DoS Detection System Using Traffic Segmentation and Thresholds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and mitigating Denial of Service (DoS) attacks in distributed networking environments are limited in their ability to effectively detect and reduce the impact of volumetric DoS attacks, which can overwhelm network resources and disrupt service.

Innovation Solution

A method for monitoring and analyzing network traffic data using pre-defined threshold criteria to automatically detect and mitigate DoS attacks by isolating malicious traffic from production, involving actions such as limiting traffic rates, blocking IP addresses, and diverting traffic to a quarantined environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing DoS detection methods are used to monitor network traffic, then detection capability is provided, but the ability to effectively detect and reduce impact of volumetric DoS attacks is limited

Engineering Contradiction:
Improveeffectiveness of DoS attack detection and mitigationVSAvoidcomplexity of detection and mitigation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments network traffic into multiple flow types (new flows, established flows, half-open flows) and applies different detection rules and threshold criteria to each segment. This allows the system to handle volumetric DoS attacks more effectively by针对性地 applying mitigation strategies to specific traffic patterns without overwhelming the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary DoS detection and mitigation system that sits between the network traffic source and destination. This intermediary system analyzes traffic flows, applies threshold criteria, and automatically invokes mitigation techniques (such as routing malicious traffic through scrubbing centers or blocking source IPs) without requiring complex changes to existing network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual monitoring and analysis of network traffic is performed, then detection accuracy can be maintained, but response time is delayed and administrative burden increases

Engineering Contradiction:
Improveresponse speed to DoS attacksVSAvoidtime for manual analysis and intervention
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring threshold criteria and mitigation strategies before attacks occur. When traffic flows exceed predefined thresholds (such as packets per second, bytes per second, or connection rates), the system automatically triggers predetermined mitigation actions without requiring manual analysis or decision-making, enabling immediate response to volumetric DoS attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The DoS detection and mitigation system operates autonomously by automatically monitoring network traffic, analyzing flow characteristics against threshold criteria, detecting attacks, and invoking mitigation techniques without human intervention. The system self-manages the entire process from detection to mitigation, eliminating administrative burden and response delays associated with manual monitoring.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If network traffic is monitored using multiple threshold criteria, then detection accuracy improves, but system complexity and processing overhead increase

Engineering Contradiction:
Improveprecision of DoS attack detectionVSAvoidcomplexity of monitoring system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies different threshold criteria and measurement parameters to different types of network flows based on their local characteristics. For example, new flows may be evaluated against different thresholds than established flows, and different protocols (HTTP, FTP, SMTP) may have protocol-specific threshold criteria. This localized approach improves detection precision while keeping the overall system manageable by applying complexity only where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11895148B2Detection and mitigation of denial of service attacks in distributed networking environments
Publication Date: 2024.02.06 ORACLE INT CORP
  • US11895148B2 patent drawing
  • US11895148B2 patent drawing
  • US11895148B2 patent drawing

AI summary

Techniques for detecting and mitigating Denial of Service (DoS) attacks in distributed networking environment are disclosed. In certain embodiments, a DoS detection and mitigation system is disclosed that automatically monitors and analyzes network traffic data in a distributed networking environment using a set of pre-defined threshold criteria. The system includes capabilities for automatically invoking various mitigation techniques that take actions on malicious traffic based on the analysis and the pre-defined threshold criteria. The system includes capabilities for automatically detecting and mitigating “outbound” DoS attacks by analyzing network traffic data originating from an entity within the network to a public network (e.g., the Internet) outside the network as well as detect and mitigate “east-west” DoS attacks by analyzing network traffic data originating from a first entity located in a first data center of the network to a second entity located in a second data center of the network.