Centralized Signal Diverter for DoS Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current detection services for network service providers are costly and inefficient, particularly at the customer-end, and result in network outages affecting all customers during malicious attacks, as they require individualized detection and mitigation for each subscriber.

Innovation Solution

A centralized system and method that employs a signal diverter and detection apparatus to redirect a portion of inbound communication signals to a detection center, where parameters for each customer determine if an attack is occurring, allowing separation of attacking signals from legitimate ones and routing only legitimate traffic to customers, thereby minimizing downtime.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If individualized detection services are provided for each customer at the customer-end, then detection accuracy is improved, but cost and device complexity increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidservice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges individual detection services into a centralized detection service located at the provider-edge. Instead of each customer having separate detection apparatus, a single centralized detector consolidates detection functions for all customers, reducing device complexity while maintaining detection capability through centralized monitoring of aggregated traffic

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized detection service performs multiple functions: it monitors traffic for multiple customers simultaneously, detects DOS attacks across the network core, and provides mitigation services to all subscribed customers through a single multi-functional system rather than individual dedicated systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of time

If centralized detection service is implemented at the provider-edge, then service shutdown time is reduced, but detection precision for individual customers may be compromised

Engineering Contradiction:
Improveservice shutdown timeVSAvoiddetection precision
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary approach where the centralized detector at the provider-edge monitors aggregated traffic from multiple customers. The detector uses intermediary analysis techniques to identify DOS attacks in the network core while maintaining the ability to trace and differentiate individual customer traffic patterns, thus preserving detection precision despite centralized monitoring

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network elements are shutdown during a DOS attack to prevent damage, then network security is improved, but service availability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts and removes the harmful DOS traffic from the network using a cleaning center that separates bad traffic from good traffic. By taking out the malicious packets through filtering and cleaning mechanisms before they reach network elements, the system prevents damage without needing to shutdown network elements, thus maintaining service availability while ensuring network security

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7694338B1Shared tap DOS-attack protection
Publication Date: 2010.04.06 T MOBILE INNOVATIONS LLC
  • US7694338B1 patent drawing
  • US7694338B1 patent drawing
  • US7694338B1 patent drawing

AI summary

A method and system are provided for centralizing services subscribed to by customers of a service provider for detecting attacks at the customer-end of a communications network. A signal diverter is installed in a signal path carrying inbound communication signals common to subscribed customers and a portion of the collective inbound signals for each customer is diverted to a detection apparatus. Finally, based on parameters for each subscribed customer, a determination is made as to if a subscribed customer is experiencing an attack.