Latency-Based Policy Activation for DoS Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewall systems face challenges in accurately detecting and mitigating Denial of Service (DoS) attacks due to the complexity of monitoring and correlating numerous data points, often resulting in false negatives or positives, and require manual configuration of static thresholds that do not dynamically scale with network changes.

Innovation Solution

Implementing latency-based policy activation techniques that collect and correlate latency measures to detect anomalous network activity, dynamically update profiles, and perform mitigation responses, reducing the need for historical connection information and manual threshold settings by using latency as a fundamental metric to identify normal versus abnormal network behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall systems monitor and correlate numerous data points to detect DoS attacks, then detection capability is improved, but system complexity and false positive/negative rates increase

Engineering Contradiction:
ImproveDoS attack detection accuracyVSAvoidmonitoring and correlation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and focuses on a single critical metric (latency) from the complex set of data points traditionally monitored. By isolating latency as the primary indicator of DoS attacks, the system simplifies monitoring while maintaining detection accuracy, directly resolving the contradiction between comprehensive monitoring and system complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the monitoring parameter from multiple complex metrics to a single latency-based metric. This parameter transformation simplifies the detection mechanism while preserving reliability, as latency naturally increases during DoS attacks without requiring complex correlation logic

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If static thresholds are used for DoS detection, then configuration simplicity is improved, but adaptability to network changes deteriorates

Engineering Contradiction:
Improveconfiguration simplicityVSAvoiddynamic scaling with network changes
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic threshold adjustment based on learned network behavior patterns. The system automatically adapts thresholds to match normal network conditions without manual reconfiguration, resolving the contradiction between simple configuration and adaptability by making the system self-adjusting rather than statically configured

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-configuration by automatically learning normal latency patterns and adjusting detection thresholds without external intervention. This self-service capability eliminates the need for manual threshold tuning while maintaining adaptability to network changes

Inventive Principle:
Principle #25Self-service

3Measurement precision

If manual configuration of detection thresholds is required, then precision of threshold setting is improved, but operational time and complexity increase

Engineering Contradiction:
Improvethreshold setting precisionVSAvoidmanual configuration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary learning during a monitoring phase to establish baseline latency patterns before enforcement begins. This preliminary action automates the threshold-setting process that would otherwise require manual configuration, eliminating time loss while maintaining precision through data-driven baseline establishment

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10135864B2Latency-based policy activation
Publication Date: 2018.11.20 PALO ALTO NETWORKS INC
  • US10135864B2 patent drawing
  • US10135864B2 patent drawing
  • US10135864B2 patent drawing

AI summary

Techniques for latency-based policy activation are disclosed. In some embodiments, a system for latency-based policy activation includes collecting a plurality of latency measures associated with monitored network communications; correlating the plurality of latency measures associated with the monitored network communications to detect anomalous network activity based on a profile; and performing a mitigation response to the anomalous network activity based on a policy.