Bot Detection Engine Aggregating Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems are ineffective in detecting botnet attacks, as the malicious activities of infected hosts blend in with normal network traffic, making it difficult to identify external control and subsequent attacks directed at other targets.

Innovation Solution

A bot detection engine that intercepts and analyzes network traffic, parses session datasets, and accumulates state data to generate host scores, identifying bots by detecting high-volume monetization behaviors such as click fraud, spam, and DDoS attacks, even when individual bot activities appear innocuous.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If conventional security systems analyze individual bot activities, then detection accuracy for single events is maintained, but the ability to detect coordinated botnet attacks is lost because individual activities blend with normal traffic

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The patent merges individual bot activities into aggregated datasets that are analyzed collectively. By combining multiple individual observations into a unified analysis perspective, the system detects patterns that emerge only at the aggregate level, such as coordinated DDoS attacks or distributed click fraud, while individual events remain indistinguishable from normal traffic.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a new dimension of analysis by creating an aggregated perspective that operates at a higher level of abstraction. Instead of analyzing individual bot events in isolation, the system aggregates events across multiple bots and time periods, creating a new analytical dimension that reveals coordinated malicious patterns without requiring precise identification of each individual event.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Difficulty of detecting and measuring

If the system aggregates bot activities to detect botnet behavior, then detection of coordinated attacks is improved, but the complexity of analysis increases

Engineering Contradiction:
Improvebotnet detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent segments the analysis process into distinct components: data collection, aggregation, analysis, and alerting. By dividing the complex task of botnet detection into manageable segments, the system can handle large volumes of data through automated aggregation while maintaining analytical depth through structured processing stages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs self-service through automated aggregation and analysis processes. The bot detection engine automatically collects data from multiple sources, aggregates it according to predefined criteria, analyzes patterns, and generates alerts without requiring manual intervention, thereby managing complexity through automation rather than manual analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3117363B1Method and system for detecting bot behavior
Publication Date: 2020.07.29 VECTRA NETWORKS
  • EP3117363B1 patent drawingFigure 1A
  • EP3117363B1 patent drawingFigure 1B
  • EP3117363B1 patent drawingFigure 2

AI summary

A bot detection engine to determine whether hosts in an organization's network are performing bot-related activities is disclosed. A bot detection engine can receive network traffic between hosts in a network, and/or between hosts across several networks. The bot engine may parse the network traffic into session datasets and discard the session datasets that were not initiated by hosts in a given network. The session datasets may be analyzed and state data may be accumulated. The state data may correspond to actions performed by the hosts, such as requesting a website or clicking ads, or requesting content within the website (e.g. clicking on a image which forms a HTTP request/response transaction for the image file).