Network Attack Classifier Verification in LLNs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting Denial of Service (DoS) attacks in Low Power and Lossy Networks (LLNs) is challenging due to resource constraints, dynamic conditions, and the difficulty in distinguishing between legitimate and malicious traffic, especially in environments with varying interference and changing environmental conditions.

Innovation Solution

A mechanism where a network device receives a classifier tracking request to verify the effectiveness of an attack detection classifier by classifying network traffic during a specified time period, mixing attack traffic with actual traffic, and evaluating the classifier's performance to ensure it remains effective in detecting network attacks without impacting legitimate traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If attack detection classifiers are deployed in LLNs to detect DoS attacks, then network security is improved, but resource consumption (processing capability, memory, energy) increases

Engineering Contradiction:
Improvenetwork securityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent divides the attack detection functionality into multiple components: a coordinator device that manages verification scheduling and a network device that performs actual classification. This segmentation allows the heavy verification tasks to be distributed, reducing the resource burden on any single device in the resource-constrained LLN environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary verification scheduling where the coordinator device determines verification schedules before actual attack detection operations. By pre-planning when and how to verify classifier effectiveness, the system avoids ad-hoc resource-intensive verification operations during critical network periods, thus managing energy consumption more efficiently.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If attack traffic is injected to verify classifier effectiveness, then detection accuracy is improved, but legitimate network operations are disrupted

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements periodic verification where attack traffic is injected only at scheduled intervals determined by the coordinator device, rather than continuously. This periodic approach allows the network to operate normally between verification periods, maintaining productivity while still achieving accurate detection measurements during the scheduled verification windows.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent uses copies of attack traffic patterns for verification purposes rather than real attack traffic. The coordinator device generates synthetic attack traffic that replicates malicious patterns, allowing verification of classifier effectiveness without introducing actual security threats or severe disruptions to legitimate network operations.

Inventive Principle:
Principle #26Copying

3Reliability

If continuous verification of attack classifiers is performed, then classifier effectiveness is maintained, but network resources are consumed

Engineering Contradiction:
Improveclassifier effectivenessVSAvoidverification overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic verification scheduling where the coordinator device adjusts verification frequency and intensity based on network conditions, threat levels, and classifier performance history. This dynamic approach maintains classifier effectiveness through adaptive verification while avoiding the fixed overhead of continuous verification, allowing the system to scale verification resources according to actual needs.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9922196B2Verifying network attack detector effectiveness
Publication Date: 2018.03.20 CISCO TECHNOLOGY INC
  • US9922196B2 patent drawing
  • US9922196B2 patent drawing
  • US9922196B2 patent drawing

AI summary

In one embodiment, a device receives a classifier tracking request from a coordinator device that specifies a classifier verification time period. During the classifier verification time period, the device classifies a set of network traffic that includes traffic observed by the device and attack traffic specified by the coordinator device. The device generates classification results based on the classified set of network traffic and provides the classification results to the coordinator device.