DDoS Detection via Sensor Grid Signal Amplification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network attack detection systems fail to provide a clear indication of the probability of attack across various network layers due to noise from normal traffic, making it difficult to detect Distributed Denial of Service (DDoS) attacks early enough to mitigate damage.

Innovation Solution

A computer-implemented method that receives signals from a sensor grid indicating the probability of a network attack, combines and amplifies these signals to produce a single indicator of the attack probability across the entire network, allowing for earlier and more reliable detection of network attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple signals from sensor grid are monitored across various network layers, then the ability to detect network attacks is improved, but the noise from normal network traffic increases making it difficult to provide a clear indication of attack probability

Engineering Contradiction:
Improveattack detection capabilityVSAvoidnoise from normal traffic
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent combines multiple signals from different network layers into a single aggregated signal that represents the overall attack probability. This merging process consolidates information from various sensors monitoring different OSI layers (application, transport, network, data link layers) into one unified indicator, reducing the complexity of analyzing multiple separate signals while maintaining comprehensive attack detection capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary processing layer that receives raw signals from the sensor grid, processes them through signal processing algorithms, and generates a refined attack probability indicator. This intermediary layer filters out noise from normal traffic and amplifies relevant attack signals before presenting the final indication to users or automated response systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If signals from multiple network layers are aggregated, then comprehensive attack detection is improved, but the complexity of processing and combining signals increases

Engineering Contradiction:
Improvecomprehensive attack detectionVSAvoidsignal processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the signal processing task into distinct modules: individual sensors monitor specific network layers independently, signals are collected and pre-processed separately, then aggregated into a combined indicator. This segmentation allows each component to operate independently with well-defined interfaces, reducing overall system complexity while achieving comprehensive multi-layer attack detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs a universal signal processing framework that can handle multiple types of signals from different network layers through a common aggregation and analysis mechanism. This multi-functional approach uses the same processing pipeline for various signal types, reducing the need for layer-specific complex processing logic and simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9060021B2DDoS detection using sensor grid
Publication Date: 2015.06.16 BANK OF AMERICA CORP
  • US9060021B2 patent drawing
  • US9060021B2 patent drawing
  • US9060021B2 patent drawing

AI summary

Methods and apparatus for detecting a network attack are disclosed. A sensor grid may be established in a network (e.g., an enterprise network). The sensors may monitor network assets across various network layers and transmit to a server signals that indicate the probability of an attack on the network. The server may apply an amplification algorithm to combine and amplify all of the received signals into a single signal that more accurately displays the probability of an attack on the network.