NoC Router DoS Attack Detection via Packet Arrival Curves

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies fail to provide a lightweight and real-time mechanism for detecting and localizing Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks in Network-on-Chip (NoC) based System-on-Chip (SoC) architectures, which are critical for preventing performance degradation and real-time violations in IoT and embedded systems.

Innovation Solution

A real-time and lightweight DoS/DDoS attack detection technique that utilizes routers to monitor packet arrivals and latency data, employing statically profiled traffic behavior and the leaky bucket algorithm to detect violations and localize malicious intellectual property (IP) sources with negligible hardware overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional monitoring mechanisms are used to detect DoS attacks, then detection capability is provided, but hardware overhead and system complexity increase significantly

Engineering Contradiction:
Improveattack detection capabilityVSAvoidhardware overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes existing NoC routers multi-functional by enabling them to perform both their traditional packet routing function and attack detection function simultaneously. The routers use their existing packet arrival and latency measurement capabilities to detect DoS attacks without requiring separate dedicated monitoring hardware, thus achieving universal functionality with minimal additional overhead

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The detection mechanism utilizes the NoC's own inherent operational data (packet arrival times and latency measurements) that are already being collected for normal routing operations. By serving dual purposes with existing resources, the system achieves self-service detection capability without external monitoring infrastructure

Inventive Principle:
Principle #25Self-service

2Speed

If comprehensive monitoring is implemented to detect attacks in real-time, then detection speed improves, but area overhead increases

Engineering Contradiction:
Improvedetection speedVSAvoidarea overhead
Core Design Contradiction:
SpeedVSArea of stationary object

Solution Approach 1:

The patent implements partial monitoring by focusing detection efforts on specific critical parameters (packet arrival rates and latency) rather than comprehensively monitoring all NoC traffic characteristics. This selective approach achieves timely detection of DoS attacks while minimizing the area overhead associated with extensive monitoring infrastructure

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If extensive monitoring resources are allocated for attack detection, then detection accuracy improves, but power consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidpower overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by stationary object

Solution Approach 1:

The routers leverage their existing operational measurements (packet arrival timestamps and latency data) for dual purposes: normal routing optimization and attack detection. This multi-functional use of existing measurement capabilities achieves accurate DoS detection without requiring additional dedicated sensing hardware that would increase power consumption

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Device complexity

If lightweight detection mechanisms are used, then hardware overhead is minimized, but real-time detection capability is lost

Engineering Contradiction:
Improvehardware overheadVSAvoidreal-time detection capability
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system performs preliminary profiling of normal NoC traffic patterns during an initial phase, establishing baseline arrival rates and latency characteristics. This pre-established knowledge enables lightweight routers to perform real-time anomaly detection by comparing current traffic against the pre-profiled behavior, achieving real-time detection with minimal hardware overhead

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The detection mechanism continuously monitors packet arrival and latency metrics, comparing real-time measurements against profiled baselines and providing immediate feedback when anomalies indicate DoS attacks. This feedback-driven approach enables real-time detection capability while keeping the monitoring infrastructure lightweight

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11797667B2Real-time detection and localization of DoS attacks in NoC based SoC architectures
Publication Date: 2023.10.24 UNIV OF FLORIDA RESEARCH FOUNDATION INC
  • US11797667B2 patent drawing
  • US11797667B2 patent drawing
  • US11797667B2 patent drawing

AI summary

Various examples are provided related to software and hardware architectures that enable lightweight and real-time Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attack detection. In one example, among others, a method for detection and localization of denial-of-service (DoS) attacks includes detecting, by a router of an intellectual property (IP) core in a network-on-chip (NoC) based system-on-chip (SoC) architecture, a compromised packet stream based at least in part upon a packet arrival curve (PAC) associated with the router; identifying, by the IP core, a candidate IP core in the NoC as a potential attacker based at least in part upon a destination packet latency curve (DLC) associated with the IP core; and transmitting, by the router, a notification message indicating that the candidate IP core is the potential attacker to a router of the candidate IP core.