Application Detection Engine Dynamic Rule Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing network-based applications face challenges in detecting and identifying poorly-behaved applications that evade detection through techniques like dynamic port selection, HTTP/HTTPS tunneling, and encryption, leading to inadequate information for reliable detection and control.
Innovation Solution
A data-driven model for an application detection engine that collects and analyzes information about network-based applications, generates data structures and rule sets, and dynamically updates detection logic to identify and manage network traffic, using a layered approach with single inspection point, multiple inspection point, and custom dissector engines for accurate detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network monitoring methods are used to detect applications, then basic network traffic can be monitored, but poorly-behaved applications using evasion techniques cannot be reliably detected
Solution Approach 1:
The system dynamically adapts its detection methods by switching between single inspection point and multiple inspection point approaches based on the detected application behavior. When evasive applications are identified using techniques like dynamic port selection or HTTP tunneling, the system activates multiple inspection points to track the application across different network layers and time periods, thereby maintaining detection reliability against adapting threats.
Solution Approach 2:
The patent adds temporal and spatial dimensions to application detection by implementing multiple inspection points that observe network traffic from different locations and time periods. This multi-dimensional approach allows the system to reconstruct application behavior patterns even when applications evade detection at any single inspection point, resolving the contradiction between reliable detection and adaptability to evasive techniques.
2Measurement precision
If multiple inspection points are used to detect evasive applications, then detection accuracy improves, but system complexity increases
Solution Approach 1:
The system segments the detection functionality into distinct inspection points, each responsible for specific detection tasks at different network locations. This segmentation allows the complex multi-point inspection system to be managed as modular components, where each inspection point can be independently configured and maintained, thereby reducing overall system complexity while maintaining high detection accuracy through coordinated observation.
Solution Approach 2:
The inspection points are designed with universal functionality to handle multiple detection scenarios and application types. Each inspection point can detect various application behaviors including standard protocols, encrypted traffic, and evasive techniques, eliminating the need for specialized inspection points for each threat type. This multi-functionality reduces system complexity by standardizing detection capabilities across all inspection points.
3Loss of information
If comprehensive information collection about network applications is performed, then detection capability improves, but information processing load increases
Solution Approach 1:
The system extracts only the most relevant information features from comprehensive network traffic data for detection purposes. Rather than processing all collected information, the system identifies and extracts key characteristics such as traffic patterns, protocol behaviors, and application signatures that are most indicative of poorly-behaved applications. This extraction process maintains information completeness for detection while significantly reducing processing load by focusing on critical features.
Solution Approach 2:
The system collects comprehensive information but applies partial processing only where necessary for detection. Information is fully collected to ensure completeness, but processing is applied selectively to relevant data subsets based on detection needs and threat levels. This approach maintains information completeness while optimizing processing efficiency by avoiding unnecessary processing of all collected data.
Data Source
AI summary
In various embodiments, a data-driven model is provided for an application detection engine for the detection and identification of network-based applications. In one embodiment, information can be input into an application detection database. The information may include a hostname, ports, transport protocol (TCP/UDP), higher layer protocol (SOCKS, HTTP, SMTP, FTP, etc), or the like. The information may be associated with a given application. The information may be used to create rule sets or custom program logic used by one or more various application detection engines for determining whether network traffic has been initiated by a given application. The information may be dynamically loaded and updated at the application detection engine.


