Traffic Flooding Attack Detection Using SNMP MIB and Data Mining
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for detecting traffic flooding attacks, such as DDoS, require expensive high-performance systems and lack extendibility, with machine learning approaches often overlooking the mechanical interpretation of system mechanisms and turning them into black-box systems, making them less comprehensive.
Innovation Solution
A system using data mining with a C4.5 decision tree algorithm for rapid detection and classification of traffic flooding attacks, combined with association rule mining for semantic analysis, based on SNMP MIB information, to provide a more stable and efficient detection method.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional packet collecting methods are used for detecting DoS/DDoS attacks, then detailed analysis of attacks can be conducted, but expensive high-performance analysis systems are required and extendibility in terms of installation and management is insufficient
Solution Approach 1:
The patent introduces SNMP MIB information as an intermediary data source between network traffic and attack detection analysis. Instead of directly analyzing raw packets which requires high-performance systems, the invention uses MIB information (a standardized intermediary format) to detect attacks. This intermediary approach enables detailed attack analysis while using simpler, more extendible systems that can collect and process MIB data from network devices.
2Productivity
If machine learning techniques are used for intrusion detection, then detection efficiency is improved, but mechanical interpretation on system mechanisms is lost and the system becomes a black-box
Solution Approach 1:
The patent segments the intrusion detection system into distinct functional modules: MIB information collection, data preprocessing, C4.5 decision tree-based attack detection, and association rule mining for semantic analysis. This segmentation allows each module to perform its function transparently, maintaining interpretability while achieving efficient detection. The C4.5 algorithm's decision trees provide explicit rules that can be interpreted, unlike opaque neural networks.
Solution Approach 2:
The patent changes the fundamental parameter of data representation from raw packets to SNMP MIB information, and from probabilistic outputs to explicit decision rules. By using C4.5 decision trees, the system transforms continuous data into discrete, interpretable classification rules. The association rule mining further transforms detection results into semantically meaningful patterns, maintaining both efficiency and interpretability through parameter transformation.
3Ease of manufacture
If traditional DDoS detection methodologies are used, then system construction is simplified, but comprehensive analysis and semantic interpretation of attacks are limited
Solution Approach 1:
The patent merges multiple analysis techniques into a unified system: SNMP MIB-based detection, C4.5 decision tree classification, and association rule mining. This combination preserves the simplicity of traditional MIB-based approaches while adding sophisticated analysis capabilities. The association rule mining specifically addresses semantic interpretation by discovering meaningful patterns and relationships in attack data, combining ease of construction with comprehensive analysis capability.
Data Source
AI summary
Provided is an apparatus and method for detecting a traffic flooding attack and conducting an in-depth analysis using data mining that may rapidly detect a distributed denial of service (DDoS) attack, for example, a traffic flooding attack, developed more variously and firmly from a denial of service (DoS) attack, perform an attack type classification, and conduct a semantic analysis with respect to the attack. The apparatus and method may support a system operation and provide a more stable service, by rapidly detecting a traffic flooding attack, classifying a type of the attack, and conducting a semantic analysis based on a prediction and analysis scheme of data mining.

