Forced Alert Thresholds for Network Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internet Service Providers face challenges in detecting and mitigating network threats, particularly bandwidth-intensive attacks, as existing methods rely on dynamic baseline profiles that can be evaded by incremental increases in traffic or data rates, leading to undetected threats.
Innovation Solution
Implementing forced alert thresholds that are independent of baseline conditions, allowing nodes in a communication network to group by data rate capacity, establish static thresholds, and trigger alerts when data rates exceed these thresholds, with the option to adjust thresholds and perform mitigation protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If dynamic baseline profiles are used for threat detection, then the system adapts to normal traffic patterns, but attackers can evade detection by incrementally increasing traffic rates to match the baseline
Solution Approach 1:
Instead of setting dynamic thresholds based on observed baseline traffic patterns (which attackers can manipulate), the patent inverts the approach by establishing static thresholds first, then measuring how much actual traffic exceeds these fixed thresholds. This prevents attackers from evading detection by gradually adapting to dynamic baselines, as the thresholds remain constant and independent of traffic patterns.
Solution Approach 2:
The patent changes the fundamental parameter from dynamic threshold values to static threshold values. By establishing fixed data rate thresholds that do not change with baseline conditions, the system eliminates the vulnerability to baseline manipulation while maintaining the ability to detect anomalies through exceedance measurement and severity assignment.
2Reliability
If static thresholds independent of baseline conditions are established, then evasion through incremental traffic increases is prevented, but the system may generate false alerts during legitimate bandwidth-intensive operations
Solution Approach 1:
The patent implements feedback through severity assignment based on the degree of threshold exceedance. When traffic exceeds the static threshold, the system calculates a severity level proportional to how much the threshold is exceeded. This allows legitimate bandwidth-intensive operations (which may occasionally exceed thresholds) to generate lower-severity alerts that can be differentiated from critical threats, reducing false alarm impact while maintaining detection reliability.
Solution Approach 2:
The system applies partial action by not treating all threshold exceedances as equal critical events. Instead, it responds proportionally to the degree of exceedance, assigning severity levels that reflect the actual threat level. This prevents overreaction to legitimate traffic spikes while maintaining sensitivity to genuine threats.
3Speed
If alerts are triggered immediately when data rates exceed static thresholds, then timely threat detection is achieved, but the system may lack context for severity assessment
Solution Approach 1:
The patent performs preliminary action by pre-establishing static thresholds and grouping nodes by data rate capacity before monitoring begins. This preparation enables immediate alert triggering when thresholds are exceeded, while the pre-defined grouping structure provides the contextual framework needed for rapid severity assessment without delaying detection.
Solution Approach 2:
The system provides immediate feedback through alert generation when thresholds are exceeded, preserving fast detection. Simultaneously, it enriches this immediate feedback with contextual information through severity assignment based on the degree of exceedance and node grouping, ensuring that speed is not sacrificed for context.
Data Source
AI summary
A node in a communication network determines a data rate capacity of one or more nodes of the communication network and creates a single managed object grouping for each node of the one or more nodes having a same data rate capacity. The node establishes one or more static thresholds for the single managed object grouping based on the data rate capacity. The static thresholds are independent of a baseline condition of detected data rates at each node of the single managed object grouping. The node further detects a current rate of received data at each node of the single managed grouping and triggers at least one alert for each node of the single managed grouping when the current rate of the received data at a particular node exceeds the one or more static thresholds.


