Network Controller Abnormal Traffic Detection via Flow Duplication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-service accommodation access networks, abnormal traffic detection is challenging due to burst traffic from IoT devices, which can be either valid or malicious, leading to increased network load when all communication frames are duplicated for analysis, and existing methods fail to quickly handle such traffic.
Innovation Solution
A communication control system with a network controller that determines whether a communication flow feature is similar to an abnormal flow feature, and if so, reduces processing priority or duplicates the flow, allowing for quick handling of abnormal frames while minimizing network load by selectively duplicating and prioritizing communication flows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If all communication frames are duplicated and transmitted to an analysis server for abnormal traffic detection, then the accuracy of detecting malicious traffic is improved, but the network load increases significantly
Solution Approach 1:
The patent segments the communication frames into normal and abnormal categories based on flow features. Instead of duplicating all frames, only frames with abnormal characteristics (such as burst traffic patterns) are selected for duplication and analysis, thereby reducing overall network load while maintaining detection accuracy for malicious traffic
Solution Approach 2:
The patent applies partial action by selectively duplicating only the portion of traffic that exhibits abnormal characteristics rather than duplicating all communication frames. The determination unit identifies flows with abnormal features and duplicates only those specific frames, avoiding the excessive network load that would result from duplicating entire traffic streams
2Measurement precision
If communication frames are duplicated and transmitted to an analysis server for processing, then abnormal traffic can be detected, but the response time is delayed due to the time required to acquire analysis results
Solution Approach 1:
The patent performs preliminary action by having the determination unit continuously monitor and identify abnormal traffic flows before malicious attacks fully manifest. By detecting abnormal patterns early and pre-duplicating these frames for analysis, the system reduces the time required to respond to actual attacks, as the analysis server already has relevant frames ready for examination
3Measurement precision
If the network controller duplicates and analyzes all communication frames to distinguish valid burst traffic from malicious traffic, then the accuracy of traffic classification is improved, but the processing complexity and network load increase
Solution Approach 1:
The patent applies local quality by differentiating processing approaches for different types of traffic flows. Normal flows are processed with standard procedures, while flows exhibiting abnormal characteristics trigger enhanced analysis with frame duplication. This localized approach to quality control improves classification accuracy for suspicious traffic without applying complex processing uniformly to all traffic, thereby reducing overall system complexity
Data Source
AI summary
In a communication control system having a plurality of layer 2 switches and a network controller, the network controller includes a determination unit and an instruction unit, the determination unit being configured to determine whether or not a transfer communication flow feature indicating a feature of a communication flow transferred by a layer 2 switch of the plurality of layer 2 switches is similar to an abnormal communication flow feature indicating a feature of a communication flow when an abnormality occurs; and the instruction unit being configured to: output to the layer 2 switch, when the determination unit determines that the transfer communication flow feature is similar to the abnormal communication flow feature, a first instruction to lower priority of transfer processing for the communication flow and a second instruction to duplicate the communication flow to the layer 2 switch; or output the first instruction to the layer 2 switch, and output, to a server detecting a malicious attack, identification information identifying the communication flow having the transfer communication flow feature.


