Application Identification Engine Scoring Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network systems lack comprehensive and integrated control mechanisms to manage access and usage across all users and devices, especially in scenarios where users access networks from alternate or unknown devices, and struggle to identify and enforce policies effectively, particularly with applications that evade fingerprinting due to encryption and advanced evasion techniques.

Innovation Solution

The implementation of an application identification function using an engine that employs signature-based parsing, heuristic processing, and a scoring system to reliably identify applications, combined with a dynamic traffic mirroring function that selectively mirrors network traffic to enable efficient monitoring and policy enforcement, allowing for granular control and management of network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network control mechanisms are used, then basic network access is managed, but comprehensive control over applications and users accessing from alternate devices is insufficient

Engineering Contradiction:
Improvenetwork control reliabilityVSAvoidcontrol coverage for alternate devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network control function is segmented into multiple independent components: application identification engine, traffic mirroring function, scoring mechanism, and policy enforcement module. This segmentation allows each component to specialize in specific tasks, improving overall control reliability while enabling comprehensive monitoring of all devices accessing the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The application identification engine is designed with multi-functionality to handle various identification techniques (signature-based, heuristic, statistical) and work with different types of network traffic and devices. This universal approach ensures reliable control across diverse devices and applications, addressing both reliability and adaptability requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If application identification uses multiple techniques (signature-based, heuristic, statistical), then identification accuracy improves, but system complexity increases

Engineering Contradiction:
Improveapplication identification accuracyVSAvoididentification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Multiple application identification techniques (signature-based parsing, heuristic processing, statistical analysis) are merged into a single integrated application identification engine. The engine combines these techniques and uses a scoring mechanism to evaluate results, achieving high identification accuracy while managing complexity through unified architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback through the scoring mechanism that evaluates identification results from multiple techniques. The scoring feedback allows the system to weigh different identification methods appropriately and adjust to improve accuracy while maintaining manageable complexity through intelligent resource allocation.

Inventive Principle:
Principle #23Feedback

3Productivity

If dynamic traffic mirroring is implemented, then monitoring efficiency improves, but network bandwidth consumption increases

Engineering Contradiction:
Improvemonitoring efficiencyVSAvoidbandwidth consumption
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The dynamic traffic mirroring function implements partial action by selectively mirroring only the portion of network traffic that is necessary for application identification and policy enforcement. Instead of mirroring all traffic, the system mirrors only relevant flows, improving monitoring efficiency while minimizing bandwidth consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The traffic mirroring function is designed to be dynamic, adjusting its operation based on current network conditions, identified applications, and policy requirements. This dynamic behavior allows the system to optimize monitoring efficiency while consuming minimal bandwidth by activating mirroring only when and where necessary.

Inventive Principle:
Principle #15Dynamics

4Reliability

If encryption and evasion techniques are used by applications, then application privacy is protected, but network policy enforcement becomes difficult

Engineering Contradiction:
Improveapplication privacy protectionVSAvoidpolicy enforcement ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system introduces an intermediary approach through the application identification engine that can detect and analyze encrypted traffic patterns without decrypting the content. The engine uses heuristic and statistical methods to identify applications behind encryption, enabling policy enforcement while preserving application privacy and encrypted communication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9230213B2Device and related method for scoring applications running on a network
Publication Date: 2016.01.05 EXTREME NETWORKS INC
  • US9230213B2 patent drawing
  • US9230213B2 patent drawing
  • US9230213B2 patent drawing

AI summary

A function is provided for effectively identifying computer applications running on a network. The function receives information related to frames of packets moving through the network. The information is compared to known information about computer applications. The known information is obtained from a plurality of mechanisms, including the option of obtaining it through custom mechanisms. The comparison information is scored for each of the plurality of mechanisms and those scores are combined to establish a single score indicative of the likely computer application associated with the received frames. One or more mathematical operations can be used to combine the scores. The mechanisms may be weighted for likely accuracy and the score that is established may include with it an indication of the level of confidence in that score. One or more of the plurality of mechanisms may be used to weight others of the types of mechanisms.