Datacenter Flow Aggregation for Volumetric DDoS Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network analytical techniques struggle to detect volumetric or 'carpet bombing' DDoS attacks, which target multiple servers within a datacenter subnet by saturating network routing devices with limited malicious packet data, making them difficult to identify.

Innovation Solution

A multi-layered aggregation processing architecture that iteratively analyzes network flow information to detect potential threats by assigning time, datacenter, subnet, and server thresholds, issuing alerts when packet data size or number exceeds predefined limits, and incorporating future aggregation for additional IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional network analytical techniques are used to monitor network traffic, then the detection of traditional DDoS attacks targeting specific hosts is effective, but the detection of volumetric DDoS attacks targeting multiple servers is difficult

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the detection process into multiple hierarchical layers: individual server level, subnet level, and datacenter level. Each layer aggregates traffic metrics from multiple sources, enabling the system to detect volumetric attacks that target multiple servers while maintaining the ability to detect traditional single-host attacks. This segmentation allows the system to adapt to different attack patterns without sacrificing detection precision.

Inventive Principle:
Principle #1Segmentation

2Reliability

If network monitoring focuses on individual host traffic analysis, then specific DDoS attacks are detected effectively, but volumetric attacks saturating network elements remain undetected

Engineering Contradiction:
Improvedetection reliabilityVSAvoidattack impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges traffic analysis from multiple individual hosts into subnet-level and datacenter-level aggregated views. By combining metrics from numerous servers, the system can detect volumetric attacks that would be invisible at the individual host level. This merging approach maintains reliable detection of traditional attacks while adding the capability to detect large-scale volumetric attacks that saturate network elements.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If the system monitors all packet data in real-time across the entire network, then comprehensive threat detection is achieved, but the complexity and resource consumption increase significantly

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the network monitoring system into hierarchical segments: individual servers, subnets, and datacenters. Each segment performs localized aggregation and analysis of traffic metrics, reducing the complexity burden on any single component. This segmentation enables comprehensive threat detection across the entire network while keeping individual system elements manageable in complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces hierarchical dimensions to the monitoring system, organizing detection capabilities across multiple levels (server → subnet → datacenter). This dimensional organization allows the system to achieve comprehensive threat detection without linearly increasing complexity, as each hierarchical level operates semi-independently and aggregates information upward through the hierarchy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Adaptability or versatility

If the system uses aggregated traffic analysis across multiple servers, then volumetric DDoS attacks are detected, but the ability to identify specific targeted servers is reduced

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetailed attack information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent maintains segmented detection capabilities at each hierarchical level, preserving detailed information about individual servers while adding aggregated views. The system can detect volumetric attacks through subnet and datacenter aggregation while still maintaining the ability to identify specific targeted servers by examining individual server metrics within the aggregated context. This segmentation prevents information loss while enhancing detection versatility.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260067310A1System and method for detection of volumetric malicious attacks on datacenter networks
Publication Date: 2026.03.05 OVH
  • US20260067310A1 patent drawing
  • US20260067310A1 patent drawing
  • US20260067310A1 patent drawing

AI summary

A method and system for detecting volumetric malicious threats by iteratively aggregating network flow information of received packet data is presented that includes: analyzing the network flow information of the received packet data; assigning a time interval window, based on the network flow information for time aggregation; determining a corresponding datacenter (DC), based on the network flow destination IP information for DC aggregation; determining a corresponding subnet IP range, based on the network flow destination IP information for subnet aggregation; and determining a transport protocol for corresponding servers of the IP subnet. The packet data size and/or number of packets for the subnet transport protocol and the server transport protocol are updated based on the received packet data. And upon detection that the subnet or server transport protocol updated packet size/number of packets exceed predefined thresholds, issue alerts indicating a potential volumetric malicious threat.