TLS Fingerprint Classification for Encrypted DDoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing detection and mitigation methods for encrypted Transport Layer Security (TLS) Distributed Denial of Service (DDoS) attacks are ineffective due to the use of encryption, which hides malicious traffic patterns, and require significant compute resources, making them complex and costly.
Innovation Solution
A system and method that characterizes and mitigates TLS DDoS attacks using real-time statistics and TLS fingerprints without decryption, by classifying fingerprints based on rate-invariant values and generating a real-time signature (RTS) to identify and mitigate anomalous traffic patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If TLS decryption is used to detect encrypted DDOS attacks, then detection accuracy is improved, but computational complexity and resource consumption increase significantly
Solution Approach 1:
The patent extracts and analyzes specific identifiable features (TLS fingerprints, rate-invariant values) from the encrypted traffic without performing full decryption. This allows detection of attack patterns while avoiding the computational burden of decrypting all traffic, thus resolving the contradiction between detection accuracy and computational complexity
Solution Approach 2:
The system performs preliminary classification of TLS fingerprints and establishes rate-invariant baselines before the actual attack detection. This preliminary characterization enables faster, more efficient detection during attacks without requiring complex real-time decryption, addressing the computational complexity issue while maintaining detection accuracy
2Reliability
If TLS termination is implemented to mitigate encrypted DDOS attacks, then mitigation effectiveness is improved, but resource consumption increases significantly
Solution Approach 1:
The patent extracts only the necessary fingerprint information from TLS handshakes without implementing full TLS termination. This selective extraction approach maintains mitigation effectiveness by identifying and blocking malicious traffic patterns while avoiding the heavy resource consumption associated with complete TLS termination for all traffic
3Reliability
If challenge-response verification methods are used to detect DDOS attacks, then detection reliability is improved, but ease of operation deteriorates due to deceptive techniques
Solution Approach 1:
The patent introduces rate-invariant values as an intermediary metric that is independent of the deceptive challenge-response interactions. These rate-invariant characteristics provide a reliable basis for detection that is not affected by attackers' ability to respond to challenges, thus maintaining detection reliability while simplifying the detection process
Solution Approach 2:
Instead of relying on the content of challenge-response verification which can be deceived, the patent inverts the approach by analyzing the rates and patterns of TLS fingerprints themselves. This inversion bypasses the deceptive techniques entirely, making detection more reliable and operationally simpler
Data Source
AI summary
A method and system for mitigating encrypted distributed denial of service (DDOS) attacks comprising: receiving a detection of an encrypted DDOS attack from an encrypted transaction related traffic, wherein the encrypted DDOS attack is associated with a plurality of transport layer security (TLS) fingerprints (FPs); classifying each of the plurality of TLS FPs as a type of FP based on a comparison of rate-invariant values to a native FP baseline, wherein the rate-invariant values are associated with the plurality of TLS FPs; selecting anomalous FPs as a subset of the plurality of TLS FPs; generating a real time signature (RTS), for the encrypted DDOS attack, having at least one unknown type of FP of the subset of anomalous FPs; and mitigating the encrypted DDOS attack based on the generated RTS.


