Threat Classifier for LSDDoS Detection in Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional threat detection systems struggle to effectively identify and defend against low and slow distributed denial-of-service (LSDDoS) attacks, which utilize application layer protocols and are difficult to detect due to their slower attack speed and lower flow rate, potentially leading to server resource exhaustion.

Innovation Solution

A threat detection system comprising a global device and a local device, where the global device trains a tensor neural network (TNN) model to build a threat classifier for the local device, enabling the identification of LSDDoS threat types by analyzing packet data and generating classification results to inform appropriate defense mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional DDoS detection methods are used, then high-speed attacks can be detected, but LSDDoS attacks with lower flow rates cannot be effectively identified

Engineering Contradiction:
Improvedetection capabilityVSAvoidattack type coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent changes the detection parameters from flow rate thresholds to tensor-based behavioral patterns. The TNN model analyzes multiple parameters simultaneously (packet timing, source/destination addresses, protocol types, payload characteristics) to detect LSDDoS attacks that conventional single-parameter methods miss due to their lower flow rates.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent combines multiple detection approaches into a composite detection system. The TNN model integrates analysis of packet timing patterns, address relationships, protocol characteristics, and payload features to create a comprehensive detection capability that covers both conventional and LSDDoS attack types.

Inventive Principle:
Principle #40Composite materials

2Productivity

If flow rate thresholding is used for detection, then simple and fast detection is achieved, but LSDDoS attacks are missed due to their lower flow rates

Engineering Contradiction:
Improvedetection speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces the mechanical threshold-based filtering system with a neural network-based analytical system. Instead of using fixed flow rate thresholds that automatically filter out low-rate traffic, the TNN model dynamically analyzes behavioral patterns in the traffic data to identify LSDDoS attacks regardless of their flow rate.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent adds temporal and relational dimensions to the detection process. The TNN model analyzes packet timing patterns, relationships between source and destination addresses, and sequences of events across multiple dimensions, transforming the detection from a single-dimensional flow rate check to a multi-dimensional behavioral analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If application layer protocols are used for attacks, then complex and varied attack methods can be implemented, but detection becomes more difficult

Engineering Contradiction:
Improveattack method diversityVSAvoiddetection system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces the TNN model as an intermediary between the complex application layer traffic and the detection decision. The model acts as a mediator that processes the complexity of HTTP and other application layer protocols, extracting meaningful behavioral patterns while filtering out legitimate traffic variations, thereby simplifying the final detection decision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary analysis of traffic patterns before making detection decisions. The TNN model pre-processes the application layer traffic data, identifying suspicious behavioral patterns and relationships in advance, which prepares the system for faster and more accurate detection of LSDDoS attacks using application layer protocols.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11368482B2Threat detection system for mobile communication system, and global device and local device thereof
Publication Date: 2022.06.21 INSTITUTE FOR INFORMATION INDUSTRY
  • US11368482B2 patent drawing
  • US11368482B2 patent drawing
  • US11368482B2 patent drawing

AI summary

A threat detection system for a mobile communication system, and a global device and a local device thereof are provided. The threat detection system is used for detecting and defensing low and slow distributed denial-of-service (LSDDoS) attacks. The global device is located in a core network of the mobile communication system, and is used for training a tensor neural network (TNN) model to build a threat classifier. The threat classifier is used for the local device to identify a plurality of threat types. The local device inputs the to-be-identified data into the threat classifier to generate a classification result corresponding to one of the threat types.