Grey Theory Network Flow Analysis for DDoS Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting distributed denial of service (DDOS) attacks are inefficient due to high data storage and computation resource requirements, often relying on costly hardware and conventional statistical and data mining technologies that struggle with rapid changes in network traffic and malicious activity characteristics.

Innovation Solution

The method employs grey theory to analyze network flow data by generating predictive sequences using development coefficients and random factors, allowing for efficient detection of malicious activity with reduced data requirements and enabling a defense procedure when predetermined conditions are met, utilizing a network device with a flow collector, analyzer, and security trigger.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional statistical and data mining technologies are used for intrusion detection, then detection accuracy can be maintained through comprehensive data analysis, but data storage requirements and computation resource consumption increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata storage requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential features and characteristics from network traffic data that are relevant for intrusion detection, rather than storing and analyzing all raw data. By identifying and extracting key predictive features, the system reduces data storage requirements while maintaining detection accuracy through analysis of only the most relevant extracted features.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary analysis and feature extraction on network traffic data before full intrusion detection is needed. By pre-processing data and extracting relevant features in advance, the system reduces the computational burden during actual detection while maintaining accuracy, effectively preparing data beforehand to avoid storing and processing all raw data later.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If conventional statistical and data mining technologies are used for intrusion detection, then comprehensive data analysis can be performed, but computation resource consumption and hardware costs increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputation resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential features and characteristics from network traffic data that are relevant for intrusion detection, rather than storing and analyzing all raw data. By identifying and extracting key predictive features, the system reduces data storage requirements while maintaining detection accuracy through analysis of only the most relevant extracted features.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary analysis and feature extraction on network traffic data before full intrusion detection is needed. By pre-processing data and extracting relevant features in advance, the system reduces the computational burden during actual detection while maintaining accuracy, effectively preparing data beforehand to avoid storing and processing all raw data later.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If characteristic patterns are continuously built and compared in intrusion detection systems, then detection capability can be maintained, but system loading increases and storage capacity becomes insufficient

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem processing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts only the essential features and characteristics from network traffic data that are relevant for intrusion detection, rather than storing and analyzing all raw data. By identifying and extracting key predictive features, the system reduces data storage requirements while maintaining detection accuracy through analysis of only the most relevant extracted features.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary analysis and feature extraction on network traffic data before full intrusion detection is needed. By pre-processing data and extracting relevant features in advance, the system reduces the computational burden during actual detection while maintaining accuracy, effectively preparing data beforehand to avoid storing and processing all raw data later.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7376090B2Method of detecting distributed denial of service based on grey theory
Publication Date: 2008.05.20 TRANSPACIFIC IP LTD
  • US7376090B2 patent drawing
  • US7376090B2 patent drawing
  • US7376090B2 patent drawing

AI summary

A method of malicious network activity detection. An intrusion detection system provides defense against distributed denial of service (DDOS) attacks through an efficient modeling process based on grey theory.