Collaborative Node Segregation for DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network architectures face challenges in distinguishing and optimizing traffic flows for specific applications due to the use of shared protocols, and detecting and mitigating Denial of Service (DoS) attacks, especially in low power and lossy networks (LLNs), where resource constraints and distributed attacks complicate detection and mitigation.
Innovation Solution
A collaborative approach using machine learning-based attack detection and mitigation systems, where nodes with complementary capabilities form groups to assist each other in identifying and segregating attack traffic, enhancing detection and mitigation efficiency even in resource-constrained environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If nodes in the network independently perform attack detection and mitigation, then each node can operate autonomously, but resource-constrained nodes cannot effectively detect and mitigate sophisticated DDoS attacks
Solution Approach 1:
The patent combines the capabilities of multiple nodes into collaborative groups where they share machine learning models and detection resources. Nodes pool their computational power and expertise to collectively detect and mitigate DDoS attacks, allowing resource-constrained nodes to benefit from aggregated resources without individually bearing the full complexity burden.
Solution Approach 2:
The patent creates universal collaborative groups that can handle multiple types of attacks and serve multiple functions. The same collaborative infrastructure provides detection, classification, and mitigation capabilities across different attack scenarios, making the system adaptable without requiring separate specialized systems for each threat type.
2Measurement precision
If all nodes use advanced machine learning detection systems, then detection accuracy improves, but resource consumption and system complexity increase significantly
Solution Approach 1:
The patent segments the network into collaborative groups based on node capabilities and attack types. Each group maintains specialized machine learning models tailored to their specific threats and resource levels, rather than all nodes running identical comprehensive systems. This segmentation allows accurate detection where needed while conserving resources in less demanding segments.
Solution Approach 2:
The patent dynamically adjusts detection parameters, model complexity, and computational intensity based on available resources and threat levels. Nodes can modify their detection sensitivity, model update frequency, and computational allocation in response to changing conditions, maintaining high accuracy when resources permit while reducing consumption during resource constraints.
3Productivity
If nodes operate independently without collaboration, then system simplicity is maintained, but detection speed and mitigation effectiveness are reduced
Solution Approach 1:
The patent introduces collaborative groups as intermediary structures between individual nodes and the network. These groups facilitate coordinated detection and response while abstracting the complexity of inter-node communication and model sharing. The intermediary layer manages the complexity of collaboration, allowing nodes to benefit from faster collective response without directly managing complex peer-to-peer interactions.
Data Source
AI summary
In one embodiment, a particular node in a network determines information relating to network attack detection and mitigation from a local machine learning attack detection and mitigation system. The particular node sends a message to an address in the network indicating capabilities of the local machine learning attack detection and mitigation system based on the information. In response to the sent message, the particular node receives an indication that it is a member of a collaborative group of nodes based on the capabilities of the local machine learning attack detection and mitigation system being complementary to capabilities of other machine learning attack detection and mitigation systems. Then, in response to an attack being detected by the local machine learning attack detection and mitigation system, the particular node provides to the collaborative group of nodes an indication of attack data flows identified as corresponding to the attack.


