Centralized Signal Diverter for DoS Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current detection services for network service providers are costly and inefficient, particularly at the customer-end, and result in network outages affecting all customers during malicious attacks, as they require individualized detection and mitigation for each subscriber.
Innovation Solution
A centralized system and method that employs a signal diverter and detection apparatus to redirect a portion of inbound communication signals to a detection center, where parameters for each customer determine if an attack is occurring, allowing separation of attacking signals from legitimate ones and routing only legitimate traffic to customers, thereby minimizing downtime.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If individualized detection services are provided for each customer at the customer-end, then detection accuracy is improved, but cost and device complexity increase
Solution Approach 1:
The patent merges individual detection services into a centralized detection service located at the provider-edge. Instead of each customer having separate detection apparatus, a single centralized detector consolidates detection functions for all customers, reducing device complexity while maintaining detection capability through centralized monitoring of aggregated traffic
Solution Approach 2:
The centralized detection service performs multiple functions: it monitors traffic for multiple customers simultaneously, detects DOS attacks across the network core, and provides mitigation services to all subscribed customers through a single multi-functional system rather than individual dedicated systems
2Loss of time
If centralized detection service is implemented at the provider-edge, then service shutdown time is reduced, but detection precision for individual customers may be compromised
Solution Approach 1:
The patent introduces an intermediary approach where the centralized detector at the provider-edge monitors aggregated traffic from multiple customers. The detector uses intermediary analysis techniques to identify DOS attacks in the network core while maintaining the ability to trace and differentiate individual customer traffic patterns, thus preserving detection precision despite centralized monitoring
3Reliability
If network elements are shutdown during a DOS attack to prevent damage, then network security is improved, but service availability deteriorates
Solution Approach 1:
The patent extracts and removes the harmful DOS traffic from the network using a cleaning center that separates bad traffic from good traffic. By taking out the malicious packets through filtering and cleaning mechanisms before they reach network elements, the system prevents damage without needing to shutdown network elements, thus maintaining service availability while ensuring network security
Data Source
AI summary
A method and system are provided for centralizing services subscribed to by customers of a service provider for detecting attacks at the customer-end of a communications network. A signal diverter is installed in a signal path carrying inbound communication signals common to subscribed customers and a portion of the collective inbound signals for each customer is diverted to a detection apparatus. Finally, based on parameters for each subscribed customer, a determination is made as to if a subscribed customer is experiencing an attack.


