DDoS Detection Controller Using Bandwidth Baseline Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies face challenges in effectively detecting and mitigating distributed denial-of-service (DDoS) attacks in broadband networks, as they often result in significant delays and inadequate response times, leading to network congestion and service disruptions.
Innovation Solution
The implementation of artificial intelligence/machine learning (AI/ML) techniques to monitor bandwidth usage across peering entry points, compare assigned and actual bandwidth, and initiate remedial actions, such as blocking malicious traffic, to rapidly identify and mitigate DDoS attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If traditional DDoS detection methods are used, then detection capability is provided, but response time is delayed and network congestion occurs
Solution Approach 1:
The system pre-calculates and stores baseline bandwidth metrics for each customer under normal conditions. When monitoring actual bandwidth usage, it immediately compares against these pre-established baselines, enabling detection within milliseconds rather than requiring complex real-time analysis, thus resolving the contradiction between fast response time and reliable service availability
Solution Approach 2:
The patent replaces traditional mechanical threshold-based detection with AI/ML-based anomaly detection that continuously learns normal traffic patterns. This substitution enables the system to distinguish legitimate high bandwidth usage from actual DDoS attacks more accurately and rapidly, improving both response time and service reliability by reducing false positives and negatives
2Measurement precision
If bandwidth monitoring is implemented to detect DDoS attacks, then detection accuracy improves, but system complexity increases
Solution Approach 1:
The system automatically collects bandwidth data from network elements, compares it against baselines, detects anomalies, and triggers remediation actions without human intervention. This self-service automation maintains high detection accuracy while reducing operational complexity by eliminating manual monitoring and response procedures
Solution Approach 2:
The patent introduces an intermediary controller that sits between network monitoring elements and remediation systems. This controller aggregates data from multiple sources, performs centralized AI/ML analysis, and coordinates responses, thereby simplifying the overall system architecture while maintaining high detection accuracy through sophisticated analysis
3Reliability
If remedial actions are initiated rapidly, then service availability is maintained, but false positives may block legitimate traffic
Solution Approach 1:
The system continuously monitors bandwidth usage and compares actual traffic patterns against AI/ML-predicted normal behavior. When anomalies are detected, remedial actions are triggered, and the system continuously feedbacks on the effectiveness of these actions, adjusting its detection thresholds and models to reduce false positives while maintaining service availability
Solution Approach 2:
The patent implements dynamic threshold adjustment where detection sensitivity and remediation triggers are continuously adapted based on learned normal traffic patterns, time of day, day of week, and historical behavior. This dynamic approach enables rapid response to actual attacks while accommodating legitimate variations in traffic patterns, thereby maintaining service availability without excessive false positives
Data Source
AI summary
Obtain, by a controller, from at least one provisioning database of an internet service provider, assigned bandwidth per customer for a plurality of internet service provider customers. Obtain, by the controller, from a plurality of peering entry points of the internet service provider, currently used bandwidth per customer for the plurality of internet service provider customers. Compare, by the controller, for the plurality of internet service provider customers, the assigned bandwidth per customer to the currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack. Initiate at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack.


