Threat Classifier for LSDDoS Detection in Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional threat detection systems struggle to effectively identify and defend against low and slow distributed denial-of-service (LSDDoS) attacks, which utilize application layer protocols and are difficult to detect due to their slower attack speed and lower flow rate, potentially leading to server resource exhaustion.
Innovation Solution
A threat detection system comprising a global device and a local device, where the global device trains a tensor neural network (TNN) model to build a threat classifier for the local device, enabling the identification of LSDDoS threat types by analyzing packet data and generating classification results to inform appropriate defense mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional DDoS detection methods are used, then high-speed attacks can be detected, but LSDDoS attacks with lower flow rates cannot be effectively identified
Solution Approach 1:
The patent changes the detection parameters from flow rate thresholds to tensor-based behavioral patterns. The TNN model analyzes multiple parameters simultaneously (packet timing, source/destination addresses, protocol types, payload characteristics) to detect LSDDoS attacks that conventional single-parameter methods miss due to their lower flow rates.
Solution Approach 2:
The patent combines multiple detection approaches into a composite detection system. The TNN model integrates analysis of packet timing patterns, address relationships, protocol characteristics, and payload features to create a comprehensive detection capability that covers both conventional and LSDDoS attack types.
2Productivity
If flow rate thresholding is used for detection, then simple and fast detection is achieved, but LSDDoS attacks are missed due to their lower flow rates
Solution Approach 1:
The patent replaces the mechanical threshold-based filtering system with a neural network-based analytical system. Instead of using fixed flow rate thresholds that automatically filter out low-rate traffic, the TNN model dynamically analyzes behavioral patterns in the traffic data to identify LSDDoS attacks regardless of their flow rate.
Solution Approach 2:
The patent adds temporal and relational dimensions to the detection process. The TNN model analyzes packet timing patterns, relationships between source and destination addresses, and sequences of events across multiple dimensions, transforming the detection from a single-dimensional flow rate check to a multi-dimensional behavioral analysis.
3Adaptability or versatility
If application layer protocols are used for attacks, then complex and varied attack methods can be implemented, but detection becomes more difficult
Solution Approach 1:
The patent introduces the TNN model as an intermediary between the complex application layer traffic and the detection decision. The model acts as a mediator that processes the complexity of HTTP and other application layer protocols, extracting meaningful behavioral patterns while filtering out legitimate traffic variations, thereby simplifying the final detection decision.
Solution Approach 2:
The patent performs preliminary analysis of traffic patterns before making detection decisions. The TNN model pre-processes the application layer traffic data, identifying suspicious behavioral patterns and relationships in advance, which prepares the system for faster and more accurate detection of LSDDoS attacks using application layer protocols.
Data Source
AI summary
A threat detection system for a mobile communication system, and a global device and a local device thereof are provided. The threat detection system is used for detecting and defensing low and slow distributed denial-of-service (LSDDoS) attacks. The global device is located in a core network of the mobile communication system, and is used for training a tensor neural network (TNN) model to build a threat classifier. The threat classifier is used for the local device to identify a plurality of threat types. The local device inputs the to-be-identified data into the threat classifier to generate a classification result corresponding to one of the threat types.


