DoS Attack Detection via Traffic and Throughput Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional denial-of-service attack detection systems often incorrectly identify traffic abnormalities that do not affect performance, leading to unnecessary intervention, as they rely solely on traffic abnormality without considering the communication device's throughput.
Innovation Solution
A system comprising a monitoring device for detecting traffic abnormalities, a performance measuring device for measuring throughput abnormalities, and an attack determining device that uses both traffic and performance abnormality information to accurately identify denial-of-service attacks, improving detection precision by considering the relationship between the two.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If only traffic abnormality information is used for attack detection, then the detection speed is fast and the system is simple, but the detection precision is low and incorrect detection increases
Solution Approach 1:
The patent combines traffic abnormality detection with performance abnormality detection into a unified attack determination system. The attack determining device integrates both traffic abnormality information from the monitoring device and performance abnormality information from the performance measuring device to make comprehensive attack determination, thereby improving detection precision while managing system complexity through modular architecture.
Solution Approach 2:
The attack determining device serves as an intermediary that receives and processes both traffic abnormality information and performance abnormality information. It acts as a mediator that correlates these two types of information to determine whether a denial-of-service attack is occurring, enabling precise detection without requiring direct complex interaction between the monitoring device and performance measuring device.
2Reliability
If traffic abnormality detection is performed without considering performance impact, then the detection coverage is wide, but the number of false positives increases
Solution Approach 1:
The patent changes the detection parameters from solely traffic-based metrics to a combination of traffic abnormality metrics and performance abnormality metrics. By introducing performance impact as an additional parameter, the system filters out false positives where traffic anomalies do not actually degrade service performance, thereby improving detection reliability.
3Measurement precision
If performance measuring device is added to the system, then the detection precision is improved, but the system complexity and cost increase
Solution Approach 1:
The patent segments the attack detection system into three functional modules: a monitoring device for traffic abnormality detection, a performance measuring device for performance abnormality detection, and an attack determining device for integrated analysis. This segmentation allows each component to perform its specific function efficiently while maintaining overall system manageability and reducing complexity through clear division of responsibilities.
Data Source
AI summary
A monitoring device monitors a packet transmitted to a communication device that is a target of the denial-of-service attack, and detects traffic abnormality information indicating an abnormality of traffic due to the packet with respect to the communication device. A performance measuring device measures performance of the communication device, and detects performance abnormality information indicating an abnormality of throughput of the communication device. An attack determining device determines whether the communication device received the denial-of-service attack, based on the traffic abnormality information and the performance abnormality information.


