Application Traffic Flow Prediction Based on Multi-Stage Network Traffic Flow Scanning

A multi-stage pattern matching process in the network control plane predicts application layer protocols and subsequent flows, enhancing security policy enforcement and reducing cyberattack risks in network systems.

JP2025521584APending Publication Date: 2025-07-10PALO ALTO NETWORKS INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024575477
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-15
Filing Date
2023-03-28
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

Existing network security systems struggle to timely identify application layer protocols and predict subsequent flows, leading to inefficiencies in policy enforcement and increased vulnerability to cyberattacks.

Method used

A multi-stage pattern matching process is employed in the network control plane to identify application layer protocols by scanning mirrored network traffic, using pre-constructed databases to recognize signaling protocols and extract flow identification information, enabling accurate prediction of subsequent data flows and policy enforcement.

Benefits of technology

Enhances timely enforcement of security policies and reduces cyberattack risks by accurately predicting and identifying application layer protocols before data transmission, thereby improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025521584000001_ABST
    Figure 2025521584000001_ABST
Patent Text Reader

Abstract

In the network control plane, a pattern matching database is constructed and maintained to identify applications or application-level protocols. Additionally, a pattern matching database is constructed and maintained to predict subsequent flows for application layer / protocol or data protocols. After flow discrimination in network traffic mirrored from the data plane, in the first stage, the network traffic flow is scanned, and then, if a signaling protocol message is detected in the first stage scan, it is scanned in the second stage. In the second stage, based on the signaling protocol message detected in the first stage scan, one of the application / data protocol pattern databases is selected for scanning purposes. If a match is found from the second stage scan, a mapping is created between the signaling protocol identifier and the identifier of the predicted application traffic flow, and it is communicated to the data plane for policy selection and enforcement. detected signaling protocol message, one of the application / data protocol pattern databases is selected for scanning purposes If a match is found from the second stage scan, a mapping is created between the signaling protocol identifier and the identifier of the predicted application traffic flow, and it is communicated to the data plane for policy selection and enforcement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to digital transmission configurations for electronic communications (e.g., CPC class H04), and for the maintenance, management, or servicing of networks (e.g., subclass H04L 41 / 00).

Background Art

[0002] Flow tracking examines information within the header of a packet (i.e., a transport layer protocol data unit) in order to classify packets of network traffic into different flows. A flow is identified using tuples, which can be 5-tuples or 3-tuples. The 5-tuple for flow classification includes the source Internet Protocol (IP) address, source Transmission Control Protocol (TCP) / User Datagram Protocol (UDP) port, destination IP address, destination TCP / UDP port, and IP protocol. The 3-tuple for flow classification includes the source IP address, destination IP address, and IP protocol. After flow classification, a firewall can use stateful inspection to identify the application of a flow based on ports and source / destination addresses. A firewall can also use deep packet inspection to identify an application based on application signatures / patterns within the application data.

Brief Description of the Drawings

[0003] Embodiments of the present disclosure may be better understood by referring to the accompanying drawings.

Figure 1

Figure 2

Figure 3

Figure 4

[0004] The following description includes exemplary systems, methods, techniques, and program flows to assist in understanding the present disclosure, but does not limit the scope of the claims. Well-known instruction instances, protocols, structures, and techniques are not shown in detail for brevity.

[0005] Summary

[0006] Before application data begins to flow across a checkpoint (e.g., a firewall), identifying the application layer protocol (e.g., Session Initiation Protocol (SIP) or File Transfer Protocol (FTP)), or the application, enables timely enforcement of relevant policies and reduces the opportunity for cyberattacks. Some applications and application layer protocols rely on session establishment by a signaling protocol (e.g., SIP or H.323) before application traffic / data begins to flow. Since the subsequent flow of data or application traffic can be expected or predicted, this description often refers to the application layer / level protocol that precedes the data / application traffic as the "predictor protocol". A security device (e.g., a firewall with an application level gateway) can use the identification of signaling protocol messages that establish a session of an application or application layer protocol to determine flow identification information to identify the application or application protocol before data begins to stream for the application or application protocol. In the network control plane, a pattern matching database is constructed and maintained to identify application or application layer protocols (e.g., SIP, Hypertext Transfer Protocol (HTTP), etc.). In addition, a pattern matching database is constructed and maintained to predict subsequent flows for application layer / level protocols or data protocols.After flow classification in the network traffic mirrored from the data plane, a process in the control plane (the "application identification engine") scans the flow in a first stage and then scans the traffic in a second stage if a predictor protocol message is detected in the scanning of the first stage. For the second stage, the application identification engine selects one of the application / data protocol pattern databases for scanning based on the predictor protocol message detected in the scanning of the first stage. If a match is found from the scanning of the second stage, the application identification engine creates a mapping between the predictor protocol identifier and the identifier of the predicted application traffic flow.

[0007] Exemplary description

[0008] Figure 1 is a diagram of a network device control plane that uses multi-stage pattern matching for application flow prediction for network traffic. Figure 1 shows a control plane 101 and a data plane 103. The data plane 103 includes a packet transfer engine 117. The control plane 101 includes an application identification engine 111 having an application flow predictor. The application identification engine 111 also includes a pattern matching engine 109. The control plane 101 also includes a traffic processor 110 that performs deep packet inspection (DPI) using flow tracking.

[0009] FIG. 1 is annotated with a series of letters A - G. Each stage represents one or more operations. These stages are ordered for this example, but these stages are provided to show one example to aid in understanding the present disclosure and should not be used to limit the claims. The technical subject matter within the scope of the claims may be different from what is illustrated.

[0010] In stage A, the network traffic received at the data plane 103 is mirrored to the control plane 101. The mirroring can be implemented using port mirroring.

[0011] In stage B, the traffic processor 110 differentiates the mirrored network traffic into detected traffic flows. For example, the traffic processor 110 creates (or generates a thread for creating) a data structure using the detected network information tuple for flow differentiation.

[0012] For each flow, the application identification engine 111 scans the packets of the flow to identify the application or application - level protocol to ensure that the corresponding policy is applied.

[0013] At stage C, the application identification engine 111 scans the traffic flow using the pattern matching engine 109 for matches in the first-stage application layer pattern database 113. The pattern matching databases 113 and 115 are pre-constructed. The expert / domain knowledge is used to select and define a pattern or regular expression based on the fields of the message representing the application, signaling protocol, etc. For the pattern matching database 115, the expert / domain knowledge is used to select and define a pattern based on the fields of the message representing the data protocol or application. For this illustration, assume that the first-stage scanning results in a matching entry indicating that an SIP message is detected in the transport layer packet payload or user data payload.

[0014] At stage D, based on the first-stage scanning results, the application identification engine 111 selects one of the pattern matching databases 115 for SIP and scans the traffic flow accordingly. The application identification engine 111 scans the traffic flow using the pattern matching engine 109 (or another instance of the pattern matching engine 109) for matches in the selected SIP pattern matching database of the database 115.

[0015] In stage E, the application identification engine 111 determines the data protocol indicated in the traffic flow and extracts the flow identification information of the data protocol from the matched packet payload based on finding a pattern match in the selected second-stage database. The matching entry can indicate the position of the flow identification information in the payload that matches the SIP message. For example, the matching pattern can be for the Real-Time Protocol (RTP) indicated in the Session Description Protocol (SDP) message of the SIP message. The matching entry can indicate the offset in the SIP message to place the network address (e.g., IP address) and port for the established RTP connection that streams multimedia data. The following is an example related to the display of the data protocol and the SIP message having the flow identification information of the data protocol. The lines in the SIP message having tokens that match the pattern are marked in bold.

[0016]

Table 1

[0017] In stage F, the control plane 101 communicates the mapping to the data plane 103. Assuming that a matching pattern is found in one of the databases 115 representing SIP, the control plane 101 communicates, for example, the mapping of "sip" to an Internet Protocol (IP) address and port. The control plane 101 can communicate the mapping via an interprocess communication channel or an in-band interface.

[0018] In stage G, the packet transfer engine 117 determines a policy for application to the flow identified in the communicated mapping. The packet transfer engine 117 accesses a repository (or, structure) 119 that indicates policies assigned to applications and / or data protocols. The packet transfer engine 117 accesses the repository 119 using the application or protocol identifier communicated from the control plane 101 to determine the configured or assigned policy. The packet transfer engine 117 then updates the memory or structure of the data plane 103 to indicate the policy determined for enforcement in the flow identified in the communicated mapping.

[0019] Figures 2-3 are flowcharts related to exemplary operations related to multi-stage prediction of application / data protocol flows following the detection of messages of support protocols and / or prior protocols, such as signaling protocol setup messages. The previous figures refer to an application identification engine, while the exemplary operations herein are described with reference to an application flow predictor, which can be a component of the application identification engine or a separate program that interacts with or supplements the application identification engine. The names selected for the program code do not limit the scope of the claims. The structure and organization of the program can vary depending on the platform, programmer / architect preferences, programming language, etc. Additionally, the names of code units (programs, modules, methods, functions, etc.) can vary for the same reason and are optional.

[0020] Figure 2 is a flowchart related to exemplary operations for constructing an application / data protocol database for multi-stage application flow prediction. At least some of the databases are pre-constructed, while others for different application / data protocols can be added later. Additionally, database maintenance can include adding, deleting, and / or editing entries. Each of these associates information for flow identification information extraction with patterns.

[0021] At block 201, the application flow predictor begins operations to construct a pattern matching database for application / data protocols that are expected or predicted to follow session establishment by the signaling protocol. For example, the application flow predictor can construct a regular (regex) matching database for each application / data protocol.

[0022] At block 203, the application flow predictor obtains the application / data protocol identifier pattern that occurs in the preceding session setup message. For example, the application flow predictor can iterate over files / structures that include regular expressions for multi-channel application layer gateway (ALG) protocols (e.g., SIP, File Transfer Protocol (FTP), H.323 protocol). The application flow predictor can process each of these files / structures in parallel or sequentially.

[0023] At block 205, the application flow predictor obtains the location of the flow identification information for association with the identifier pattern. In the case of SIP, the network address follows the matching c line pattern, and the port follows the matching m line pattern. The obtained location can be indicated or represented using the offset from the start of the payload / message or with respect to the matching pattern.

[0024] In block 207, the application flow predictor compiles the identifier pattern selected to represent the application / data protocol into the database. For example, the application flow predictor compiles a regular expression of the application / data protocol into a regular matching database. The compilation depends on the implementation of the regular matching engine used. For example, the compilation function of the Hyperscan library can be used to compile the regular expression selected for the application / data protocol. In the case of the SIP pattern database, c-line tokens and m-line tokens from the SDP payload can be used to predict the media flow (e.g., audio / video, RTP / AVP). As another example, the pattern can be based on FTP port commands. The following is an exemplary SIP pattern defined using wildcards that can be compiled into a regular database for the application / data protocol that is expected / predicted to follow the SIP session setup.

[0025]

Table 2

[0026] In block 209, the application flow predictor associates the obtained flow identification information location with the compiled pattern in the corresponding database entry. The application flow predictor can update a pointer or field to indicate the location information. This is an optional operation since the location information can be defined separately for each signaling protocol. For example, a match in the SIP pattern matching database causes the application flow predictor to look up the location information based on finding a match instead of having the location information in the database.

[0027] In block 211, the application flow predictor determines whether there are patterns for additional application / data protocols for flow prediction. If so, the operation flow returns to block 201. Otherwise, the operation flow ends.

[0028] FIG. 3 is a flowchart relating to exemplary operations for a multi-stage scan of network traffic for application flow prediction. The exemplary operations are performed after flow differentiation of network traffic mirrored from the data plane. Thus, the scanning is a scanning of individual flows. Different threads can be instantiated for each flow to be scanned, depending on the implementation.

[0029] In block 301, the application identification engine scans the mirrored packets of the traffic flow against the pattern database of the first stage. For example, the Hyperscan library in scan mode can be used to scan the payloads of the packets within the flow. The scan generates the scan result 302 of the first stage.

[0030] In block 303, the application identification engine determines whether the scan result 302 of the first stage indicates a match in the pattern database of the first stage. If the scan result of the first stage is negative for a match, the operation flow ends. In some cases, a default policy is shown for the scanned flow. If the scan result of the first stage indicates a match, the operation flow proceeds to block 305.

[0031] In block 305, the application identification engine determines whether the first-stage scan result indicates a match for the "predictor" protocol. The predictor protocol is an application-level protocol (i.e., above the transport layer), and perhaps because the predictor protocol is establishing a session or control information for subsequent application / data protocols, a conforming message indicates another application-level protocol in advance. An example of the predictor protocol frequently used in this description is SIP. The first-stage scanning result includes an identifier based on the match (e.g., "SIP" or "H.323"). The predictor protocol does not necessarily have to be different from the protocol for subsequent data flows. For example, FTP establishes a control connection and then a data connection. The FTP process uses the control connection to communicate commands. Illustrated, a pattern match for detecting FTP in a traffic flow as the predictor protocol matches a pattern based on FTP commands or response codes (e.g., USER, RETR, CDUP, CWD, XRCP, XRMD, 220, 227, 332, 421, etc.). If the predictor protocol is not indicated, the operation flow proceeds to block 307. If the predictor protocol is indicated in the first-stage scan result, the operation flow proceeds to block 309 for the second-stage scanning.

[0032] In block 307, the application identification engine communicates the identified application to the data plane. The application traffic corresponding to the identified application has perhaps already started flowing across the inspection point, but the data plane can start implementing the relevant policies. The operation flow ends after block 307.

[0033] In block 309, the application flow predictor of the application identification engine selects the second-stage database based on the scan results of the first stage. For example, the predictor protocol pattern matching database is indexed or identified by the value returned from the matching entry in the first-stage pattern matching database.

[0034] In block 311, the application flow predictor scans the mirrored packets of the traffic flow in which the predictor protocol message was detected for matches in the selected predictor protocol database.

[0035] In block 313, the application flow predictor determines whether a match has been found in the selected database. If not, the operation flow ends. For example, scanning multiple patterns in parallel can return a match indication or a set of match indications. As an example, using FTP, after the FTP port command message "227 Entering Passive Mode", which communicates the address and port used by the FTP server for data transfer, is detected by the first-stage scanning, the second-stage scanning finds the pattern related to the flow identification information. If a match is found, the operation flow proceeds to block 315.

[0036] In block 315, the application flow predictor extracts predicted flow information based on matching entries. A match in the selected predictor protocol database predicts that at least one subsequent flow (e.g., an RTP flow for an audio stream after SIP setup) will begin to cross the inspection point. A matching entry can indicate the location of flow information within the predictor protocol message (e.g., the location of network address and port). Embodiments may separately indicate the location of flow information based on a match in the predictor protocol database. For example, a match in the predictor protocol XYZ pattern matching database causes the application flow predictor to look up the network address and port location information in a separate table. The predictor protocol may allow multiple flows to be indicated within a conformity message. For example, the SIP message body can include SDP descriptions for multiple flows having multiple connections and multiple media sessions. Referring again to the example of FTP, the application flow predictor can extract flow identification information by forming the network address and port using the detected portion of the FTP port command message. Using a command message formatted as PORT-COMMAND-CODE(I1,I2,I3,I4,p1,p2), the application flow predictor can form a network address having I1.I2.I3.I4 and a port as (p1*256)+p2. Using a more specific example related to detecting the port command message "Enter passive mode 227 (192,168,20,101,117,254)", the application flow predictor can form the network address 192.168.20.101 and calculate the port as 30206.

[0037] In block 317, the application flow predictor creates a mapping 318 of predicted flow information for the identifier of the predictor protocol. The application flow predictor can use the predictor protocol identifier indicated in the first stage scan results. Using the above FTP example, the application flow predictor creates the mapping 192.168.20.101:30206 <-> FTP.

[0038] In block 321, the application flow predictor (or another process in the control plane of the inspection point) communicates the mapping to the data plane. This can be communicated using inter - process communication via an interface between the control plane and the data plane, etc.

[0039] Variations

[0040] This description refers to detecting or identifying signaling protocol messages within the traffic flow before branching to the second stage of scanning, but the embodiments are not so limited. The signaling protocol was selected as a representative type of predictor protocol because it often precedes ALG application traffic. (For example, SIP messages precede RTP audio streams).

[0041] The flowchart is provided to assist in the understanding of the example and should not be used to limit the scope of the claims. The flowchart shows exemplary operations that can be changed within the scope of the claims. Additional operations may be performed. That is, fewer operations may be performed, the operations may be performed in parallel, and the operations may be performed in a different order. It will be understood that each block of the flowchart illustration and / or block diagram, and combinations of blocks in the flowchart illustration and / or block diagram, can be implemented by program code. The program code can be provided to a processor of a general purpose computer, a special purpose computer, or other programmable machine or device.

[0042] As will be understood, aspects of the present disclosure can be embodied as a system, method, or program code / instructions stored in one or more machine-readable media. Accordingly, the aspects can take the form of hardware, software (including firmware, resident software, microcode, etc.), or a combination of software aspects and hardware aspects, which may generally be referred to herein as "circuit", "module", or "system". The functions presented as individual modules / units in the exemplary diagrams can be arranged differently according to any one of the platform (operating system and / or hardware), application ecosystem, interface, programmer preference, programming language, administrator preference, etc.

[0043] Any combination of one or more machine-readable media may be utilized. The machine-readable media may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable storage medium can be, for example, but not limited to, any one or a combination of electronic, magnetic, optical, electromagnetic, infrared, or semiconductor technologies for storing program code, or a system, apparatus, or device that employs such a combination. More specific examples (a non-exhaustive list) of the machine-readable storage medium would include the following. That is, portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing. In the context of this specification, the machine-readable storage medium can be any tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable storage medium is not a machine-readable signal medium.

[0044] The machine-readable signal medium can include, for example, a propagated data signal in which the machine-readable program code is embodied within the baseband or as part of a carrier wave. Such propagated signals can take any of a variety of forms, including, but not limited to, electromagnetic, optical, or any suitable combination thereof. The machine-readable signal medium is not a machine-readable storage medium and can be any machine-readable medium that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0045] The program code embodied on the machine-readable medium can be transmitted using any suitable medium, including, but not limited to, wireless, wired, fiber optic cable, RF, etc., or any suitable combination of the foregoing.

[0046] Program code / instructions may also be stored on a machine-readable medium that can direct a machine to function in a particular manner so as to produce a product including instructions stored thereon that perform the functions / operations specified in one or more blocks of a flowchart and / or block diagram.

[0047] Figure 4 shows an exemplary computer system having a data plane and a control plane, including an application flow predictor. The computer system includes a control plane 401 and a data plane 413. The control plane 401 includes a processor 403 (possibly including multiple processors, multiple cores, multiple nodes, and / or implementing multithreading, etc.). The computer system includes a memory 405. The memory 405 can be the system memory or any one or more of the possible realizations of the machine-readable medium described above. The control plane 401 also includes an application identification engine 407 that includes an application flow predictor 411. The processor 403 can implement the application identification engine 411 (e.g., execute instructions of program code). The application identification engine 407 is coupled to the processor 403 but can be an application-specific integrated circuit different from the processor 403. A communication channel 410 communicatively couples the control plane 401 to the data plane 413. The data plane 413 includes line cards 416A, 416B that communicate via a switch fabric 419. The line card 416A includes packet forwarding engines (PFEs) 417A, 417B. The line card 416B includes PFEs 417C, 417D. The application identification engine 407 differentiates the network traffic mirrored from at least one of the PFEs 417A - 417D and scans the differentiated flows against a primary database for application identification. When a predictor protocol message is detected in a flow from the application identification, the application flow predictor 411 scans the flow for pattern matches to predict future traffic for an application / data protocol (e.g., a cloud-based conferencing application or protocol), and extracts the predicted flow identification information to create a mapping between the predictor protocol and the predicted flow. The control plane 401 then communicates the mapping to the appropriate PFE for policy selection and enforcement.

[0048] The embodiments are not limited to deployment in network devices having line cards as shown in FIG. 4. The embodiments can be deployed, for example, as virtual firewalls or cloud-based firewalls.

[0049] Terminology

[0050] The use of the phrase “at least one of” preceding a list accompanied by the conjunction “and” should not be treated as an exclusive list and, unless otherwise specified, should not be construed as a list of categories having one item from each category. The phrase “at least one of A, B, and C” can be violated by only one of the listed items, by a plurality of the listed items, and by one or more of the listed items and another item not listed.

Claims

Claim 1 A method comprising: selecting a first signaling protocol pattern database from a plurality of signaling protocol pattern databases, wherein the selection is based at least in part on detecting messages of the first signaling protocol in a first network traffic flow, wherein the plurality of signaling protocol pattern databases are constructed using patterns corresponding to a plurality of different signaling protocols, a step; scanning the first network traffic flow for pattern matches in the first signaling protocol pattern database in a control plane; extracting first application traffic flow identification information indicative of an application or data protocol shown in a payload of the first network traffic flow corresponding to the pattern match based on the scan indicating a pattern match in the first signaling protocol pattern database; associating the identifier of the first signaling protocol with a first application traffic flow identifier based on the first application traffic flow identification information identifying information for generating a first mapping; communicating the first mapping from the control plane to a data plane; selecting a first policy among a plurality of policies in the data plane based on the first mapping; A method comprising the above steps. Claim 2 The method further comprises: detecting the messages of the first signaling protocol in the first network traffic flow, wherein the step of detecting the messages comprises: scanning the first network traffic flow for pattern matches in a first pattern matching database constructed using patterns for identifying applications and application layer protocols in the control plane. Based on the step of scanning for a match of a pattern in the first pattern matching database, which indicates a match of a pattern in the first pattern matching database, determining whether the match of the pattern in the first pattern matching database indicates a signaling protocol. The step of detecting the message of the first signaling protocol in the first network traffic flow is based on determining that the match of the pattern in the first pattern matching database pertains to the first signaling protocol. The method according to claim 1.

3. The step of extracting a first network traffic flow identifier from the first network traffic flow is based on an offset indication returned together with an indication of the match of the pattern. The first network traffic flow identifier includes a network address and a port. The method according to claim 1.

4. The method further includes mirroring the first network traffic flow from the data plane to the control plane. constructing a first signaling protocol pattern database using a pattern from a session description protocol description in the first signaling protocol message, and / or applying the first policy to network traffic corresponding to the first network traffic flow identifier. The method according to claim 2, including these steps.

5. The method further includes based on the step of scanning for a match of a second pattern in the signaling protocol pattern database, extracting second application traffic flow identification information for the application or data protocol indicated in the payload of the first network traffic flow, and forming a first application flow identifier using the first application traffic flow identification information and the second application traffic flow identification information. The method according to any one of claims 1 to 4, including these steps.

6. One or more non-transitory machine-readable storage media storing program code, the program code including instructions that, when executed, In a control plane, scan a payload of a first transport layer traffic flow for a pattern match in a first pattern database, Detect a session establishment message of a first application level protocol based on an indication of a pattern match in the first pattern database, Based on the detection of the session establishment message of the first application level protocol, select a second pattern database, the second pattern database being constructed using patterns of the first application level protocol, Scan the payload for a pattern match in the second pattern database, Based on the scan indicating a first pattern match in the second pattern database, create a first mapping between an identifier of the first application level protocol and a first application traffic flow identifier determined from at least a first payload of the payload corresponding to the first pattern match, and Communicate the first mapping from the control plane to a data plane, A non-transitory machine-readable storage media. **Claim 7** The program code further includes instructions that, when executed, In the data plane, select a first policy among a plurality of policies based on the first mapping, and Apply the first policy to network traffic corresponding to the first application traffic flow identifier following the first transport layer traffic flow, The non-transitory machine-readable storage media according to claim 6. **Claim 8** The program code further includes instructions that, when executed, Extract the first application traffic flow identifier from the first payload, The instructions for extracting the first application traffic flow identifier from the first payload, when executed, Based on the scan indicating the first pattern match in the second pattern database, extract a network address from the first payload, and Extract a port from the first payload based on an indication of a match of a second pattern in the second pattern database, The network address and the port form the first application traffic flow identifier, The non-transitory machine-readable storage medium according to claim 7. **Claim 9** The second pattern database is a regular expression database, The non-transitory machine-readable storage medium according to any one of claims 6 to 8. **Claim 10** An apparatus comprising: A processor; and A non-transitory machine-readable storage medium storing instructions, When the instructions are executed by the processor, the apparatus is caused to: Scan the payload of a first transport layer traffic flow for a match of a pattern in a first pattern database, Detect a session establishment message of a first application level protocol based on the scan indicating a match of a pattern in the first pattern database, Select a second pattern database from a plurality of pattern databases based on the detection of the session establishment message, the plurality of pattern databases being constructed using patterns of an application level protocol, Scan a first network traffic flow for one or more matches in the second pattern database, Create a first mapping between an identifier of the first application level protocol and a first predicted traffic flow determined at least in part based on the first match, based on the scan for matches in the second pattern database indicating at least a first match in the second pattern database, and Communicate the first mapping to a data plane. An apparatus. **Claim 11** The non-transitory machine-readable storage medium further includes instructions, When the instructions are executed by the processor, the apparatus is caused to: Extract a first application traffic flow identifier from at least a first payload in the first network traffic flow corresponding to the first match. The apparatus according to claim 10. **Claim 12** The instructions for extracting the first application traffic flow identifier from the first payload are Extract a network address from the first payload based on the scan for the match in the second pattern database indicating the first match in the second pattern database. Extract a port from the first payload based on an indication of a second match in the second pattern database. including an instruction to cause; The network address and the port form the first application traffic flow identifier, and The non-transitory machine-readable storage medium further stores instructions that, when executed by the processor, cause the apparatus to Determine an offset for extracting the network address and the port based at least in part on the first match. The apparatus according to claim 11, which causes the apparatus to perform the above. **Claim 13** The first application level protocol is a session initiation protocol. The apparatus according to claim 10. **Claim 14** The non-transitory machine-readable storage medium further stores instructions that, when executed by the processor, cause the apparatus to Create a second mapping between the identifier of the first application level protocol and the identifier of a second predicted traffic flow determined based at least in part on a second match in the second pattern database. The apparatus according to claim 10, which causes the apparatus to perform the above.

Citation Information

Patent Citations

  • Network intrusion prevention method, device and system and computer readable storage medium

    CN107872456A

  • Dos attack countermeasure system and dos attack countermeasure method

    JP2006235876A

  • Sip communication system, sip gateway device and sip communication control method used for the same

    JP2007235638A

  • Communication controller and communication control method used therefore, and program thereof

    JP2008017075A

  • Information processing device, method and program

    JP2016127394A