Network Flow Probe for DDoS Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current detection mechanisms for denial of service attacks in communication networks are inadequate, as they rely on quantitative analysis and are ineffective for unknown attacks, often requiring minutes to respond and can misidentify or block legitimate traffic, especially in distributed denial of service scenarios.
Innovation Solution
A method for collecting information about network flows in a software-defined communication network by identifying flow-processing rules associated with endpoint devices, allowing for the identification of attacking sources and targets, and dynamically installing specific processing rules to monitor and mitigate attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If edge filtering is used to block malicious traffic at network entrance, then legitimate traffic protection is improved, but the firewall itself becomes vulnerable to DDoS attacks and response time increases
Solution Approach 1:
The patent introduces a specialized probe as an intermediary component between the network edge and the firewall. This probe performs preliminary analysis of incoming traffic and identifies malicious flows before they reach the firewall, thereby protecting the firewall from being overwhelmed by DDoS attacks while still providing protection for legitimate traffic.
Solution Approach 2:
The system performs preliminary analysis and identification of malicious traffic using the specialized probe before the traffic reaches the firewall. By detecting and characterizing attack patterns in advance, the system can prepare appropriate filtering rules and protect the firewall from being subjected to the full burden of DDoS traffic.
2Measurement precision
If traffic is redirected to a specialized probe for analysis, then detection accuracy is improved, but response time increases by several minutes and legitimate traffic may be lost
Solution Approach 1:
Instead of redirecting all traffic to the specialized probe for complete analysis, the system applies partial action by having the probe analyze only specific suspicious flows or samples of traffic. This selective analysis approach maintains high detection accuracy for malicious traffic while minimizing the impact on overall response time and avoiding loss of legitimate traffic.
Solution Approach 2:
The system applies different quality levels of analysis to different traffic flows. The specialized probe performs deep analysis only on suspected malicious traffic, while legitimate traffic flows through the network with minimal intervention. This localized high-quality analysis maintains detection accuracy where needed without causing widespread delays.
3Ease of manufacture
If quantitative analysis of packets is used to detect DDoS attacks, then implementation simplicity is improved, but effectiveness against unknown attacks deteriorates
Solution Approach 1:
The specialized probe implements self-learning capabilities that allow it to automatically adapt to new attack patterns without requiring manual configuration or updates. The system observes traffic patterns, identifies anomalies, and develops detection rules autonomously, combining the simplicity of automated quantitative analysis with the adaptability needed to detect unknown attacks.
Solution Approach 2:
The system incorporates feedback mechanisms where the results of traffic analysis are continuously fed back into the detection algorithms. The specialized probe learns from detected attacks and adjusts its analysis parameters, enabling the simple quantitative analysis framework to become increasingly effective against evolving and unknown attack types through continuous adaptation.
Data Source
AI summary
A technique for collecting information relating to a flow routed in a communication network. This network includes, in a data plane, packet-processing devices that are configured so as to process packets on the basis of flow-processing rules and, in a control plane, at least one control device that is configured so as to control packet-processing devices and to manage the flow-processing rules. An analysis device identifies at least one flow-processing rule configured so as to process a flow including a first characteristic associated with a first endpoint device of a flow to be sought in the communication network and applied by a processing device. Based on the identified processing rule, the control device determines a second characteristic associated with a second endpoint device.

