Distributed Nodes Mitigating DDoS Attacks via Traffic Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for mitigating Distributed Denial of Service (DDoS) attacks are costly to maintain and compromise network security, lacking an effective and inexpensive solution for protecting each node in the network.

Innovation Solution

A system of nodes that exchange information, determine reconstruction errors, and segregate genuine traffic from anomalous traffic using AI techniques to select and generate attack patterns, updating patterns to differentiate between legitimate and malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If commonly used systems and methods for monitoring and mitigation of DDoS attacks are implemented, then network security is improved, but maintenance cost increases

Engineering Contradiction:
Improvenetwork securityVSAvoidmaintenance cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system enables nodes to autonomously detect, analyze, and respond to DDoS attacks without requiring external security services. Each node independently monitors its own traffic patterns, identifies anomalies using the developed framework, and implements mitigation measures, thereby eliminating dependency on costly external security providers while maintaining robust network security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a simplified model of normal traffic patterns that can be replicated and compared against actual traffic. This copying approach allows the system to identify deviations indicating attacks without requiring complex, expensive security infrastructure, achieving effective security through pattern replication and comparison

Inventive Principle:
Principle #26Copying

2Reliability

If commonly used systems and methods for monitoring and mitigation of DDoS attacks are implemented, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the DDoS mitigation task into discrete, manageable components: traffic monitoring, pattern recognition, anomaly detection, and response execution. Each node independently performs these segmented functions, avoiding the need for complex centralized systems while maintaining effective security through distributed, modular operations

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms the complex problem of DDoS detection into parameter-based analysis by monitoring specific traffic characteristics such as request rates, packet sizes, and temporal patterns. This parameter-focused approach simplifies the system architecture compared to comprehensive security suites, enabling effective attack detection through targeted parameter monitoring and comparison

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If traditional traffic analysis methods are used, then implementation cost is reduced, but accuracy in identifying malicious traffic deteriorates

Engineering Contradiction:
Improveimplementation costVSAvoidtraffic anomaly detection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The system performs preliminary analysis of traffic patterns during normal operation to establish baseline behavior for each node. This pre-characterization of legitimate traffic enables more accurate real-time detection of anomalies without requiring expensive, complex analysis tools during attack events, achieving high detection accuracy through advance preparation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where detected anomalies and confirmed attacks are fed back into the system to refine traffic patterns and improve future detection accuracy. This continuous learning approach enhances measurement precision over time using simple, low-cost computational methods, eliminating the need for expensive proprietary analysis systems

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240259421A1SYSTEM AND METHOD TO MITIGATE DISTRIBUTED DENIAL OF SERVICE (DDoS) ATTACKS
Publication Date: 2024.08.01 SHARMA NAVEEN KUMAR
  • US20240259421A1 patent drawing
  • US20240259421A1 patent drawing
  • US20240259421A1 patent drawing

AI summary

Disclosed is a system (100) comprising a plurality of nodes (102) configured to (i) exchange node information with one another, (ii) determine a reconstruction error from the node information associated with each node, and (iii) determine a set of traffic anomalies for a first set of nodes (102a) of the plurality of nodes (102) having the reconstruction error higher than a first threshold value, a second set of nodes (102a) are configured to (i) select a predetermined attack pattern from a set of predetermined attack patterns for each traffic anomaly having a similarity score higher than a second threshold value, (ii) generate an new attack pattern for each traffic anomaly having the similarity score less than the second threshold value, and (iii) segregate genuine traffic from overall traffic at the first set of nodes (102a) using one of, the set of predetermined attack patterns and the new attack pattern.