anomaly detection by continuously monitoring multiple traffic dimensions and automatically adjusting detection parameters based on observed patterns. This dynamic approach replaces static rules with adaptive algorithms that automatically respond to different attack patterns, maintaining ease of operation while significantly improving adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes detection parameters dynamically based on traffic conditions and identified attack patterns. By adjusting thresholds, weights, and analysis focus according to real-time observations, the system achieves high adaptability to various DDOS attack types without requiring manual reconfiguration, thus maintaining operational simplicity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multi-dimensional analysis with multiple security modules is implemented, then measurement precision and reliability of detection are improved, but device complexity increases

Engineering Contradiction:
Improvereliability of DDoS defenseVSAvoidcomplexity of multi-module detection system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security modules (traffic analysis, connection tracking, anomaly detection, rate limiting) into a unified integrated system. This consolidation achieves reliable multi-dimensional detection while managing complexity by coordinating modules through a centralized architecture that shares data and coordinates actions across all components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The detection system is designed with universal components that perform multiple functions. For example, the traffic analysis module simultaneously monitors multiple dimensions (rate, connection state, byte/packet volume) and feeds information to multiple detection algorithms. This multi-functionality reduces overall system complexity while maintaining high reliability through comprehensive analysis.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Object-affected harmful factors

If aggressive anomaly blocking is performed, then protection against attacks is improved, but harmful factors increase due to disruption of legitimate traffic

Engineering Contradiction:
Improveprotection level against malicious attacksVSAvoiddisruption to legitimate traffic flow
Core Design Contradiction:
Object-affected harmful factorsVSObject-generated harmful factors

Solution Approach 1:

The system applies partial blocking actions rather than complete traffic cessation. By implementing rate limiting and selective filtering that blocks only the excessive malicious portion of traffic while allowing legitimate traffic to pass, the system achieves strong attack protection without generating harmful disruptions to normal services.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent applies different quality levels of filtering to different traffic streams. Legitimate traffic receives minimal intervention with high-quality pass-through, while suspicious traffic undergoes stricter inspection and selective blocking. This localized quality approach ensures strong protection against attacks while minimizing disruption to legitimate users based on their specific traffic characteristics.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250350629A1Adaptive multi-dimensional anomaly detection
Publication Date: 2025.11.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250350629A1 patent drawing
  • US20250350629A1 patent drawing
  • US20250350629A1 patent drawing

AI summary

Adaptive multi-dimensional anomaly detection is provided. System load metrics of a computing device are monitored. Multi-dimensional analysis of traffic data from a plurality of traffic sources is performed with security modules of an anomaly detector on the computing device. A traffic source is identified from the plurality of traffic sources based on the multi-dimensional analysis of traffic data from the plurality of traffic sources and associated historical traffic data. An action is performed on the traffic data from the identified traffic source, while the traffic data from the plurality of traffic sources other than the identified traffic source is allowed unaffected.