Mirrored Response Traffic Analysis for Malicious Source Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management techniques struggle to detect malicious traffic sources, particularly when legitimate sources are hijacked, as they rely on inspecting source traffic, which can be difficult to differentiate from legitimate traffic.
Innovation Solution
A system and method that analyze mirrored response transmissions from destination nodes to determine if initiating transmissions are malicious, using a sensor/analyzing apparatus to inspect response traffic and initiate countermeasures if the source is deemed malicious.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If source traffic inspection is used to detect malicious traffic, then detection capability is improved, but reliability deteriorates when legitimate sources are hijacked
Solution Approach 1:
Instead of inspecting source traffic to detect malicious sources, the patent inverts the approach by inspecting response traffic from destination nodes. The sensor analyzes responses sent back to source nodes to determine if the initiating transmissions were malicious, thereby resolving the reliability issue when sources are hijacked.
Solution Approach 2:
The patent introduces response traffic as an intermediary indicator. Rather than directly analyzing suspicious source traffic, the system uses the destination node's response traffic as a mediator to indirectly identify malicious sources, improving reliability when direct source inspection fails.
2Reliability
If response traffic analysis is implemented, then detection reliability is improved, but device complexity increases
Solution Approach 1:
The patent uses mirrored copies of response traffic for analysis. A sensor receives mirrored versions of transmissions sent by destination nodes in response to initiating transmissions, allowing analysis without interfering with actual network operations and reducing implementation complexity.
Solution Approach 2:
The destination nodes themselves generate the response traffic that reveals malicious activity. The system leverages the natural response behavior of destination nodes to identify malicious sources, eliminating the need for complex active probing or additional intermediary components.
Data Source
AI summary
A system and method are provided to receive mirrored versions of transmissions sent by a node in response to initiating transmissions received by the node over a network. At least one mirrored response transmission sent from the node in response to at least one corresponding initiating transmission is analyzed to determine whether or not the corresponding at least one initiating transmission is malicious.


