Application Detection Engine Dynamic Rule Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing network-based applications face challenges in detecting and identifying poorly-behaved applications that evade detection through techniques like dynamic port selection, HTTP/HTTPS tunneling, and encryption, leading to inadequate information for reliable detection and control.

Innovation Solution

A data-driven model for an application detection engine that collects and analyzes information about network-based applications, generates data structures and rule sets, and dynamically updates detection logic to identify and manage network traffic, using a layered approach with single inspection point, multiple inspection point, and custom dissector engines for accurate detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network monitoring methods are used to detect applications, then basic network traffic can be monitored, but poorly-behaved applications using evasion techniques cannot be reliably detected

Engineering Contradiction:
Improvedetection reliabilityVSAvoidability to detect evasive applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its detection methods by switching between single inspection point and multiple inspection point approaches based on the detected application behavior. When evasive applications are identified using techniques like dynamic port selection or HTTP tunneling, the system activates multiple inspection points to track the application across different network layers and time periods, thereby maintaining detection reliability against adapting threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent adds temporal and spatial dimensions to application detection by implementing multiple inspection points that observe network traffic from different locations and time periods. This multi-dimensional approach allows the system to reconstruct application behavior patterns even when applications evade detection at any single inspection point, resolving the contradiction between reliable detection and adaptability to evasive techniques.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If multiple inspection points are used to detect evasive applications, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the detection functionality into distinct inspection points, each responsible for specific detection tasks at different network locations. This segmentation allows the complex multi-point inspection system to be managed as modular components, where each inspection point can be independently configured and maintained, thereby reducing overall system complexity while maintaining high detection accuracy through coordinated observation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The inspection points are designed with universal functionality to handle multiple detection scenarios and application types. Each inspection point can detect various application behaviors including standard protocols, encrypted traffic, and evasive techniques, eliminating the need for specialized inspection points for each threat type. This multi-functionality reduces system complexity by standardizing detection capabilities across all inspection points.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If comprehensive information collection about network applications is performed, then detection capability improves, but information processing load increases

Engineering Contradiction:
Improveinformation completenessVSAvoidinformation processing efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The system extracts only the most relevant information features from comprehensive network traffic data for detection purposes. Rather than processing all collected information, the system identifies and extracts key characteristics such as traffic patterns, protocol behaviors, and application signatures that are most indicative of poorly-behaved applications. This extraction process maintains information completeness for detection while significantly reducing processing load by focusing on critical features.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system collects comprehensive information but applies partial processing only where necessary for detection. Information is fully collected to ensure completeness, but processing is applied selectively to relevant data subsets based on detection needs and threat levels. This approach maintains information completeness while optimizing processing efficiency by avoiding unnecessary processing of all collected data.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8413111B2Techniques for dynamic updating and loading of custom application detectors
Publication Date: 2013.04.02 ACTIANCE INC
  • US8413111B2 patent drawing
  • US8413111B2 patent drawing
  • US8413111B2 patent drawing

AI summary

In various embodiments, a data-driven model is provided for an application detection engine for the detection and identification of network-based applications. In one embodiment, information can be input into an application detection database. The information may include a hostname, ports, transport protocol (TCP/UDP), higher layer protocol (SOCKS, HTTP, SMTP, FTP, etc), or the like. The information may be associated with a given application. The information may be used to create rule sets or custom program logic used by one or more various application detection engines for determining whether network traffic has been initiated by a given application. The information may be dynamically loaded and updated at the application detection engine.