Network Monitoring Device DoS Detection Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet Service Providers face challenges in detecting and mitigating Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, as the source of these attacks is often difficult to determine due to forged source addresses, and existing detection systems require manual configuration and trial-and-error tuning of threshold settings, especially in high-speed networks with limited resources.

Innovation Solution

A method and system for configuring network monitoring devices that analyze historical network traffic flow information to automatically set threshold values based on identified characteristic metrics, enabling timely detection of DoS and DDoS attacks and reducing the need for manual tuning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual configuration and trial-and-error tuning of threshold settings are used, then detection accuracy can be achieved, but configuration complexity and time consumption increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidconfiguration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically configures threshold settings by analyzing historical network traffic data and identifying characteristic values, eliminating the need for manual configuration and trial-and-error tuning. The monitoring device performs self-configuration based on learned patterns from historical malicious activity data

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-processes historical network traffic flow information to identify characteristic values and establish baseline thresholds before actual DoS detection begins. This preliminary analysis phase prepares the detection system with pre-configured thresholds based on historical patterns, enabling faster and more accurate detection without manual intervention during operation

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manual configuration of threshold settings is performed, then detection specificity can be improved, but time consumption and operational overhead increase

Engineering Contradiction:
Improvedetection specificityVSAvoidconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The monitoring device automatically determines appropriate threshold values by analyzing historical network traffic data and identifying characteristic patterns of malicious activity. This self-configuration process eliminates manual tuning time while maintaining detection specificity through data-driven threshold selection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses historical network traffic flow information as feedback to automatically adjust and configure threshold settings. By learning from past malicious activity patterns stored in the database, the system refines its threshold values to improve detection specificity without requiring manual configuration time

Inventive Principle:
Principle #23Feedback

3Speed

If network monitoring analyzes all traffic in real-time, then detection timeliness is improved, but resource consumption increases

Engineering Contradiction:
Improvedetection speedVSAvoidprocessing resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system pre-analyzes historical network traffic data to establish baseline thresholds and characteristic values before real-time monitoring begins. This preliminary processing phase creates reference patterns that enable faster real-time detection by comparing current traffic against pre-established benchmarks rather than analyzing all traffic from scratch

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts monitoring parameters and threshold values based on historical traffic patterns and identified characteristic values. By changing the parameters of what to monitor and at what thresholds, the system optimizes resource consumption while maintaining detection speed through adaptive parameter selection based on learned traffic characteristics

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10637885B2DoS detection configuration
Publication Date: 2020.04.28 ARBOR NETWORKS INC
  • US10637885B2 patent drawing
  • US10637885B2 patent drawing
  • US10637885B2 patent drawing

AI summary

A method for configuring a network monitoring device is provided. One or more performance metrics associated with one or more thresholds to be configured are received from a user. Historical network traffic flow information associated with a previously detected malicious activity is analyzed to identify characteristic values for the one or more performance metrics. Threshold values are automatically configured based on the identified characteristic values.