DDoS Detection via Pre-computed Traffic Variation Curves
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DDoS attack detection methods require heavy computation to calculate predicted traffic at each detection moment, leading to increased calculation loads and potential false alarms.
Innovation Solution
A method and apparatus that utilize a pre-acquired traffic cyclic variation curve to determine predicted traffic patterns, allowing for efficient DDoS attack detection by sampling network traffic and comparing it against the cyclic variation curve, reducing the need for extensive historical data calculations and minimizing false alarms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If predicted traffic is calculated using interval estimation algorithm or cumulative variable algorithm applied to historical network traffic, then detection accuracy is improved, but calculation load increases significantly
Solution Approach 1:
The patent pre-calculates and stores traffic variation curves during off-peak periods when computational resources are abundant. These pre-computed curves capture historical traffic patterns and are stored for rapid retrieval during peak detection periods, eliminating the need for real-time complex calculations and significantly reducing online computational load while maintaining detection accuracy
Solution Approach 2:
Instead of performing complex interval estimation or cumulative variable calculations on actual historical traffic data during detection, the patent creates simplified copy representations in the form of traffic variation curves. These curves capture the essential traffic patterns and are used as substitutes for the full historical data, reducing calculation complexity while preserving detection effectiveness
2Measurement precision
If complex algorithms are applied to historical traffic data for each detection, then detection precision is improved, but detection time increases
Solution Approach 1:
Traffic variation curves are pre-computed during off-peak periods when time is not critical, capturing historical traffic patterns in advance. During actual detection operations, the pre-computed curves are quickly retrieved and compared against current traffic, dramatically reducing detection time while maintaining precision through the use of these pre-analyzed patterns
3Productivity
If traditional threshold-based detection is used without considering traffic patterns, then detection speed is improved, but false alarm rate increases
Solution Approach 1:
The patent replaces static threshold values with dynamic traffic variation curves that adapt to changing traffic patterns. The curves are continuously updated to reflect current traffic behavior, allowing the detection system to dynamically adjust what constitutes abnormal traffic. This maintains high detection speed through efficient curve comparison while reducing false alarms by accommodating legitimate traffic variations
Solution Approach 2:
The system continuously monitors actual traffic against the variation curves and uses this feedback to refine and update the curves over time. This feedback mechanism allows the system to learn from past traffic patterns and adjust its expectations, maintaining low false alarm rates while preserving fast detection capabilities through the use of updated baseline patterns
Data Source
AI summary
Provided are a DDoS attack detection method and apparatus. The method comprises: acquiring network traffic of a target moment within a first period by sampling, then querying a traffic period change curve acquired in advance, determining predicted traffic corresponding to the target moment, and confirming a DDoS attack if the network traffic acquired by sampling is larger than the determined predicted traffic. The traffic period change curve is used for indicating a period change law of the predicted traffic, so that before DDoS attack detection is performed at each target moment, it only needs to determine the predicted traffic corresponding to the target moment according to the traffic period change curve without calculating the predicted traffic according to massive historical traffic data before each DDoS attack detection; and the calculation volume is reduced.

