Latency-Based Policy Activation for DoS Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current firewall systems face challenges in accurately detecting and mitigating Denial of Service (DoS) attacks due to the complexity of monitoring and correlating numerous data points, often resulting in false negatives or positives, and require manual configuration of static thresholds that do not dynamically scale with network changes.
Innovation Solution
Implementing latency-based policy activation techniques that collect and correlate latency measures to detect anomalous network activity, dynamically update profiles, and perform mitigation responses, reducing the need for historical connection information and manual threshold settings by using latency as a fundamental metric to identify normal versus abnormal network behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall systems monitor and correlate numerous data points to detect DoS attacks, then detection capability is improved, but system complexity and false positive/negative rates increase
Solution Approach 1:
The patent extracts and focuses on a single critical metric (latency) from the complex set of data points traditionally monitored. By isolating latency as the primary indicator of DoS attacks, the system simplifies monitoring while maintaining detection accuracy, directly resolving the contradiction between comprehensive monitoring and system complexity
Solution Approach 2:
The patent changes the monitoring parameter from multiple complex metrics to a single latency-based metric. This parameter transformation simplifies the detection mechanism while preserving reliability, as latency naturally increases during DoS attacks without requiring complex correlation logic
2Ease of manufacture
If static thresholds are used for DoS detection, then configuration simplicity is improved, but adaptability to network changes deteriorates
Solution Approach 1:
The patent implements dynamic threshold adjustment based on learned network behavior patterns. The system automatically adapts thresholds to match normal network conditions without manual reconfiguration, resolving the contradiction between simple configuration and adaptability by making the system self-adjusting rather than statically configured
Solution Approach 2:
The system performs self-configuration by automatically learning normal latency patterns and adjusting detection thresholds without external intervention. This self-service capability eliminates the need for manual threshold tuning while maintaining adaptability to network changes
3Measurement precision
If manual configuration of detection thresholds is required, then precision of threshold setting is improved, but operational time and complexity increase
Solution Approach 1:
The system performs preliminary learning during a monitoring phase to establish baseline latency patterns before enforcement begins. This preliminary action automates the threshold-setting process that would otherwise require manual configuration, eliminating time loss while maintaining precision through data-driven baseline establishment
Data Source
AI summary
Techniques for latency-based policy activation are disclosed. In some embodiments, a system for latency-based policy activation includes collecting a plurality of latency measures associated with monitored network communications; correlating the plurality of latency measures associated with the monitored network communications to detect anomalous network activity based on a profile; and performing a mitigation response to the anomalous network activity based on a policy.


