DDoS Detection via Sensor Grid Signal Amplification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network attack detection systems fail to provide a clear indication of the probability of attack across various network layers due to noise from normal traffic, making it difficult to detect Distributed Denial of Service (DDoS) attacks early enough to mitigate damage.
Innovation Solution
A computer-implemented method that receives signals from a sensor grid indicating the probability of a network attack, combines and amplifies these signals to produce a single indicator of the attack probability across the entire network, allowing for earlier and more reliable detection of network attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple signals from sensor grid are monitored across various network layers, then the ability to detect network attacks is improved, but the noise from normal network traffic increases making it difficult to provide a clear indication of attack probability
Solution Approach 1:
The patent combines multiple signals from different network layers into a single aggregated signal that represents the overall attack probability. This merging process consolidates information from various sensors monitoring different OSI layers (application, transport, network, data link layers) into one unified indicator, reducing the complexity of analyzing multiple separate signals while maintaining comprehensive attack detection capability.
Solution Approach 2:
The patent introduces an intermediary processing layer that receives raw signals from the sensor grid, processes them through signal processing algorithms, and generates a refined attack probability indicator. This intermediary layer filters out noise from normal traffic and amplifies relevant attack signals before presenting the final indication to users or automated response systems.
2Reliability
If signals from multiple network layers are aggregated, then comprehensive attack detection is improved, but the complexity of processing and combining signals increases
Solution Approach 1:
The patent segments the signal processing task into distinct modules: individual sensors monitor specific network layers independently, signals are collected and pre-processed separately, then aggregated into a combined indicator. This segmentation allows each component to operate independently with well-defined interfaces, reducing overall system complexity while achieving comprehensive multi-layer attack detection.
Solution Approach 2:
The patent employs a universal signal processing framework that can handle multiple types of signals from different network layers through a common aggregation and analysis mechanism. This multi-functional approach uses the same processing pipeline for various signal types, reducing the need for layer-specific complex processing logic and simplifying the overall system architecture.
Data Source
AI summary
Methods and apparatus for detecting a network attack are disclosed. A sensor grid may be established in a network (e.g., an enterprise network). The sensors may monitor network assets across various network layers and transmit to a server signals that indicate the probability of an attack on the network. The server may apply an amplification algorithm to combine and amplify all of the received signals into a single signal that more accurately displays the probability of an attack on the network.


