Mirrored Response Traffic Analysis for Malicious Source Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management techniques struggle to detect malicious traffic sources, particularly when legitimate sources are hijacked, as they rely on inspecting source traffic, which can be difficult to differentiate from legitimate traffic.

Innovation Solution

A system and method that analyze mirrored response transmissions from destination nodes to determine if initiating transmissions are malicious, using a sensor/analyzing apparatus to inspect response traffic and initiate countermeasures if the source is deemed malicious.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If source traffic inspection is used to detect malicious traffic, then detection capability is improved, but reliability deteriorates when legitimate sources are hijacked

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection reliability
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

Instead of inspecting source traffic to detect malicious sources, the patent inverts the approach by inspecting response traffic from destination nodes. The sensor analyzes responses sent back to source nodes to determine if the initiating transmissions were malicious, thereby resolving the reliability issue when sources are hijacked.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces response traffic as an intermediary indicator. Rather than directly analyzing suspicious source traffic, the system uses the destination node's response traffic as a mediator to indirectly identify malicious sources, improving reliability when direct source inspection fails.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If response traffic analysis is implemented, then detection reliability is improved, but device complexity increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses mirrored copies of response traffic for analysis. A sensor receives mirrored versions of transmissions sent by destination nodes in response to initiating transmissions, allowing analysis without interfering with actual network operations and reducing implementation complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The destination nodes themselves generate the response traffic that reveals malicious activity. The system leverages the natural response behavior of destination nodes to identify malicious sources, eliminating the need for complex active probing or additional intermediary components.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8990938B2Analyzing response traffic to detect a malicious source
Publication Date: 2015.03.24 ARBOR NETWORKS INC
  • US8990938B2 patent drawing
  • US8990938B2 patent drawing
  • US8990938B2 patent drawing

AI summary

A system and method are provided to receive mirrored versions of transmissions sent by a node in response to initiating transmissions received by the node over a network. At least one mirrored response transmission sent from the node in response to at least one corresponding initiating transmission is analyzed to determine whether or not the corresponding at least one initiating transmission is malicious.