Out-of-Path DDoS Detection via Enriched Flow Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DDoS attack detection methods, particularly out-of-path (OOP) techniques, face inefficiencies and inaccuracies due to reliance on Flow data alone, leading to high false positives and negatives, and struggle to accurately identify entities and correlate attack traffic with network topology, limiting effective detection and mitigation in large-scale networks.

Innovation Solution

The proposed solution involves enriching Flow data with additional types of data from various sources, using machine learning techniques to analyze and categorize traffic patterns, and deploying an OOP detector that can dynamically create clusters of entities based on traffic behavior, enabling more accurate anomaly detection and entity-aware DDoS attack identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If out-of-path detection is used instead of inline detection, then deployment convenience is improved, but detection accuracy and response speed deteriorate

Engineering Contradiction:
Improvedeployment convenienceVSAvoiddetection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent combines multiple data sources (Flow data, NetFlow, telemetry data, entity identity information) into a unified detection framework. By merging these diverse data streams and enriching them with entity context, the system achieves both out-of-path deployment convenience and inline-level detection accuracy, resolving the contradiction between ease of operation and measurement precision.

Inventive Principle:
Principle #5Merging (Combining)

2Device complexity

If Flow data only is used for detection, then data processing simplicity is improved, but detection accuracy deteriorates due to high false positives and negatives

Engineering Contradiction:
Improvedata processing simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent segments the detection process into multiple independent modules: Flow data collection, telemetry data collection, entity identity resolution, enrichment processing, and anomaly detection. Each module handles a specific aspect independently, maintaining processing simplicity while collectively achieving high detection accuracy through multi-dimensional analysis.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If manual threshold configuration is used, then detection rule simplicity is improved, but detection accuracy deteriorates due to excessive false positives and negatives

Engineering Contradiction:
Improvedetection rule simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system implements feedback mechanisms where detection results and traffic patterns continuously inform threshold adjustments. Machine learning models analyze historical data and automatically optimize detection thresholds, providing both simplicity (automatic adjustment) and high accuracy (data-driven optimization) simultaneously.

Inventive Principle:
Principle #23Feedback

4Device complexity

If IP address based telemetry is used for anomaly detection, then data collection simplicity is improved, but entity identification accuracy deteriorates

Engineering Contradiction:
Improvedata collection simplicityVSAvoidentity identification accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent introduces entity identity resolution as an intermediary layer between IP address telemetry and anomaly detection. This mediator resolves IP addresses to actual entity identities using multiple data sources, maintaining simple data collection while dramatically improving entity identification accuracy by bridging the gap between network addresses and real-world entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

5Reliability

If existing anomaly detection solutions are applied to large-scale networks, then scalability is challenged, but detection coverage is improved

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent adds the entity identity dimension to traditional IP-based detection. By enriching Flow data with entity context (organizing principle, application, device type), the system transforms the detection space from simple IP addresses to multi-dimensional entity profiles. This enables scalable detection in large networks by providing meaningful aggregation and correlation capabilities across hundreds of thousands of IPs.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11632391B2System and method for out of path DDoS attack detection
Publication Date: 2023.04.18 RADWARE LTD
  • US11632391B2 patent drawing
  • US11632391B2 patent drawing
  • US11632391B2 patent drawing

AI summary

A system and method for out-of-path detection of cyber-attacks are provided. The method includes receiving, by a detector, a plurality of data feeds from a plurality of data sources, wherein the detector is communicatively connected to the plurality of data sources; processing, by the detector, the plurality of received data feeds to generate enriched Flow data sets; analyzing the enriched Flow data sets to detect a potential cyber-attack; and upon detection of a potential cyber-attack, providing indication to each network entity of the network entities that is under attack.