Active Session Initiation for Protocol Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Deep Packet Inspection (DPI) methods struggle to identify certain communication protocols, particularly Peer-to-Peer (P2P) protocols that use obfuscation techniques, leading to difficulties in tracking protocol variants and attributes, resulting in ineffective protocol identification and classification.

Innovation Solution

The proposed solution involves behavioral characterization of network traffic to identify suspected communication sessions, followed by initiating an imitated communication session using the target protocol to positively confirm protocol usage, allowing for accurate classification and control of sessions, even when DPI methods fail due to countermeasures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If DPI methods are used to identify communication protocols, then protocol identification capability is improved, but effectiveness deteriorates when protocols use obfuscation techniques

Engineering Contradiction:
Improveprotocol identification capabilityVSAvoididentification effectiveness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the protocol identification process into two distinct phases: passive behavioral analysis phase and active verification phase. The behavioral analysis segment monitors traffic patterns, packet sizes, and timing characteristics without interfering with normal traffic. The active verification segment then initiates test sessions to confirm protocol identification. This segmentation allows the system to maintain high identification capability while achieving reliable verification even against obfuscated protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary behavioral analysis before final protocol identification. By monitoring communication patterns, packet structures, and session characteristics in advance, the system builds a profile of suspected protocols. This preliminary action enables the system to prepare verification strategies and reduce the complexity of active testing, thereby maintaining identification effectiveness despite protocol obfuscation.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If active session initiation is used to confirm protocol usage, then identification accuracy is improved, but processing complexity increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies partial action by initiating active verification sessions only for traffic that exhibits suspicious behavioral characteristics during passive monitoring. Instead of actively testing all traffic, the system selectively applies active verification only when behavioral analysis indicates potential protocol violations or unidentified traffic patterns. This partial approach maintains high identification accuracy while significantly reducing processing complexity compared to universal active testing.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent introduces an intermediary classification engine that acts as a mediator between passive behavioral analysis and active verification. This intermediary component analyzes behavioral data, determines verification necessity, and manages active session initiation. By inserting this intermediary layer, the system achieves accurate protocol identification through coordinated multi-phase processing while managing complexity through centralized control and selective verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If behavioral characterization is used to identify suspected sessions, then protocol detection capability is improved, but processing time increases

Engineering Contradiction:
Improveprotocol detection capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic action by conducting behavioral analysis at regular intervals rather than continuously monitoring every packet. The system samples traffic patterns at defined periods, analyzes behavioral characteristics at these intervals, and triggers active verification only when periodic analysis identifies suspicious patterns. This periodic approach maintains reliable protocol detection capability while significantly reducing processing time compared to continuous deep inspection of all traffic.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS7996520B2Behavioral classification of communication sessions using active session initiation
Publication Date: 2011.08.09 CISCO TECHNOLOGY INC
  • US7996520B2 patent drawing
  • US7996520B2 patent drawing
  • US7996520B2 patent drawing

AI summary

A method includes measuring behavioral characteristics of a plurality of communication sessions in a communication network. A subset of the sessions is identified using the behavioral characteristics, such that the sessions in the subset are suspected of using a target communication protocol. A candidate session is selected from the subset. A trial communication session is initiated with a node of the communication network, which participates in the candidate session, using the target communication protocol. Responsively to receiving a positive response from the node to initiation of the trial communication session, it is determined that one or more further sessions in the plurality are using the target communication protocol. The one or more further sessions are controlled responsively to a predetermined control criterion that is applicable to the target communication protocol.