Network Traffic Filtering for DoS Alert Precision

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network monitoring systems lack the ability to effectively differentiate between Denial of Service (DoS) attacks and legitimate network traffic, leading to difficulties in identifying and mitigating attacks due to the bursty nature of network traffic.

Innovation Solution

A method and system for monitoring network traffic flow that detects DoS attacks and allows users to filter out legitimate network traffic parameters, generating a second set of data based on user-defined filtering criteria to focus on malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network monitoring systems monitor all network traffic parameters to detect DoS attacks, then detection capability is improved, but the ability to differentiate legitimate traffic from attacks deteriorates due to bursty traffic patterns

Engineering Contradiction:
ImproveDoS attack detection capabilityVSAvoidDifferentiation between legitimate traffic and attacks
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments network traffic data into distinct categories by implementing a filtering system that separates legitimate traffic from potential DoS attacks. The system divides the monitoring process into multiple stages: initial traffic capture, filtering based on user-defined criteria, and analysis of filtered results. This segmentation allows administrators to focus on suspicious traffic patterns while excluding normal traffic variations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic filtering criteria that can be adjusted in real-time based on network conditions and administrator requirements. The filtering system is not static but adapts to changing traffic patterns, allowing administrators to modify parameters such as traffic volume thresholds, time windows, and protocol-specific criteria. This dynamic approach enables the system to maintain accurate differentiation between legitimate and malicious traffic even as network conditions evolve.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If network administrators analyze detailed network traffic data to identify attacks, then detection accuracy is improved, but the time and complexity of analysis increases

Engineering Contradiction:
ImproveAttack identification accuracyVSAvoidAnalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary filtering actions to network traffic data before detailed analysis. By pre-filtering traffic based on user-defined criteria such as traffic volume, protocol type, source/destination addresses, and time patterns, the system eliminates obvious legitimate traffic early in the analysis process. This preliminary action reduces the volume of data requiring in-depth examination, thereby maintaining high detection accuracy while significantly reducing analysis time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual traffic analysis with an automated filtering system. Instead of administrators manually examining detailed traffic data, the system automatically applies filtering criteria, sorts results, and presents filtered traffic information. This mechanical substitution of automated processes for manual analysis maintains accurate attack identification while dramatically reducing the time and effort required for analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If network monitoring systems block all suspicious traffic patterns, then attack mitigation is improved, but legitimate traffic may be blocked causing loss of information

Engineering Contradiction:
ImproveAttack mitigation effectivenessVSAvoidLegitimate traffic blocking
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements local quality control in traffic filtering by allowing different filtering criteria to be applied to different types of traffic. Instead of applying a single blanket filtering rule, the system enables administrators to define specific criteria for different protocols, sources, destinations, and traffic patterns. This localized approach ensures that filtering actions are precisely targeted at malicious traffic while preserving legitimate traffic that may share some characteristics with attacks.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent incorporates feedback mechanisms where filtering results are monitored and used to refine filtering criteria. The system provides administrators with information about filtered traffic, allowing them to review and adjust criteria to prevent false positives. This feedback loop ensures that attack mitigation remains effective while minimizing blocking of legitimate traffic, as criteria can be continuously optimized based on actual network conditions and administrator feedback.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9961106B2Filtering legitimate traffic elements from a DoS alert
Publication Date: 2018.05.01 ARBOR NETWORKS INC
  • US9961106B2 patent drawing
  • US9961106B2 patent drawing
  • US9961106B2 patent drawing

AI summary

A method for monitoring traffic flow in a network is provided. A network monitoring probe monitors one or more network traffic flow parameters to detect a denial of service attack. In response to detecting the denial of service attack, a first set of data representing the denial of service attack alert is displayed. Filtering criteria are received from a user. The filtering criteria include at least one of the network flow parameters identified as legitimate network traffic. A second set of data is generated and displayed based on the filtering criteria.