Network Traffic Filtering for DoS Alert Precision
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network monitoring systems lack the ability to effectively differentiate between Denial of Service (DoS) attacks and legitimate network traffic, leading to difficulties in identifying and mitigating attacks due to the bursty nature of network traffic.
Innovation Solution
A method and system for monitoring network traffic flow that detects DoS attacks and allows users to filter out legitimate network traffic parameters, generating a second set of data based on user-defined filtering criteria to focus on malicious traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network monitoring systems monitor all network traffic parameters to detect DoS attacks, then detection capability is improved, but the ability to differentiate legitimate traffic from attacks deteriorates due to bursty traffic patterns
Solution Approach 1:
The patent segments network traffic data into distinct categories by implementing a filtering system that separates legitimate traffic from potential DoS attacks. The system divides the monitoring process into multiple stages: initial traffic capture, filtering based on user-defined criteria, and analysis of filtered results. This segmentation allows administrators to focus on suspicious traffic patterns while excluding normal traffic variations.
Solution Approach 2:
The patent implements dynamic filtering criteria that can be adjusted in real-time based on network conditions and administrator requirements. The filtering system is not static but adapts to changing traffic patterns, allowing administrators to modify parameters such as traffic volume thresholds, time windows, and protocol-specific criteria. This dynamic approach enables the system to maintain accurate differentiation between legitimate and malicious traffic even as network conditions evolve.
2Measurement precision
If network administrators analyze detailed network traffic data to identify attacks, then detection accuracy is improved, but the time and complexity of analysis increases
Solution Approach 1:
The patent applies preliminary filtering actions to network traffic data before detailed analysis. By pre-filtering traffic based on user-defined criteria such as traffic volume, protocol type, source/destination addresses, and time patterns, the system eliminates obvious legitimate traffic early in the analysis process. This preliminary action reduces the volume of data requiring in-depth examination, thereby maintaining high detection accuracy while significantly reducing analysis time.
Solution Approach 2:
The patent replaces manual traffic analysis with an automated filtering system. Instead of administrators manually examining detailed traffic data, the system automatically applies filtering criteria, sorts results, and presents filtered traffic information. This mechanical substitution of automated processes for manual analysis maintains accurate attack identification while dramatically reducing the time and effort required for analysis.
3Reliability
If network monitoring systems block all suspicious traffic patterns, then attack mitigation is improved, but legitimate traffic may be blocked causing loss of information
Solution Approach 1:
The patent implements local quality control in traffic filtering by allowing different filtering criteria to be applied to different types of traffic. Instead of applying a single blanket filtering rule, the system enables administrators to define specific criteria for different protocols, sources, destinations, and traffic patterns. This localized approach ensures that filtering actions are precisely targeted at malicious traffic while preserving legitimate traffic that may share some characteristics with attacks.
Solution Approach 2:
The patent incorporates feedback mechanisms where filtering results are monitored and used to refine filtering criteria. The system provides administrators with information about filtered traffic, allowing them to review and adjust criteria to prevent false positives. This feedback loop ensures that attack mitigation remains effective while minimizing blocking of legitimate traffic, as criteria can be continuously optimized based on actual network conditions and administrator feedback.
Data Source
AI summary
A method for monitoring traffic flow in a network is provided. A network monitoring probe monitors one or more network traffic flow parameters to detect a denial of service attack. In response to detecting the denial of service attack, a first set of data representing the denial of service attack alert is displayed. Filtering criteria are received from a user. The filtering criteria include at least one of the network flow parameters identified as legitimate network traffic. A second set of data is generated and displayed based on the filtering criteria.


