Relay Device Detecting Reflector Attacks via Packet Ratios
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques are inadequate for detecting reflector attacks in networks, particularly due to the large response packets from UPnP-enabled devices, which are easily exploited for distributed denial-of-service (DDoS) attacks.
Innovation Solution
A relay device with port monitoring units and a determining unit that calculates thresholds based on packet ratios to differentiate between normal and attack scenarios, allowing for the detection of reflector attacks by comparing packet ratios to dynamically set thresholds corresponding to the number of UPnP devices in the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional detection techniques are used, then general network attacks can be detected, but reflector attacks cannot be effectively detected
Solution Approach 1:
The patent changes the detection parameter from general attack patterns to specific packet ratio metrics. By monitoring the ratio of multicast to unicast packets and comparing it against dynamically calculated thresholds, the system can specifically detect reflector attacks while maintaining reliability for other attack types.
Solution Approach 2:
The patent implements dynamic threshold calculation based on the number of UPnP devices in the network. The threshold is not fixed but adapts to network conditions, allowing the detection system to remain effective as the network grows or changes, thus resolving the contradiction between reliability and adaptability.
2Ease of operation
If all UPnP-enabled devices respond to M-SEARCH requests, then service discovery works properly, but the network becomes vulnerable to reflector attacks
Solution Approach 1:
The patent introduces a relay device as an intermediary between the control point and UPnP devices. This intermediary monitors packet ratios and can filter or block suspicious traffic, thereby protecting the network from reflector attacks while allowing legitimate service discovery to continue uninterrupted.
Solution Approach 2:
The system implements feedback by continuously monitoring packet ratios and dynamically adjusting thresholds based on network conditions. This feedback mechanism allows the system to distinguish between normal service discovery traffic and malicious reflector attack traffic, maintaining functionality while preventing attacks.
3Loss of information
If response packet size is large compared to request packet, then device information is transmitted effectively, but network bandwidth is easily occupied by attacks
Solution Approach 1:
The patent applies partial action by monitoring only the ratio of multicast to unicast packets rather than analyzing every packet in detail. This selective monitoring approach allows effective detection of reflector attacks without consuming excessive network bandwidth, resolving the contradiction between information transmission and bandwidth conservation.
Data Source
AI summary
A relay device coupled to a network including a plurality of information processing devices, the relay device includes a port coupled to any one of the plurality of information processing devices, and a processor coupled to the port and configured to specify a first number which is a number of packets of a first communication protocol transmitted from the port, specify a second number which is a number of packets of the first communication protocol received at the port, and determine, based on comparison of a ratio of the first number and the second number and a threshold corresponding to a third number which is a number of the plurality of information processing devices included in the network, whether an attack by at least one information processing device of the plurality of information processing devices occurs.


