Collaborative Node Segregation for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network architectures face challenges in distinguishing and optimizing traffic flows for specific applications due to the use of shared protocols, and detecting and mitigating Denial of Service (DoS) attacks, especially in low power and lossy networks (LLNs), where resource constraints and distributed attacks complicate detection and mitigation.

Innovation Solution

A collaborative approach using machine learning-based attack detection and mitigation systems, where nodes with complementary capabilities form groups to assist each other in identifying and segregating attack traffic, enhancing detection and mitigation efficiency even in resource-constrained environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If nodes in the network independently perform attack detection and mitigation, then each node can operate autonomously, but resource-constrained nodes cannot effectively detect and mitigate sophisticated DDoS attacks

Engineering Contradiction:
Improveattack detection effectivenessVSAvoidnode resource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the capabilities of multiple nodes into collaborative groups where they share machine learning models and detection resources. Nodes pool their computational power and expertise to collectively detect and mitigate DDoS attacks, allowing resource-constrained nodes to benefit from aggregated resources without individually bearing the full complexity burden.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal collaborative groups that can handle multiple types of attacks and serve multiple functions. The same collaborative infrastructure provides detection, classification, and mitigation capabilities across different attack scenarios, making the system adaptable without requiring separate specialized systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If all nodes use advanced machine learning detection systems, then detection accuracy improves, but resource consumption and system complexity increase significantly

Engineering Contradiction:
Improveattack detection accuracyVSAvoidnode energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the network into collaborative groups based on node capabilities and attack types. Each group maintains specialized machine learning models tailored to their specific threats and resource levels, rather than all nodes running identical comprehensive systems. This segmentation allows accurate detection where needed while conserving resources in less demanding segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent dynamically adjusts detection parameters, model complexity, and computational intensity based on available resources and threat levels. Nodes can modify their detection sensitivity, model update frequency, and computational allocation in response to changing conditions, maintaining high accuracy when resources permit while reducing consumption during resource constraints.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If nodes operate independently without collaboration, then system simplicity is maintained, but detection speed and mitigation effectiveness are reduced

Engineering Contradiction:
Improveattack mitigation speedVSAvoidcollaborative system structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces collaborative groups as intermediary structures between individual nodes and the network. These groups facilitate coordinated detection and response while abstracting the complexity of inter-node communication and model sharing. The intermediary layer manages the complexity of collaboration, allowing nodes to benefit from faster collective response without directly managing complex peer-to-peer interactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20160028755A1Traffic segregation in ddos attack architecture
Publication Date: 2016.01.28 CISCO TECHNOLOGY INC
  • US20160028755A1 patent drawing
  • US20160028755A1 patent drawing
  • US20160028755A1 patent drawing

AI summary

In one embodiment, a particular node in a network determines information relating to network attack detection and mitigation from a local machine learning attack detection and mitigation system. The particular node sends a message to an address in the network indicating capabilities of the local machine learning attack detection and mitigation system based on the information. In response to the sent message, the particular node receives an indication that it is a member of a collaborative group of nodes based on the capabilities of the local machine learning attack detection and mitigation system being complementary to capabilities of other machine learning attack detection and mitigation systems. Then, in response to an attack being detected by the local machine learning attack detection and mitigation system, the particular node provides to the collaborative group of nodes an indication of attack data flows identified as corresponding to the attack.