Two-Stage DDoS Detection Using SNMP and Netflow Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting Distributed Denial of Service (DDoS) attacks in computer networks are ineffective, particularly in the core network where traffic is high, leading to delayed detection and increased costs due to the need for extensive processing capabilities and resource-intensive fine-grained detection techniques.

Innovation Solution

A two-stage detection framework is implemented at customer provider edge routers, using coarse-grained data for initial anomaly detection via Simple Network Management Protocol (SNMP) and triggering fine-grained analysis with Netflow data only when anomalies are detected, reducing resource consumption and improving detection accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If fine-grained detection techniques are used to detect subtle DDoS attacks, then detection accuracy is improved, but processing cost and resource consumption increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing cost
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the detection process into two distinct stages: a first stage using coarse-grained detection for initial anomaly identification, and a second stage using fine-grained detection for detailed analysis. This segmentation allows the system to apply computationally expensive fine-grained techniques only when necessary, rather than continuously processing all traffic with high-cost methods.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial action by applying fine-grained detection selectively only to traffic flows that trigger anomalies in the coarse-grained stage. Instead of performing exhaustive fine-grained analysis on all network traffic, the system performs detailed analysis only on the subset of traffic that requires it, reducing overall processing cost while maintaining detection accuracy for suspicious flows.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If fine-grained detection techniques are deployed in the core network, then detection capability is improved, but implementation cost and resource requirements increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies different detection qualities to different parts of the network: coarse-grained detection is deployed at core network routers where traffic volume is high, while fine-grained detection is applied at edge routers or monitoring systems where suspicious traffic is identified. This local differentiation allows the system to maintain high detection capability where needed while reducing implementation costs in the core network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary coarse-grained detection layer that mediates between the core network and fine-grained detection. This intermediary stage filters and identifies suspicious traffic patterns, allowing the system to trigger detailed fine-grained analysis only when anomalies are detected, thereby reducing the burden on core network resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If coarse-grained detection is used for DDoS attack detection, then resource consumption is reduced, but detection precision decreases making subtle attacks undetectable

Engineering Contradiction:
Improveresource efficiencyVSAvoiddetection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements a dynamic two-stage detection framework where the detection approach adapts based on traffic conditions. The system starts with resource-efficient coarse-grained detection and dynamically transitions to more resource-intensive fine-grained detection when anomalies are detected. This dynamic adaptation allows the system to maintain high resource efficiency during normal operation while achieving high detection precision when threats are present.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies preliminary coarse-grained detection to identify potential anomalies before triggering detailed fine-grained analysis. This preliminary action filters out normal traffic patterns early, allowing the system to conserve resources while maintaining the capability to detect subtle attacks that would be missed by coarse-grained detection alone.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8001601B2Method and apparatus for large-scale automated distributed denial of service attack detection
Publication Date: 2011.08.16 AT&T INTELLECTUAL PROPERTY II LP
  • US8001601B2 patent drawing
  • US8001601B2 patent drawing
  • US8001601B2 patent drawing

AI summary

A multi-staged framework for detecting and diagnosing Denial of Service attacks is disclosed in which a low-cost anomaly detection mechanism is first used to collect coarse data, such as may be obtained from Simple Network Management Protocol (SNMP) data flows. Such data is analyzed to detect volume anomalies that could possibly be indicative of a DDoS attack. If such an anomaly is suspected, incident reports are then generated and used to trigger the collection and analysis of fine grained data, such as that available in Netflow data flows. Both types of collection and analysis are illustratively conducted at edge routers within the service provider network that interface customers and customer networks to the service provider. Once records of the more detailed information have been retrieved, they are examined to determine whether the anomaly represents a distributed denial of service attack, at which point an alarm is generated.