Application Identification Engine Scoring Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network systems lack comprehensive and integrated control mechanisms to manage access and usage across all users and devices, especially in scenarios where users access networks from alternate or unknown devices, and struggle to identify and enforce policies effectively, particularly with applications that evade fingerprinting due to encryption and advanced evasion techniques.
Innovation Solution
The implementation of an application identification function using an engine that employs signature-based parsing, heuristic processing, and a scoring system to reliably identify applications, combined with a dynamic traffic mirroring function that selectively mirrors network traffic to enable efficient monitoring and policy enforcement, allowing for granular control and management of network resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network control mechanisms are used, then basic network access is managed, but comprehensive control over applications and users accessing from alternate devices is insufficient
Solution Approach 1:
The network control function is segmented into multiple independent components: application identification engine, traffic mirroring function, scoring mechanism, and policy enforcement module. This segmentation allows each component to specialize in specific tasks, improving overall control reliability while enabling comprehensive monitoring of all devices accessing the network.
Solution Approach 2:
The application identification engine is designed with multi-functionality to handle various identification techniques (signature-based, heuristic, statistical) and work with different types of network traffic and devices. This universal approach ensures reliable control across diverse devices and applications, addressing both reliability and adaptability requirements.
2Measurement precision
If application identification uses multiple techniques (signature-based, heuristic, statistical), then identification accuracy improves, but system complexity increases
Solution Approach 1:
Multiple application identification techniques (signature-based parsing, heuristic processing, statistical analysis) are merged into a single integrated application identification engine. The engine combines these techniques and uses a scoring mechanism to evaluate results, achieving high identification accuracy while managing complexity through unified architecture.
Solution Approach 2:
The system implements feedback through the scoring mechanism that evaluates identification results from multiple techniques. The scoring feedback allows the system to weigh different identification methods appropriately and adjust to improve accuracy while maintaining manageable complexity through intelligent resource allocation.
3Productivity
If dynamic traffic mirroring is implemented, then monitoring efficiency improves, but network bandwidth consumption increases
Solution Approach 1:
The dynamic traffic mirroring function implements partial action by selectively mirroring only the portion of network traffic that is necessary for application identification and policy enforcement. Instead of mirroring all traffic, the system mirrors only relevant flows, improving monitoring efficiency while minimizing bandwidth consumption.
Solution Approach 2:
The traffic mirroring function is designed to be dynamic, adjusting its operation based on current network conditions, identified applications, and policy requirements. This dynamic behavior allows the system to optimize monitoring efficiency while consuming minimal bandwidth by activating mirroring only when and where necessary.
4Reliability
If encryption and evasion techniques are used by applications, then application privacy is protected, but network policy enforcement becomes difficult
Solution Approach 1:
The system introduces an intermediary approach through the application identification engine that can detect and analyze encrypted traffic patterns without decrypting the content. The engine uses heuristic and statistical methods to identify applications behind encryption, enabling policy enforcement while preserving application privacy and encrypted communication reliability.
Data Source
AI summary
A function is provided for effectively identifying computer applications running on a network. The function receives information related to frames of packets moving through the network. The information is compared to known information about computer applications. The known information is obtained from a plurality of mechanisms, including the option of obtaining it through custom mechanisms. The comparison information is scored for each of the plurality of mechanisms and those scores are combined to establish a single score indicative of the likely computer application associated with the received frames. One or more mathematical operations can be used to combine the scores. The mechanisms may be weighted for likely accuracy and the score that is established may include with it an indication of the level of confidence in that score. One or more of the plurality of mechanisms may be used to weight others of the types of mechanisms.


