Application Classifier for Compressed Encrypted Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network technologies face challenges in classifying and managing applications over compressed or encrypted traffic, as these processes conflict with and are complicated by wide area network compression and encryption techniques.
Innovation Solution
A system and method that classify and manage applications by receiving uncompressed traffic, determining an application classifier, saving it, and propagating it to compressed or encrypted interfaces, allowing for accurate identification and management of applications even in optimized or secured network conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If compression or encryption techniques are applied to network traffic, then network bandwidth efficiency and security are improved, but application classification and management capabilities deteriorate
Solution Approach 1:
The system performs application classification on uncompressed traffic before the traffic enters the compression or encryption pipeline. By determining the application type early in the data flow, the system can propagate this classification information through subsequent compression and encryption stages, enabling accurate application identification even when the actual traffic data is transformed. This preliminary classification action resolves the contradiction by establishing application identity before bandwidth optimization techniques obscure the original data characteristics.
2Productivity
If compression techniques are applied to network traffic, then network bandwidth utilization is improved, but application identification capability deteriorates
Solution Approach 1:
The system introduces an intermediary application classifier component that sits between the traffic source and the compression mechanism. This classifier analyzes uncompressed traffic to determine application types and propagates classification information through the compression pipeline. The intermediary acts as a bridge, enabling application identification without interfering with the compression process's bandwidth optimization benefits, thus resolving the contradiction between bandwidth utilization and application detection capability.
3Reliability
If encryption techniques are applied to network traffic, then data security is improved, but application management capability deteriorates
Solution Approach 1:
The system performs application classification and management decisions before traffic enters the encryption pipeline. By determining application types and applying appropriate management policies on uncompressed, unencrypted traffic, the system maintains full application management capability while preserving data security through subsequent encryption. This preliminary action allows administrators to manage applications effectively without compromising security benefits.
4Measurement precision
If behavioral or statistical mechanisms are used for application classification over compressed traffic, then application identification may be achieved, but system complexity increases
Solution Approach 1:
The system extracts application classification from the compressed or encrypted traffic stream by performing classification on the original uncompressed traffic before compression or encryption occurs. This extraction approach eliminates the need for complex behavioral or statistical analysis mechanisms that would be required to classify applications within compressed or encrypted data. The classification information is determined once upfront and propagated through the pipeline, significantly reducing system complexity while maintaining identification accuracy.
Data Source
AI summary
System and methods for identifying and managing applications over compressed or encrypted traffic in a network are described. The first and second embodiments, which provides a method for managing applications over compressed or encrypted traffic respectively, comprise identifying applications on the traffic, saving the application classification per connection, and propagating the application classification to the network. A method for providing application identification over compressed or encrypted traffic is also disclosed, which includes an application recognition module configured to, among other functions, determine an application classifier for compressed or encrypted traffic without applying an application classification process, and utilize the application classification for previous packets originating from the connection for the current packets from the same connection.


