DoS Attack Management Node Mimics Target Behavior

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting and mitigating Denial of Service (DoS) attacks in computer networks, particularly in Low Power and Lossy Networks (LLNs), is challenging due to the difficulty in distinguishing between legitimate and malicious traffic, especially when network resources are limited, and existing methods struggle to simulate the success of an attack without affecting the targeted resources.

Innovation Solution

A network architecture that includes a DoS attack management node and a trap server or proxy, which determines the type and target of the DoS attack and triggers an attack mimicking action to mimic the behavior of the intended target, making the attacker believe the attack was successful without affecting the resources, using machine learning and traffic flagging mechanisms to redirect and manage attack traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If attack traffic is blocked or dropped to mitigate DoS attack, then network resources are protected, but the attacker can detect the attack and adjust their strategy

Engineering Contradiction:
Improvenetwork resource protectionVSAvoidattack detection and adaptation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a copy of the intended target (a trap server or proxy that mimics the target's behavior) to deceive the attacker. Instead of directly blocking attack traffic, the system redirects it to a copy that replicates the target's response patterns, making the attacker believe the real target is under attack while actually protecting it

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary component (the DoS attack management node and trap server) between the attacker and the real target. This intermediary absorbs and handles the malicious traffic, preventing it from reaching the actual target while maintaining the illusion of a successful attack for the attacker

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If machine learning is used to distinguish legitimate from malicious traffic, then attack detection accuracy is improved, but network processing overhead increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidnetwork processing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary classification of traffic at the network edge using lightweight mechanisms before applying more complex machine learning analysis. The DoS attack management node pre-identifies suspicious traffic patterns and redirects them to trap servers, reducing the volume of traffic that requires intensive processing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the traffic handling process into different stages: initial filtering at the edge, redirection to trap servers for suspected attack traffic, and machine learning analysis only for ambiguous cases. This segmentation allows the system to apply computational resources selectively rather than processing all traffic uniformly

Inventive Principle:
Principle #1Segmentation

3Reliability

If attack traffic is redirected to a trap server, then the real target is protected, but additional network infrastructure is required

Engineering Contradiction:
Improvetarget protectionVSAvoidnetwork infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the trap server to serve multiple functions: it mimics the target's behavior to deceive attackers, absorbs malicious traffic to protect the real target, and provides data for machine learning model training. This multi-functionality reduces the need for separate specialized components for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9497215B2Stealth mitigation for simulating the success of an attack
Publication Date: 2016.11.15 CISCO TECHNOLOGY INC
  • US9497215B2 patent drawing
  • US9497215B2 patent drawing
  • US9497215B2 patent drawing

AI summary

In one embodiment, attack traffic corresponding to a detected DoS attack from one or more attacker nodes is received at a denial of service (DoS) attack management node in a network. The DoS attack management node determines attack information relating to the attack traffic, including a type of the DoS attack and an intended target of the DoS attack. Then, the DoS attack management node triggers an attack mimicking action based on the attack information, where the attack mimicking action mimics a behavior of the intended target of the DoS attack that would be expected by the one or more attacker nodes if the DoS attack were successful.