Endpoint Local Proxy Detection for DDoS Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in securing communications against distributed denial of service (DDoS) attacks, with existing methods failing to effectively identify and remediate compromised endpoints in a timely manner.

Innovation Solution

A system that monitors outbound traffic from endpoints, detects potential trigger events for DDoS attacks, and isolates endpoints with increased network traffic to high-reputation addresses, preventing further traffic until remediation is performed, using a combination of reputation information and network usage history to differentiate between malicious and legitimate activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security methods are used to monitor network traffic, then network security is maintained, but compromised endpoints participating in DDoS attacks cannot be identified and remediated in a timely manner

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidremediation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by detecting potential trigger events for DDoS attacks before the actual attack occurs. The system monitors for suspicious processes and behaviors that indicate an endpoint is about to be compromised or is being used for DDoS activities, allowing security personnel to take preventive measures before the attack escalates, thus reducing remediation time while maintaining security effectiveness

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring network traffic from endpoints and providing real-time information about suspicious activities. When an endpoint exhibits DDoS-related behavior patterns, the system generates alerts and feedback to security systems, enabling rapid response and remediation. This continuous feedback loop improves both detection speed and security effectiveness

Inventive Principle:
Principle #23Feedback

2Measurement precision

If all network traffic is monitored in detail to detect DDoS attacks, then detection accuracy is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by focusing monitoring resources on specific high-risk areas rather than uniformly monitoring all network traffic. The system identifies endpoints with suspicious characteristics or behaviors and applies enhanced monitoring only to those specific locations, improving detection accuracy for DDoS attacks while reducing overall system complexity and processing overhead by avoiding blanket monitoring of all traffic

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces intermediary components such as proxy servers and analysis intermediaries that sit between the network traffic and the monitoring system. These intermediaries pre-process and filter traffic, extracting only the most relevant DDoS indicators before passing them to the analysis system, thereby improving detection accuracy while reducing the complexity of the overall monitoring infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10986109B2Local proxy detection
Publication Date: 2021.04.20 SOPHOS LTD
  • US10986109B2 patent drawing
  • US10986109B2 patent drawing
  • US10986109B2 patent drawing

AI summary

A technique for local proxy detection includes monitoring outbound traffic from the endpoint with remote network addresses outside the enterprise network, detecting use of a secure communication protocol with a request from the endpoint to one of the remote network addresses, identifying a plaintext network address within the request, and in response to identifying a plaintext network address in the request, initiating remediation of a potentially malicious local proxy on the endpoint.