Flow State Value Tracking for Zero-Day Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network traffic analyzers are unable to detect 'zero-day' attacks effectively and are costly due to their reliance on previously observed signatures for anomaly detection, and they consume significant power and resources at high data rates.
Innovation Solution
A processor-readable medium that updates flow state values associated with data flows based on received packets or time expiration, using independently operating logic modules to identify anomalies without deep packet inspection, allowing for the detection of network anomalies like denial of service attacks without relying on pre-defined signatures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If known network traffic analyzers rely on previously-observed signatures to detect data flow anomalies, then detection capability for known attacks is improved, but detection capability for zero-day attacks deteriorates
Solution Approach 1:
The patent pre-calculates and stores flow state values that represent characteristic patterns of anomalous data flows before actual attacks occur. These pre-computed flow state values serve as reference signatures that enable detection of both known and unknown attacks by comparing actual flow states against the pre-prepared reference set, eliminating the need for post-attack signature development
Solution Approach 2:
The patent transforms packet flow data into flow state values through parameter transformation and aggregation. By converting raw packet characteristics into condensed flow state parameters and comparing these against pre-computed reference values, the system achieves signature-less detection that is adaptable to both known and zero-day attacks while maintaining high detection reliability
2Measurement precision
If known network traffic analyzers perform packet inspection based on previously-observed signatures at high data rates, then detection accuracy is improved, but power consumption and cost increase
Solution Approach 1:
The patent extracts only the essential characteristics of packet flows and condenses them into compact flow state values, eliminating the need for deep packet inspection. By extracting and storing only the critical flow state parameters rather than analyzing entire packet contents, the system achieves accurate anomaly detection at high data rates with significantly reduced power consumption and processing requirements
Solution Approach 2:
The patent creates simplified copies of packet flow characteristics in the form of flow state values that can be rapidly compared against pre-computed reference values. These flow state value copies enable fast, accurate detection without requiring full packet inspection, reducing power consumption while maintaining detection accuracy at high throughput rates
3Measurement precision
If flow state values are updated for every received packet, then detection accuracy is improved, but processing overhead and resource usage increase
Solution Approach 1:
The patent implements periodic updates of flow state values at predetermined time intervals rather than updating for every single packet. This periodic update mechanism maintains sufficient detection accuracy by capturing flow state changes at regular intervals while dramatically reducing processing overhead and resource consumption compared to continuous per-packet updates
Data Source
AI summary
In one embodiment, a processor-readable medium storing code representing instructions that when executed by a processor cause the processor to update, at a memory location, a first flow state value associated with a data flow to a second flow state value when at least one of a packet from the data flow is received or the memory location is selected after a time period has expired. At least a portion of the packet is analyzed when the second flow state value represents a flow rate of a network data flow anomaly.


