Application-Layer Signatures for HTTP Flood Attack Characterization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions fail to accurately and efficiently characterize HTTP flood attacks, as they struggle to distinguish between legitimate and malicious requests due to the complexity and randomness of attack patterns, leading to high false positive and false negative rates, especially during ultra-high volume attacks.
Innovation Solution
A system that computes attacker probabilities based on peacetime and attack distributions of applicative attributes, generating application-layer signatures with inclusive and exclusive sections to identify ongoing attacks, using paraphrase buffers and dynamic thresholds to differentiate between legitimate and malicious traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If current solutions are used to characterize HTTP flood attacks, then the system can process traffic at high speed, but the measurement precision of distinguishing legitimate from malicious requests deteriorates
Solution Approach 1:
The patent segments the attack characterization into multiple independent components: peacetime baseline distribution, attack distribution, attacker probability computation, and signature generation. Each component processes specific aspects of traffic analysis separately, allowing high-speed processing while maintaining precision through specialized handling of each segmentation element.
Solution Approach 2:
The system performs preliminary action by computing peacetime baseline distributions and attack distributions in advance, storing them for rapid retrieval during attack detection. This pre-computation allows the system to quickly compare incoming traffic against established patterns without performing complex calculations in real-time, thus maintaining both speed and precision.
2Measurement precision
If the system uses complex characterization methods to improve measurement precision, then the false positive and false negative rates decrease, but the device complexity increases
Solution Approach 1:
The patent implements feedback mechanisms where the system continuously refines attacker probability computations based on comparing observed traffic distributions against baseline and attack distributions. The signature generation process uses feedback from probability thresholds to iteratively improve classification accuracy, reducing false positives and negatives while maintaining manageable system complexity through automated refinement.
Solution Approach 2:
The system changes parameters dynamically by adjusting probability thresholds and selecting different applicative attributes based on the specific attack scenario. This allows the system to optimize measurement precision for different attack types without requiring a completely different system architecture, thus improving accuracy while controlling complexity through parameter adjustment rather than structural changes.
3Measurement precision
If the system processes all applicative attributes in real-time, then the measurement precision improves, but the loss of time increases
Solution Approach 1:
The patent applies partial action by selecting and processing only the most relevant applicative attributes for each attack scenario rather than analyzing all possible attributes. The system computes attacker probabilities for selected attributes and uses dynamic thresholding to focus computational resources on the most discriminating features, achieving high detection accuracy while minimizing processing time through selective attribute analysis.
Data Source
AI summary
A method and device for generating application-layer signatures characterizing advanced application-layer attacks are provided. The method includes computing, based on applicative peacetime baseline distributions and attack distributions of applicative attributes included in application-layer transactions directed to a protected entity, an attacker probability of an attacker executing an ongoing application-layer attack; comparing the attacker probability computed for each of the applicative attributes to a dynamic attacker probability threshold; and including in an application-layer signature eligible applicative attributes having an attacker probability higher than the dynamic attacker threshold, wherein the application-layer signature includes an inclusive section and an exclusive section, and wherein the application-layer signature is indicative of an ongoing attack based on one of the exclusive section and the inclusive section.


