Active Session Initiation for Protocol Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Deep Packet Inspection (DPI) methods struggle to identify certain communication protocols, particularly Peer-to-Peer (P2P) protocols that use obfuscation techniques, leading to difficulties in tracking protocol variants and attributes, resulting in ineffective protocol identification and classification.
Innovation Solution
The proposed solution involves behavioral characterization of network traffic to identify suspected communication sessions, followed by initiating an imitated communication session using the target protocol to positively confirm protocol usage, allowing for accurate classification and control of sessions, even when DPI methods fail due to countermeasures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If DPI methods are used to identify communication protocols, then protocol identification capability is improved, but effectiveness deteriorates when protocols use obfuscation techniques
Solution Approach 1:
The patent segments the protocol identification process into two distinct phases: passive behavioral analysis phase and active verification phase. The behavioral analysis segment monitors traffic patterns, packet sizes, and timing characteristics without interfering with normal traffic. The active verification segment then initiates test sessions to confirm protocol identification. This segmentation allows the system to maintain high identification capability while achieving reliable verification even against obfuscated protocols.
Solution Approach 2:
The patent performs preliminary behavioral analysis before final protocol identification. By monitoring communication patterns, packet structures, and session characteristics in advance, the system builds a profile of suspected protocols. This preliminary action enables the system to prepare verification strategies and reduce the complexity of active testing, thereby maintaining identification effectiveness despite protocol obfuscation.
2Measurement precision
If active session initiation is used to confirm protocol usage, then identification accuracy is improved, but processing complexity increases
Solution Approach 1:
The patent applies partial action by initiating active verification sessions only for traffic that exhibits suspicious behavioral characteristics during passive monitoring. Instead of actively testing all traffic, the system selectively applies active verification only when behavioral analysis indicates potential protocol violations or unidentified traffic patterns. This partial approach maintains high identification accuracy while significantly reducing processing complexity compared to universal active testing.
Solution Approach 2:
The patent introduces an intermediary classification engine that acts as a mediator between passive behavioral analysis and active verification. This intermediary component analyzes behavioral data, determines verification necessity, and manages active session initiation. By inserting this intermediary layer, the system achieves accurate protocol identification through coordinated multi-phase processing while managing complexity through centralized control and selective verification.
3Reliability
If behavioral characterization is used to identify suspected sessions, then protocol detection capability is improved, but processing time increases
Solution Approach 1:
The patent implements periodic action by conducting behavioral analysis at regular intervals rather than continuously monitoring every packet. The system samples traffic patterns at defined periods, analyzes behavioral characteristics at these intervals, and triggers active verification only when periodic analysis identifies suspicious patterns. This periodic approach maintains reliable protocol detection capability while significantly reducing processing time compared to continuous deep inspection of all traffic.
Data Source
AI summary
A method includes measuring behavioral characteristics of a plurality of communication sessions in a communication network. A subset of the sessions is identified using the behavioral characteristics, such that the sessions in the subset are suspected of using a target communication protocol. A candidate session is selected from the subset. A trial communication session is initiated with a node of the communication network, which participates in the candidate session, using the target communication protocol. Responsively to receiving a positive response from the node to initiation of the trial communication session, it is determined that one or more further sessions in the plurality are using the target communication protocol. The one or more further sessions are controlled responsively to a predetermined control criterion that is applicable to the target communication protocol.


