Adaptive Control Protocol Templates for Network Traffic Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively detect and attribute new command-and-control (C&C) domain names used by malware, as they often rely on limited protocols and do not adapt well to varying network traffic patterns, leading to high false positives and missed detections.

Innovation Solution

The system generates adaptive control protocol templates (CPTs) by learning from known C&C communications, considering the entire content of HTTP requests, and deploying them at network edges to detect traffic destined for new C&C domains, while self-tuning to specific deployment scenarios to minimize false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current systems use limited protocols and do not adapt to varying network traffic patterns, then device complexity is reduced, but detection precision and reliability deteriorate with high false positives and missed detections

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system dynamically adapts to varying network traffic patterns by learning from observed traffic characteristics and adjusting detection parameters in real-time. The protocol template generation process creates adaptive models that evolve with changing traffic conditions, allowing the system to maintain high detection precision without requiring overly complex static configurations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-learning and self-adjustment by automatically generating protocol templates from observed traffic patterns. This self-service capability enables the system to improve its own detection accuracy without external intervention, reducing the need for complex manual configuration while maintaining high measurement precision.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If the system considers the entire content of HTTP requests for detection, then detection precision improves, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts and focuses on the most discriminative features from HTTP request content rather than analyzing every byte. By identifying and prioritizing key indicators of command-and-control traffic, the system achieves high detection precision while significantly reducing the computational burden and processing time compared to exhaustive content analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies different levels of analysis to different parts of the HTTP request based on their diagnostic value. Critical fields such as headers and specific payload patterns receive intensive analysis, while less informative portions are processed more efficiently, optimizing the balance between detection precision and processing speed.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If adaptive templates are deployed at network edges to detect new C&C domains, then detection capability improves, but false positives may increase without proper self-tuning

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system incorporates feedback mechanisms that allow templates to self-tune based on their performance in specific deployment scenarios. By continuously monitoring detection outcomes and adjusting template parameters accordingly, the system maintains high adaptability to new threats while minimizing false positives through iterative optimization.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically adjusts template parameters based on deployment context and observed traffic characteristics. This parameter adaptation allows the same template framework to operate effectively across diverse network environments while maintaining appropriate sensitivity thresholds to reduce false positives in each specific scenario.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10050986B2Systems and methods for traffic classification
Publication Date: 2018.08.14 FORTRA LLC
  • US10050986B2 patent drawing
  • US10050986B2 patent drawing
  • US10050986B2 patent drawing

AI summary

Systems and methods of classifying network traffic may monitor network traffic. Monitored traffic may be compared with a control protocol template (CPT). When a similarity between the monitored traffic and the CPT exceeds a match threshold, the monitored traffic may be associated with the CPT.