DDoS Threshold Recommendation Engine for Granular Traffic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In complex networks with multiple DDoS attack mitigation appliances, existing methods struggle to accurately set granular thresholds for traffic anomalies due to varying traffic distribution and network failures, leading to potential false positives and inadequate anomaly detection.

Innovation Solution

A DDoS threshold recommendation engine combines traffic rate parameters from multiple appliances, applying a rate multiplier to determine maximum expected packet rates and setting thresholds to avoid false positives, ensuring consistent anomaly detection across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If simple traffic behavior schemes based on past traffic estimation are used, then the system is easy to operate, but it produces false positives in complex network scenarios with multiple appliances and dynamic traffic distribution

Engineering Contradiction:
Improvesimplicity of threshold settingVSAvoidaccuracy of anomaly detection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines traffic rate parameters from multiple DDoS mitigation appliances to establish unified granular thresholds. By merging data from multiple sources (appliances 403 and 404) and applying a rate multiplier, the system creates comprehensive thresholds that account for dynamic traffic distribution across the network, eliminating false positives while maintaining operational simplicity.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If granular thresholds are set for each individual appliance, then the detection precision is high for single appliance scenarios, but false positives occur in multi-appliance networks with varying traffic distribution

Engineering Contradiction:
Improvegranular threshold accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system implements feedback by continuously monitoring traffic rate parameters from multiple appliances and dynamically adjusting granular thresholds based on combined observations. The rate multiplier mechanism provides feedback that accounts for traffic distribution variations, ensuring thresholds remain accurate across different network conditions and appliance configurations.

Inventive Principle:
Principle #23Feedback

3Ease of manufacture

If traffic thresholds are established without considering traffic distribution dynamics, then the system is simple to implement, but it fails to adapt to network failures and traffic switching scenarios

Engineering Contradiction:
Improveimplementation simplicityVSAvoidadaptability to network changes
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic threshold adjustment by continuously monitoring traffic rate parameters from multiple appliances and adapting thresholds based on observed traffic distribution patterns. The rate multiplier mechanism dynamically scales thresholds to account for traffic switching between appliances during failures or load balancing scenarios, maintaining adaptability without complex manual configuration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20230007040A1Recommendation of granular traffic thresholds from multiple sensor appliances
Publication Date: 2023.01.05 FORTINET INC
  • US20230007040A1 patent drawing
  • US20230007040A1 patent drawing
  • US20230007040A1 patent drawing

AI summary

Recommendations are made for granular traffic thresholds for a plurality of DDoS attack mitigation appliances that act as a set appliances. The set of appliances can be those commonly found in highly available networks, active-active or active-passive appliances, disaster recovery data centers, backup appliances, etc.