Distributed Nodes Mitigating DDoS Attacks via Traffic Segregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for mitigating Distributed Denial of Service (DDoS) attacks are costly to maintain and compromise network security, lacking an effective and inexpensive solution for protecting each node in the network.
Innovation Solution
A system of nodes that exchange information, determine reconstruction errors, and segregate genuine traffic from anomalous traffic using AI techniques to select and generate attack patterns, updating patterns to differentiate between legitimate and malicious traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If commonly used systems and methods for monitoring and mitigation of DDoS attacks are implemented, then network security is improved, but maintenance cost increases
Solution Approach 1:
The system enables nodes to autonomously detect, analyze, and respond to DDoS attacks without requiring external security services. Each node independently monitors its own traffic patterns, identifies anomalies using the developed framework, and implements mitigation measures, thereby eliminating dependency on costly external security providers while maintaining robust network security
Solution Approach 2:
The patent creates a simplified model of normal traffic patterns that can be replicated and compared against actual traffic. This copying approach allows the system to identify deviations indicating attacks without requiring complex, expensive security infrastructure, achieving effective security through pattern replication and comparison
2Reliability
If commonly used systems and methods for monitoring and mitigation of DDoS attacks are implemented, then network security is improved, but system complexity increases
Solution Approach 1:
The system divides the DDoS mitigation task into discrete, manageable components: traffic monitoring, pattern recognition, anomaly detection, and response execution. Each node independently performs these segmented functions, avoiding the need for complex centralized systems while maintaining effective security through distributed, modular operations
Solution Approach 2:
The patent transforms the complex problem of DDoS detection into parameter-based analysis by monitoring specific traffic characteristics such as request rates, packet sizes, and temporal patterns. This parameter-focused approach simplifies the system architecture compared to comprehensive security suites, enabling effective attack detection through targeted parameter monitoring and comparison
3Ease of manufacture
If traditional traffic analysis methods are used, then implementation cost is reduced, but accuracy in identifying malicious traffic deteriorates
Solution Approach 1:
The system performs preliminary analysis of traffic patterns during normal operation to establish baseline behavior for each node. This pre-characterization of legitimate traffic enables more accurate real-time detection of anomalies without requiring expensive, complex analysis tools during attack events, achieving high detection accuracy through advance preparation
Solution Approach 2:
The patent implements a feedback mechanism where detected anomalies and confirmed attacks are fed back into the system to refine traffic patterns and improve future detection accuracy. This continuous learning approach enhances measurement precision over time using simple, low-cost computational methods, eliminating the need for expensive proprietary analysis systems
Data Source
AI summary
Disclosed is a system (100) comprising a plurality of nodes (102) configured to (i) exchange node information with one another, (ii) determine a reconstruction error from the node information associated with each node, and (iii) determine a set of traffic anomalies for a first set of nodes (102a) of the plurality of nodes (102) having the reconstruction error higher than a first threshold value, a second set of nodes (102a) are configured to (i) select a predetermined attack pattern from a set of predetermined attack patterns for each traffic anomaly having a similarity score higher than a second threshold value, (ii) generate an new attack pattern for each traffic anomaly having the similarity score less than the second threshold value, and (iii) segregate genuine traffic from overall traffic at the first set of nodes (102a) using one of, the set of predetermined attack patterns and the new attack pattern.


