Application-Layer Signatures for HTTP Flood Attack Characterization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions fail to accurately and efficiently characterize HTTP flood attacks, as they struggle to distinguish between legitimate and malicious requests due to the complexity and randomness of attack patterns, leading to high false positive and false negative rates, especially during ultra-high volume attacks.

Innovation Solution

A system that computes attacker probabilities based on peacetime and attack distributions of applicative attributes, generating application-layer signatures with inclusive and exclusive sections to identify ongoing attacks, using paraphrase buffers and dynamic thresholds to differentiate between legitimate and malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If current solutions are used to characterize HTTP flood attacks, then the system can process traffic at high speed, but the measurement precision of distinguishing legitimate from malicious requests deteriorates

Engineering Contradiction:
Improvetraffic processing speedVSAvoidattack characterization accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent segments the attack characterization into multiple independent components: peacetime baseline distribution, attack distribution, attacker probability computation, and signature generation. Each component processes specific aspects of traffic analysis separately, allowing high-speed processing while maintaining precision through specialized handling of each segmentation element.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by computing peacetime baseline distributions and attack distributions in advance, storing them for rapid retrieval during attack detection. This pre-computation allows the system to quickly compare incoming traffic against established patterns without performing complex calculations in real-time, thus maintaining both speed and precision.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If the system uses complex characterization methods to improve measurement precision, then the false positive and false negative rates decrease, but the device complexity increases

Engineering Contradiction:
Improverequest classification accuracyVSAvoidsystem structure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously refines attacker probability computations based on comparing observed traffic distributions against baseline and attack distributions. The signature generation process uses feedback from probability thresholds to iteratively improve classification accuracy, reducing false positives and negatives while maintaining manageable system complexity through automated refinement.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes parameters dynamically by adjusting probability thresholds and selecting different applicative attributes based on the specific attack scenario. This allows the system to optimize measurement precision for different attack types without requiring a completely different system architecture, thus improving accuracy while controlling complexity through parameter adjustment rather than structural changes.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the system processes all applicative attributes in real-time, then the measurement precision improves, but the loss of time increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by selecting and processing only the most relevant applicative attributes for each attack scenario rather than analyzing all possible attributes. The system computes attacker probabilities for selected attributes and uses dynamic thresholding to focus computational resources on the most discriminating features, achieving high detection accuracy while minimizing processing time through selective attribute analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240396932A1Method and system for generating application-layer signatures characterizing advanced application-layer attacks
Publication Date: 2024.11.28 RADWARE LTD
  • US20240396932A1 patent drawing
  • US20240396932A1 patent drawing
  • US20240396932A1 patent drawing

AI summary

A method and device for generating application-layer signatures characterizing advanced application-layer attacks are provided. The method includes computing, based on applicative peacetime baseline distributions and attack distributions of applicative attributes included in application-layer transactions directed to a protected entity, an attacker probability of an attacker executing an ongoing application-layer attack; comparing the attacker probability computed for each of the applicative attributes to a dynamic attacker probability threshold; and including in an application-layer signature eligible applicative attributes having an attacker probability higher than the dynamic attacker threshold, wherein the application-layer signature includes an inclusive section and an exclusive section, and wherein the application-layer signature is indicative of an ongoing attack based on one of the exclusive section and the inclusive section.