Forced Alert Thresholds for Network Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet Service Providers face challenges in detecting and mitigating network threats, particularly bandwidth-intensive attacks, as existing methods rely on dynamic baseline profiles that can be evaded by incremental increases in traffic or data rates, leading to undetected threats.

Innovation Solution

Implementing forced alert thresholds that are independent of baseline conditions, allowing nodes in a communication network to group by data rate capacity, establish static thresholds, and trigger alerts when data rates exceed these thresholds, with the option to adjust thresholds and perform mitigation protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dynamic baseline profiles are used for threat detection, then the system adapts to normal traffic patterns, but attackers can evade detection by incrementally increasing traffic rates to match the baseline

Engineering Contradiction:
Improveadaptation to normal traffic patternsVSAvoiddetection reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Instead of setting dynamic thresholds based on observed baseline traffic patterns (which attackers can manipulate), the patent inverts the approach by establishing static thresholds first, then measuring how much actual traffic exceeds these fixed thresholds. This prevents attackers from evading detection by gradually adapting to dynamic baselines, as the thresholds remain constant and independent of traffic patterns.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent changes the fundamental parameter from dynamic threshold values to static threshold values. By establishing fixed data rate thresholds that do not change with baseline conditions, the system eliminates the vulnerability to baseline manipulation while maintaining the ability to detect anomalies through exceedance measurement and severity assignment.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If static thresholds independent of baseline conditions are established, then evasion through incremental traffic increases is prevented, but the system may generate false alerts during legitimate bandwidth-intensive operations

Engineering Contradiction:
Improvedetection reliabilityVSAvoidfalse alerts
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback through severity assignment based on the degree of threshold exceedance. When traffic exceeds the static threshold, the system calculates a severity level proportional to how much the threshold is exceeded. This allows legitimate bandwidth-intensive operations (which may occasionally exceed thresholds) to generate lower-severity alerts that can be differentiated from critical threats, reducing false alarm impact while maintaining detection reliability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies partial action by not treating all threshold exceedances as equal critical events. Instead, it responds proportionally to the degree of exceedance, assigning severity levels that reflect the actual threat level. This prevents overreaction to legitimate traffic spikes while maintaining sensitivity to genuine threats.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If alerts are triggered immediately when data rates exceed static thresholds, then timely threat detection is achieved, but the system may lack context for severity assessment

Engineering Contradiction:
Improvealert response speedVSAvoidcontext for severity assessment
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent performs preliminary action by pre-establishing static thresholds and grouping nodes by data rate capacity before monitoring begins. This preparation enables immediate alert triggering when thresholds are exceeded, while the pre-defined grouping structure provides the contextual framework needed for rapid severity assessment without delaying detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides immediate feedback through alert generation when thresholds are exceeded, preserving fast detection. Simultaneously, it enriches this immediate feedback with contextual information through severity assignment based on the degree of exceedance and node grouping, ensuring that speed is not sacrificed for context.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9344440B2Forced alert thresholds for profiled detection
Publication Date: 2016.05.17 ARBOR NETWORKS INC
  • US9344440B2 patent drawing
  • US9344440B2 patent drawing
  • US9344440B2 patent drawing

AI summary

A node in a communication network determines a data rate capacity of one or more nodes of the communication network and creates a single managed object grouping for each node of the one or more nodes having a same data rate capacity. The node establishes one or more static thresholds for the single managed object grouping based on the data rate capacity. The static thresholds are independent of a baseline condition of detected data rates at each node of the single managed object grouping. The node further detects a current rate of received data at each node of the single managed grouping and triggers at least one alert for each node of the single managed grouping when the current rate of the received data at a particular node exceeds the one or more static thresholds.