Datacenter Flow Aggregation for Volumetric DDoS Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network analytical techniques struggle to detect volumetric or 'carpet bombing' DDoS attacks, which target multiple servers within a datacenter subnet by saturating network routing devices with limited malicious packet data, making them difficult to identify.
Innovation Solution
A multi-layered aggregation processing architecture that iteratively analyzes network flow information to detect potential threats by assigning time, datacenter, subnet, and server thresholds, issuing alerts when packet data size or number exceeds predefined limits, and incorporating future aggregation for additional IP addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional network analytical techniques are used to monitor network traffic, then the detection of traditional DDoS attacks targeting specific hosts is effective, but the detection of volumetric DDoS attacks targeting multiple servers is difficult
Solution Approach 1:
The patent segments the detection process into multiple hierarchical layers: individual server level, subnet level, and datacenter level. Each layer aggregates traffic metrics from multiple sources, enabling the system to detect volumetric attacks that target multiple servers while maintaining the ability to detect traditional single-host attacks. This segmentation allows the system to adapt to different attack patterns without sacrificing detection precision.
2Reliability
If network monitoring focuses on individual host traffic analysis, then specific DDoS attacks are detected effectively, but volumetric attacks saturating network elements remain undetected
Solution Approach 1:
The patent merges traffic analysis from multiple individual hosts into subnet-level and datacenter-level aggregated views. By combining metrics from numerous servers, the system can detect volumetric attacks that would be invisible at the individual host level. This merging approach maintains reliable detection of traditional attacks while adding the capability to detect large-scale volumetric attacks that saturate network elements.
3Measurement precision
If the system monitors all packet data in real-time across the entire network, then comprehensive threat detection is achieved, but the complexity and resource consumption increase significantly
Solution Approach 1:
The patent divides the network monitoring system into hierarchical segments: individual servers, subnets, and datacenters. Each segment performs localized aggregation and analysis of traffic metrics, reducing the complexity burden on any single component. This segmentation enables comprehensive threat detection across the entire network while keeping individual system elements manageable in complexity.
Solution Approach 2:
The patent introduces hierarchical dimensions to the monitoring system, organizing detection capabilities across multiple levels (server → subnet → datacenter). This dimensional organization allows the system to achieve comprehensive threat detection without linearly increasing complexity, as each hierarchical level operates semi-independently and aggregates information upward through the hierarchy.
4Adaptability or versatility
If the system uses aggregated traffic analysis across multiple servers, then volumetric DDoS attacks are detected, but the ability to identify specific targeted servers is reduced
Solution Approach 1:
The patent maintains segmented detection capabilities at each hierarchical level, preserving detailed information about individual servers while adding aggregated views. The system can detect volumetric attacks through subnet and datacenter aggregation while still maintaining the ability to identify specific targeted servers by examining individual server metrics within the aggregated context. This segmentation prevents information loss while enhancing detection versatility.
Data Source
AI summary
A method and system for detecting volumetric malicious threats by iteratively aggregating network flow information of received packet data is presented that includes: analyzing the network flow information of the received packet data; assigning a time interval window, based on the network flow information for time aggregation; determining a corresponding datacenter (DC), based on the network flow destination IP information for DC aggregation; determining a corresponding subnet IP range, based on the network flow destination IP information for subnet aggregation; and determining a transport protocol for corresponding servers of the IP subnet. The packet data size and/or number of packets for the subnet transport protocol and the server transport protocol are updated based on the received packet data. And upon detection that the subnet or server transport protocol updated packet size/number of packets exceed predefined thresholds, issue alerts indicating a potential volumetric malicious threat.


