DoS Detection System Using Traffic Segmentation and Thresholds
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting and mitigating Denial of Service (DoS) attacks in distributed networking environments are limited in their ability to effectively detect and reduce the impact of volumetric DoS attacks, which can overwhelm network resources and disrupt service.
Innovation Solution
A method for monitoring and analyzing network traffic data using pre-defined threshold criteria to automatically detect and mitigate DoS attacks by isolating malicious traffic from production, involving actions such as limiting traffic rates, blocking IP addresses, and diverting traffic to a quarantined environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing DoS detection methods are used to monitor network traffic, then detection capability is provided, but the ability to effectively detect and reduce impact of volumetric DoS attacks is limited
Solution Approach 1:
The system segments network traffic into multiple flow types (new flows, established flows, half-open flows) and applies different detection rules and threshold criteria to each segment. This allows the system to handle volumetric DoS attacks more effectively by针对性地 applying mitigation strategies to specific traffic patterns without overwhelming the entire system.
Solution Approach 2:
The patent introduces an intermediary DoS detection and mitigation system that sits between the network traffic source and destination. This intermediary system analyzes traffic flows, applies threshold criteria, and automatically invokes mitigation techniques (such as routing malicious traffic through scrubbing centers or blocking source IPs) without requiring complex changes to existing network infrastructure.
2Productivity
If manual monitoring and analysis of network traffic is performed, then detection accuracy can be maintained, but response time is delayed and administrative burden increases
Solution Approach 1:
The system performs preliminary actions by pre-configuring threshold criteria and mitigation strategies before attacks occur. When traffic flows exceed predefined thresholds (such as packets per second, bytes per second, or connection rates), the system automatically triggers predetermined mitigation actions without requiring manual analysis or decision-making, enabling immediate response to volumetric DoS attacks.
Solution Approach 2:
The DoS detection and mitigation system operates autonomously by automatically monitoring network traffic, analyzing flow characteristics against threshold criteria, detecting attacks, and invoking mitigation techniques without human intervention. The system self-manages the entire process from detection to mitigation, eliminating administrative burden and response delays associated with manual monitoring.
3Measurement precision
If network traffic is monitored using multiple threshold criteria, then detection accuracy improves, but system complexity and processing overhead increase
Solution Approach 1:
The patent applies different threshold criteria and measurement parameters to different types of network flows based on their local characteristics. For example, new flows may be evaluated against different thresholds than established flows, and different protocols (HTTP, FTP, SMTP) may have protocol-specific threshold criteria. This localized approach improves detection precision while keeping the overall system manageable by applying complexity only where needed.
Data Source
AI summary
Techniques for detecting and mitigating Denial of Service (DoS) attacks in distributed networking environment are disclosed. In certain embodiments, a DoS detection and mitigation system is disclosed that automatically monitors and analyzes network traffic data in a distributed networking environment using a set of pre-defined threshold criteria. The system includes capabilities for automatically invoking various mitigation techniques that take actions on malicious traffic based on the analysis and the pre-defined threshold criteria. The system includes capabilities for automatically detecting and mitigating “outbound” DoS attacks by analyzing network traffic data originating from an entity within the network to a public network (e.g., the Internet) outside the network as well as detect and mitigate “east-west” DoS attacks by analyzing network traffic data originating from a first entity located in a first data center of the network to a second entity located in a second data center of the network.


