DDoS Detection via Inbound Outbound Traffic Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems are unable to automatically detect and mitigate Distributed Denial of Service (DDoS) Reflection/Amplification attacks without human intervention, leading to delayed response times and prolonged service outages due to the inability to categorize novel amplification protocols effectively.

Innovation Solution

A system and method that intercepts and correlates inbound and outbound traffic packets to create separate data repositories for packet count and byte length analysis, automatically detecting DDoS attacks by comparing inbound and outbound traffic statistics to identify novel Reflection/Amplification attack vectors and trigger mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current attack detection systems detect novel amplification protocols, then the attack can be identified, but automatic blocking cannot be performed without human intervention

Engineering Contradiction:
Improveattack detection accuracyVSAvoidautomatic mitigation capability
Core Design Contradiction:
Measurement precisionVSExtent of automation

Solution Approach 1:

The system performs self-diagnosis and self-mitigation by automatically analyzing traffic patterns, identifying DDoS attacks, and blocking malicious traffic without requiring human intervention. The mitigation device autonomously categorizes novel amplification protocols and implements blocking rules based on correlated traffic statistics from inbound and outbound packets.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback loop by continuously monitoring inbound and outbound traffic, comparing packet counts and byte lengths, detecting anomalies that indicate DDoS attacks, and automatically adjusting blocking rules. The correlated traffic analysis provides real-time feedback that enables dynamic mitigation decisions.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual reconfiguration is required to mitigate detected attacks, then accurate detection can be achieved, but response time is significantly delayed

Engineering Contradiction:
Improveattack detection accuracyVSAvoidmitigation response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing traffic baseline profiles through correlated analysis of inbound and outbound packets during normal operation. When attacks occur, the system compares current traffic against pre-established baselines and immediately implements mitigation, eliminating the need for manual analysis and configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mitigation device autonomously performs the complete mitigation workflow including detection, analysis, decision-making, and rule generation without human intervention. The system self-configures blocking rules based on correlated traffic statistics, enabling immediate response to DDoS attacks.

Inventive Principle:
Principle #25Self-service

3Reliability

If human intervention is required for mitigation deployment, then precise attack categorization can be achieved, but networks remain out of service for prolonged periods

Engineering Contradiction:
Improveattack mitigation accuracyVSAvoidservice outage duration
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The system autonomously categorizes attacks by analyzing correlated traffic patterns from inbound and outbound packets, automatically identifying DDoS characteristics and generating appropriate blocking rules without human intervention, thereby maintaining service continuity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system ensures continuous protection by maintaining constant monitoring of traffic correlations and automatically sustaining mitigation actions. The correlated traffic analysis operates continuously, enabling uninterrupted detection and response to DDoS attacks without service interruptions.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12166791B2Detecting DDOS attacks by correlating inbound and outbound network traffic information
Publication Date: 2024.12.10 ARBOR NETWORKS INC
  • US12166791B2 patent drawing
  • US12166791B2 patent drawing
  • US12166791B2 patent drawing

AI summary

A computer system and process for mitigating a Distributed Denial of Service (DDoS) attack by analyzing and correlating inbound and outbound packet information relative to the one or more protected computer networks for detecting novel DDoS Reflection/Amplification attack vectors. Created are separate data repositories that respectively store information relating to captured inbound and outbound packets flowing to and from the protected computer networks. Stored in each respective inbound and outbound data repository are identified inbound destination ports respectively associated with the captured inbound and outbound packets such that each identified inbound destination port number is associated with 1) a packet count relating to the inbound and outbound packets; and 2) a packet byte length count relating to each of the inbound and outbound packets. By accessing the inbound and outbound data repositories, a determination is made as to whether a total inbound packet count for a first inbound destination port is substantially the same to a total outbound packet count for a same inbound destination port. A next determination is then made as to whether a total outbound packet byte length count for the first inbound destination port exceeds a total inbound packet byte length count for the same inbound destination port. DDoS attack mitigation is automatically performed for the protected computer networks responsive to preferably determining 1) the total inbound packet count for a first inbound destination port is substantially the same to a total outbound packet count for a same inbound destination port; and 2) the total outbound packet byte length count exceeds a ratio value relative to the total inbound packet byte length count for the same inbound destination port.