Application Identification via Dynamic Traffic Mirroring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network systems lack comprehensive and integrated control mechanisms to manage access and usage across all users and devices, especially in scenarios where users access networks from alternate or unknown devices, and struggle to identify and enforce policies effectively, particularly with applications that evade fingerprinting like encrypted Bittorrent and Skype.

Innovation Solution

The implementation of an application identification function using a scoring system that combines signature-based and heuristic processing, along with dynamic traffic mirroring, allows for the characterization of applications running on the network by snoopings flows and examining packet frames, enabling reliable application fingerprinting and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional network control mechanisms are used, then network access is restricted based on user identity, but applications running on unknown or alternate devices cannot be effectively identified or controlled

Engineering Contradiction:
Improvenetwork access controlVSAvoidapplication identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent replaces traditional identity-based network control mechanisms with application-based control using deep packet inspection. Instead of relying on user authentication and device identification, the system examines packet contents, protocols, and traffic patterns to identify applications running on any device connected to the network, enabling precise control regardless of device identity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a network monitoring and control device as an intermediary between network traffic and policy enforcement. This intermediary device captures packets, analyzes application behavior, and enforces policies based on application identification rather than device identity, bridging the gap between traditional control mechanisms and modern application-based networking needs

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encrypted applications like Bittorrent and Skype are used, then user privacy is protected, but application fingerprinting becomes difficult or impossible

Engineering Contradiction:
Improveprivacy protectionVSAvoidapplication fingerprinting accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent performs preliminary analysis of encrypted traffic by examining packet headers, protocols, and traffic patterns before the encrypted payload can be inspected. By analyzing characteristics that exist outside the encrypted portion of packets, the system can identify applications like Bittorrent and Skype without requiring decryption, maintaining both privacy protection and identification accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameters used for application identification from content-based analysis to metadata-based analysis. Instead of attempting to fingerprint applications through their encrypted payload content, the system identifies applications through unchanged parameters such as packet timing, size patterns, protocol handshakes, and header information that remain visible even in encrypted traffic

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive network monitoring is implemented, then application identification accuracy improves, but network device complexity and processing overhead increase

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidnetwork monitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network monitoring function into distinct modules: packet capture, protocol analysis, application identification, and policy enforcement. Each module handles specific tasks independently, reducing overall system complexity while maintaining comprehensive monitoring capabilities. This modular approach allows the system to process traffic efficiently without requiring a single complex device to perform all functions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial monitoring by analyzing only the portions of packets necessary for application identification rather than examining complete packet contents. By focusing on specific protocol fields, packet headers, and traffic patterns while ignoring unnecessary data, the system achieves accurate application identification with reduced processing overhead and simpler device requirements

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9813447B2Device and related method for establishing network policy based on applications
Publication Date: 2017.11.07 EXTREME NETWORKS INC
  • US9813447B2 patent drawing
  • US9813447B2 patent drawing
  • US9813447B2 patent drawing

AI summary

A function is provided in a network system for adjusting network policies associated with the operation of network infrastructure devices of the network system. Network policies are established on network devices including packet forwarding devices. The network has a capability to identify computer applications associated with traffic running on the network. A network policy controller of the network is arranged to change one or more policies of one or more network devices based on computer application information acquired. The policies changed may be network policies as well as mirroring policies. An example policy to change is direct a network device to mirror traffic to an application identification appliance for the purpose of identifying applications running on the network through a plurality of mechanisms. The function may be provided in one or more devices of the network.