Network Flow Probe for DDoS Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current detection mechanisms for denial of service attacks in communication networks are inadequate, as they rely on quantitative analysis and are ineffective for unknown attacks, often requiring minutes to respond and can misidentify or block legitimate traffic, especially in distributed denial of service scenarios.

Innovation Solution

A method for collecting information about network flows in a software-defined communication network by identifying flow-processing rules associated with endpoint devices, allowing for the identification of attacking sources and targets, and dynamically installing specific processing rules to monitor and mitigate attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If edge filtering is used to block malicious traffic at network entrance, then legitimate traffic protection is improved, but the firewall itself becomes vulnerable to DDoS attacks and response time increases

Engineering Contradiction:
Improveprotection of legitimate trafficVSAvoidvulnerability of firewall to DDoS
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a specialized probe as an intermediary component between the network edge and the firewall. This probe performs preliminary analysis of incoming traffic and identifies malicious flows before they reach the firewall, thereby protecting the firewall from being overwhelmed by DDoS attacks while still providing protection for legitimate traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary analysis and identification of malicious traffic using the specialized probe before the traffic reaches the firewall. By detecting and characterizing attack patterns in advance, the system can prepare appropriate filtering rules and protect the firewall from being subjected to the full burden of DDoS traffic.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If traffic is redirected to a specialized probe for analysis, then detection accuracy is improved, but response time increases by several minutes and legitimate traffic may be lost

Engineering Contradiction:
Improvedetection accuracy of attacksVSAvoidresponse time to attacks
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Instead of redirecting all traffic to the specialized probe for complete analysis, the system applies partial action by having the probe analyze only specific suspicious flows or samples of traffic. This selective analysis approach maintains high detection accuracy for malicious traffic while minimizing the impact on overall response time and avoiding loss of legitimate traffic.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system applies different quality levels of analysis to different traffic flows. The specialized probe performs deep analysis only on suspected malicious traffic, while legitimate traffic flows through the network with minimal intervention. This localized high-quality analysis maintains detection accuracy where needed without causing widespread delays.

Inventive Principle:
Principle #3Local quality

3Ease of manufacture

If quantitative analysis of packets is used to detect DDoS attacks, then implementation simplicity is improved, but effectiveness against unknown attacks deteriorates

Engineering Contradiction:
Improveease of implementing detectionVSAvoideffectiveness against unknown attacks
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The specialized probe implements self-learning capabilities that allow it to automatically adapt to new attack patterns without requiring manual configuration or updates. The system observes traffic patterns, identifies anomalies, and develops detection rules autonomously, combining the simplicity of automated quantitative analysis with the adaptability needed to detect unknown attacks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where the results of traffic analysis are continuously fed back into the detection algorithms. The specialized probe learns from detected attacks and adjusts its analysis parameters, enabling the simple quantitative analysis framework to become increasingly effective against evolving and unknown attack types through continuous adaptation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11997070B2Technique for collecting information relating to a flow routed in a network
Publication Date: 2024.05.28 ORANGE SA
  • US11997070B2 patent drawing
  • US11997070B2 patent drawing

AI summary

A technique for collecting information relating to a flow routed in a communication network. This network includes, in a data plane, packet-processing devices that are configured so as to process packets on the basis of flow-processing rules and, in a control plane, at least one control device that is configured so as to control packet-processing devices and to manage the flow-processing rules. An analysis device identifies at least one flow-processing rule configured so as to process a flow including a first characteristic associated with a first endpoint device of a flow to be sought in the communication network and applied by a processing device. Based on the identified processing rule, the control device determines a second characteristic associated with a second endpoint device.