Reversible Sketches for Amplification Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks face challenges in effectively detecting and mitigating amplification attacks, which exploit the one-to-one mapping relationship between request and response packets, leading to unbalanced traffic patterns that traditional detection methods struggle to identify accurately and efficiently.

Innovation Solution

The implementation of reversible sketches at edge routers to monitor and record network traffic, combined with centralized aggregation and analysis by a controller, allows for the identification of anomalies by weighting request and response packets, enabling detection of amplification attacks through the identification of anomalous keys and subsequent mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional detection methods are used to monitor network traffic, then the system can handle basic traffic analysis, but it fails to accurately detect amplification attacks due to unbalanced traffic patterns

Engineering Contradiction:
Improveattack detection accuracyVSAvoiddetection reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent applies the concept of 'color changes' by using reversible sketches to visually distinguish between normal and anomalous traffic patterns. The sketch data structures act as indicators that change state based on traffic characteristics, enabling the detection system to identify amplification attacks through pattern recognition rather than traditional threshold-based methods

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent changes the detection parameters from traditional packet counting to using reversible sketch data structures that capture traffic flow characteristics. By transforming the traffic analysis into sketch space and applying weighting schemes to request-response packet pairs, the system achieves more accurate detection of unbalanced traffic patterns characteristic of amplification attacks

Inventive Principle:
Principle #35Parameter changes

2Productivity

If flow sampling and aggregation techniques are applied to reduce data volume, then processing efficiency improves, but detection precision may be compromised

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidanomaly detection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent uses reversible sketches as compact copies of traffic flow data that preserve essential characteristics while reducing volume. Instead of processing complete packet streams, the system processes sketch representations that maintain the statistical properties needed for anomaly detection, achieving both efficiency and precision

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms traffic analysis from packet-level detail to sketch-space representation, adding a dimensional transformation that enables efficient aggregation across multiple routers. This dimensionality change allows the system to process large-scale traffic while maintaining detection capability through the mathematical properties of reversible sketches

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If centralized aggregation of traffic records from multiple edge devices is implemented, then comprehensive network-wide detection is achieved, but system complexity and memory requirements increase

Engineering Contradiction:
Improvenetwork-wide detection capabilityVSAvoidaggregation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges traffic records from multiple edge devices through centralized aggregation of reversible sketches. The sketch data structures are designed to be combinable through simple addition operations, enabling network-wide detection without complex coordination between devices. The merging process maintains reliability by aggregating evidence from multiple vantage points while keeping system complexity manageable through the mathematical properties of sketches

Inventive Principle:
Principle #5Merging (Combining)

4Measurement precision

If weights are applied to request and response packets to identify anomalies, then amplification attack detection improves, but false positives may increase

Engineering Contradiction:
Improveamplification attack detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the detection system continuously monitors traffic patterns and adjusts its analysis based on aggregated sketch data from multiple edge devices. The weighting scheme for request-response packets is applied in the context of network-wide aggregation, allowing the system to distinguish between legitimate traffic variations and actual amplification attacks, thereby reducing false positives while maintaining detection accuracy

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3756324B1Network security
Publication Date: 2024.10.02 NOKIA TECHNOLOGIES OY
  • EP3756324B1 patent drawingFigure 1
  • EP3756324B1 patent drawingFigure 2
  • EP3756324B1 patent drawingFigure 3

AI summary

Various example embodiments relate generally to providing security for a communication network based on detection and mitigation of an attack in the communication network. Various example embodiments supporting attack detection and mitigation may be configured to support detection and mitigation of an attack in a communication network based on distributed collection of network traffic information at network elements and analysis of aggregated network traffic information at a network controller for determining whether a traffic anomaly indicative of an attack on the communication network is detected. Various example embodiments supporting attack detection and mitigation may be configured to support detection and mitigation of an attack in a communication network based on use of traffic records for supporting the collection, aggregation, and analysis of network traffic information.