Traffic Flooding Attack Detection Using SNMP MIB and Data Mining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for detecting traffic flooding attacks, such as DDoS, require expensive high-performance systems and lack extendibility, with machine learning approaches often overlooking the mechanical interpretation of system mechanisms and turning them into black-box systems, making them less comprehensive.

Innovation Solution

A system using data mining with a C4.5 decision tree algorithm for rapid detection and classification of traffic flooding attacks, combined with association rule mining for semantic analysis, based on SNMP MIB information, to provide a more stable and efficient detection method.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional packet collecting methods are used for detecting DoS/DDoS attacks, then detailed analysis of attacks can be conducted, but expensive high-performance analysis systems are required and extendibility in terms of installation and management is insufficient

Engineering Contradiction:
Improveattack analysis detailVSAvoidsystem cost and extendibility
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces SNMP MIB information as an intermediary data source between network traffic and attack detection analysis. Instead of directly analyzing raw packets which requires high-performance systems, the invention uses MIB information (a standardized intermediary format) to detect attacks. This intermediary approach enables detailed attack analysis while using simpler, more extendible systems that can collect and process MIB data from network devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If machine learning techniques are used for intrusion detection, then detection efficiency is improved, but mechanical interpretation on system mechanisms is lost and the system becomes a black-box

Engineering Contradiction:
Improvedetection efficiencyVSAvoidsystem mechanism interpretability
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent segments the intrusion detection system into distinct functional modules: MIB information collection, data preprocessing, C4.5 decision tree-based attack detection, and association rule mining for semantic analysis. This segmentation allows each module to perform its function transparently, maintaining interpretability while achieving efficient detection. The C4.5 algorithm's decision trees provide explicit rules that can be interpreted, unlike opaque neural networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the fundamental parameter of data representation from raw packets to SNMP MIB information, and from probabilistic outputs to explicit decision rules. By using C4.5 decision trees, the system transforms continuous data into discrete, interpretable classification rules. The association rule mining further transforms detection results into semantically meaningful patterns, maintaining both efficiency and interpretability through parameter transformation.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If traditional DDoS detection methodologies are used, then system construction is simplified, but comprehensive analysis and semantic interpretation of attacks are limited

Engineering Contradiction:
Improvesystem construction simplicityVSAvoidattack semantic analysis capability
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent merges multiple analysis techniques into a unified system: SNMP MIB-based detection, C4.5 decision tree classification, and association rule mining. This combination preserves the simplicity of traditional MIB-based approaches while adding sophisticated analysis capabilities. The association rule mining specifically addresses semantic interpretation by discovering meaningful patterns and relationships in attack data, combining ease of construction with comprehensive analysis capability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9230102B2Apparatus and method for detecting traffic flooding attack and conducting in-depth analysis using data mining
Publication Date: 2016.01.05 ELECTRONICS & TELECOMM RES INST
  • US9230102B2 patent drawing
  • US9230102B2 patent drawing

AI summary

Provided is an apparatus and method for detecting a traffic flooding attack and conducting an in-depth analysis using data mining that may rapidly detect a distributed denial of service (DDoS) attack, for example, a traffic flooding attack, developed more variously and firmly from a denial of service (DoS) attack, perform an attack type classification, and conduct a semantic analysis with respect to the attack. The apparatus and method may support a system operation and provide a more stable service, by rapidly detecting a traffic flooding attack, classifying a type of the attack, and conducting a semantic analysis based on a prediction and analysis scheme of data mining.