Botnet Detection via Network Event Proximity and Time Density

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of cyber threats, particularly malicious botnets exploiting IoT devices, makes it difficult to track and block distributed denial-of-service attacks and other malicious activities due to their distributed nature and use of dynamic IP addresses.

Innovation Solution

A method and system for identifying botnets by analyzing network data to determine network event proximity, time density, and trend patterns, using a detection server with processing circuitry and memory to detect botnet activity and trigger alerts or mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IP blocking methods are used to prevent botnet attacks, then single IP addresses can be easily blocked, but thousands of dynamically changing IP addresses from distributed botnets become much more difficult to control and block

Engineering Contradiction:
Improveeffectiveness of blockingVSAvoidcomplexity of tracking and blocking system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the problem of botnet detection by breaking down network traffic analysis into multiple analytical dimensions: network event proximity (temporal clustering), time density (event frequency over time), and trend patterns (behavioral sequences). This segmentation allows the system to detect botnet activity through multiple independent indicators rather than relying on a single blocking mechanism, effectively addressing the challenge of distributed dynamic IP addresses.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional single-dimension IP address blocking to multi-dimensional network behavior analysis. By introducing temporal dimensions (time density, event proximity) and pattern dimensions (trend analysis, behavioral sequences), the system creates a higher-dimensional detection space that can identify botnet activity regardless of IP address changes, effectively resolving the contradiction between blocking effectiveness and system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Power

If botnets use distributed IoT devices with dynamic IP addresses to conduct attacks, then the attack coverage and processing power increase significantly, but the ability to track and block the attacks deteriorates

Engineering Contradiction:
Improveattack processing powerVSAvoiddifficulty of tracking botnet activity
Core Design Contradiction:
PowerVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms by continuously monitoring network events and updating detection models in real-time. The system analyzes network event proximity, time density, and trend patterns with continuous feedback loops that adjust detection thresholds and parameters based on observed botnet behavior, enabling the system to track and detect distributed botnet attacks despite their dynamic nature and high processing power.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary detection layer between network traffic and blocking actions. This intermediary system analyzes network events through multiple dimensions (temporal proximity, time density, trend patterns) and generates detection signals that trigger appropriate responses. This intermediary layer simplifies the tracking problem by abstracting complex distributed botnet behavior into detectable pattern signatures.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If real-time analysis of network data is performed to detect botnet activity, then timely identification and mitigation of attacks is achieved, but the computational resources and system complexity increase

Engineering Contradiction:
Improveresponse time to botnet attacksVSAvoidcomplexity of detection system
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent applies partial action by focusing detection efforts on specific critical dimensions rather than analyzing all possible network parameters. The system selectively monitors network event proximity, time density, and trend patterns - three key dimensions that provide sufficient detection capability without requiring exhaustive analysis of all network data, thus achieving timely detection with moderate system complexity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements preliminary action by establishing detection thresholds and analysis frameworks in advance. The system pre-configures detection criteria for network event proximity, time density, and trend patterns, allowing it to quickly evaluate incoming network data against predetermined standards. This preliminary preparation enables rapid real-time detection without requiring complex runtime decision-making, reducing both response time and operational complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10721148B2System and method for botnet identification
Publication Date: 2020.07.21 RADWARE LTD
  • US10721148B2 patent drawing
  • US10721148B2 patent drawing
  • US10721148B2 patent drawing

AI summary

A system and method for identifying botnets. The method includes determining a network event proximity based on collected network data, where the network data relates to at least one network device; determining time density of the network data; determining trend patterns of the network data; and determining, based on the network event proximity, time density, and trend patterns, when a botnet activity is present within the network data.