Referrer Data Structures for DDoS Detection and Search Ranking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems lack effective methods to detect and respond to cyber threats, such as distributed denial-of-service attacks and malicious bots, based on referrer information, which are crucial for maintaining high security and reliability of network resources.
Innovation Solution
A system and method that involves a server receiving requests from client devices, determining referrer information to identify potential threats, and using this information to log and analyze requests to detect distributed denial-of-service attacks and malicious bots, while also improving search result ranking based on referrer indications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If referrer information is collected and analyzed to detect cyber threats, then security detection capability is improved, but system complexity increases
Solution Approach 1:
The system segments the complex threat detection task into distinct functional modules: a referrer information collector that gathers referrer data from requests, a referrer data structure generator that organizes this data into structured formats, and a threat detector that analyzes the structured data for malicious patterns. This segmentation reduces overall system complexity by making each component specialized and manageable.
Solution Approach 2:
The patent introduces referrer data structures as intermediary representations between raw referrer information and threat detection analysis. These structured data formats serve as a mediator that transforms unstructured or semi-structured referrer data into a standardized format suitable for analysis, simplifying the detection process while improving security capability.
2Measurement precision
If referrer data structures are generated and maintained for all network resources, then threat detection accuracy is improved, but information storage requirements increase
Solution Approach 1:
The system applies local quality by generating referrer data structures selectively for network resources that are relevant to threat detection, rather than uniformly for all resources. The referrer data structures capture specifically the referrer information needed for security analysis, storing only pertinent details about referrer relationships that contribute to detecting coordinated attacks.
Solution Approach 2:
The patent implements partial action by focusing referrer data structure generation on resources that exhibit suspicious patterns or are part of coordinated attack chains. Rather than comprehensively structuring referrer data for every network resource, the system applies this processing selectively to resources where it provides maximum detection value, thereby reducing overall storage requirements while maintaining high detection accuracy.
Data Source
AI summary
For each network resource request received at a server of a cloud-based service, a determination of whether that request originated from a second network resource is made. For each such request where the network resource originated from the second network resource, a referrer indication is logged that indicates the second network resource is a referrer to that network resource. A network resource relevance dataset is generated based on the referrer indications of the second network resources. A relevance metric is associated with each second network resource based on a total number of referrer indications. A search request is received from a client device. Based at least in part on the network resource relevance dataset, search results are determined. The search results are transmitted to the client device.


