Bot Detection Engine Aggregating Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security systems are ineffective in detecting botnet attacks, as the malicious activities of infected hosts blend in with normal network traffic, making it difficult to identify external control and subsequent attacks directed at other targets.
Innovation Solution
A bot detection engine that intercepts and analyzes network traffic, parses session datasets, and accumulates state data to generate host scores, identifying bots by detecting high-volume monetization behaviors such as click fraud, spam, and DDoS attacks, even when individual bot activities appear innocuous.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If conventional security systems analyze individual bot activities, then detection accuracy for single events is maintained, but the ability to detect coordinated botnet attacks is lost because individual activities blend with normal traffic
Solution Approach 1:
The patent merges individual bot activities into aggregated datasets that are analyzed collectively. By combining multiple individual observations into a unified analysis perspective, the system detects patterns that emerge only at the aggregate level, such as coordinated DDoS attacks or distributed click fraud, while individual events remain indistinguishable from normal traffic.
Solution Approach 2:
The patent introduces a new dimension of analysis by creating an aggregated perspective that operates at a higher level of abstraction. Instead of analyzing individual bot events in isolation, the system aggregates events across multiple bots and time periods, creating a new analytical dimension that reveals coordinated malicious patterns without requiring precise identification of each individual event.
2Difficulty of detecting and measuring
If the system aggregates bot activities to detect botnet behavior, then detection of coordinated attacks is improved, but the complexity of analysis increases
Solution Approach 1:
The patent segments the analysis process into distinct components: data collection, aggregation, analysis, and alerting. By dividing the complex task of botnet detection into manageable segments, the system can handle large volumes of data through automated aggregation while maintaining analytical depth through structured processing stages.
Solution Approach 2:
The system performs self-service through automated aggregation and analysis processes. The bot detection engine automatically collects data from multiple sources, aggregates it according to predefined criteria, analyzes patterns, and generates alerts without requiring manual intervention, thereby managing complexity through automation rather than manual analysis.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
A bot detection engine to determine whether hosts in an organization's network are performing bot-related activities is disclosed. A bot detection engine can receive network traffic between hosts in a network, and/or between hosts across several networks. The bot engine may parse the network traffic into session datasets and discard the session datasets that were not initiated by hosts in a given network. The session datasets may be analyzed and state data may be accumulated. The state data may correspond to actions performed by the hosts, such as requesting a website or clicking ads, or requesting content within the website (e.g. clicking on a image which forms a HTTP request/response transaction for the image file).