Two-Stage DDoS Detection Using SNMP and Netflow Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting Distributed Denial of Service (DDoS) attacks in computer networks are ineffective, particularly in the core network where traffic is high, leading to delayed detection and increased costs due to the need for extensive processing capabilities and resource-intensive fine-grained detection techniques.
Innovation Solution
A two-stage detection framework is implemented at customer provider edge routers, using coarse-grained data for initial anomaly detection via Simple Network Management Protocol (SNMP) and triggering fine-grained analysis with Netflow data only when anomalies are detected, reducing resource consumption and improving detection accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If fine-grained detection techniques are used to detect subtle DDoS attacks, then detection accuracy is improved, but processing cost and resource consumption increase significantly
Solution Approach 1:
The patent divides the detection process into two distinct stages: a first stage using coarse-grained detection for initial anomaly identification, and a second stage using fine-grained detection for detailed analysis. This segmentation allows the system to apply computationally expensive fine-grained techniques only when necessary, rather than continuously processing all traffic with high-cost methods.
Solution Approach 2:
The patent implements partial action by applying fine-grained detection selectively only to traffic flows that trigger anomalies in the coarse-grained stage. Instead of performing exhaustive fine-grained analysis on all network traffic, the system performs detailed analysis only on the subset of traffic that requires it, reducing overall processing cost while maintaining detection accuracy for suspicious flows.
2Reliability
If fine-grained detection techniques are deployed in the core network, then detection capability is improved, but implementation cost and resource requirements increase
Solution Approach 1:
The patent applies different detection qualities to different parts of the network: coarse-grained detection is deployed at core network routers where traffic volume is high, while fine-grained detection is applied at edge routers or monitoring systems where suspicious traffic is identified. This local differentiation allows the system to maintain high detection capability where needed while reducing implementation costs in the core network.
Solution Approach 2:
The patent introduces an intermediary coarse-grained detection layer that mediates between the core network and fine-grained detection. This intermediary stage filters and identifies suspicious traffic patterns, allowing the system to trigger detailed fine-grained analysis only when anomalies are detected, thereby reducing the burden on core network resources.
3Productivity
If coarse-grained detection is used for DDoS attack detection, then resource consumption is reduced, but detection precision decreases making subtle attacks undetectable
Solution Approach 1:
The patent implements a dynamic two-stage detection framework where the detection approach adapts based on traffic conditions. The system starts with resource-efficient coarse-grained detection and dynamically transitions to more resource-intensive fine-grained detection when anomalies are detected. This dynamic adaptation allows the system to maintain high resource efficiency during normal operation while achieving high detection precision when threats are present.
Solution Approach 2:
The patent applies preliminary coarse-grained detection to identify potential anomalies before triggering detailed fine-grained analysis. This preliminary action filters out normal traffic patterns early, allowing the system to conserve resources while maintaining the capability to detect subtle attacks that would be missed by coarse-grained detection alone.
Data Source
AI summary
A multi-staged framework for detecting and diagnosing Denial of Service attacks is disclosed in which a low-cost anomaly detection mechanism is first used to collect coarse data, such as may be obtained from Simple Network Management Protocol (SNMP) data flows. Such data is analyzed to detect volume anomalies that could possibly be indicative of a DDoS attack. If such an anomaly is suspected, incident reports are then generated and used to trigger the collection and analysis of fine grained data, such as that available in Netflow data flows. Both types of collection and analysis are illustratively conducted at edge routers within the service provider network that interface customers and customer networks to the service provider. Once records of the more detailed information have been retrieved, they are examined to determine whether the anomaly represents a distributed denial of service attack, at which point an alarm is generated.


