Application Identification Function for Network Security Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network systems lack comprehensive and integrated control mechanisms to manage access and usage across all users and devices, especially in BYOD and Cloud Computing environments, where the rapid increase in application types and models poses challenges for security and efficiency.

Innovation Solution

The implementation of an application identification function, dynamic traffic mirroring, and policy-based dynamic mirroring within a network system controller, which uses signature languages and heuristic processing to characterize applications and enforce policies dynamically, allowing for granular control and monitoring of network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network control mechanisms are used, then basic network connectivity is maintained, but comprehensive application-level control and security are insufficient

Engineering Contradiction:
Improvenetwork securityVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an application identification function as an intermediary component between the network infrastructure and attached functions. This function acts as a mediator that identifies applications, determines their trustworthiness scores, and provides this information to the network control manager, which then enforces appropriate policies. This intermediary approach enhances security without requiring complete redesign of the entire network control architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network control system is segmented into distinct functional components: the application identification function that analyzes traffic and identifies applications, the network control manager that receives identification results and determines policies, and the policy enforcement points that execute control actions. This segmentation allows each component to specialize in specific tasks, improving overall security while maintaining manageable complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

2Productivity

If comprehensive application identification and control is implemented, then security and efficiency are enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic policy enforcement where network control policies are not static but adapt based on real-time application identification results and trustworthiness scores. The network control manager dynamically determines appropriate policies based on the identified application and its trustworthiness level, allowing the system to respond flexibly to different traffic patterns and security threats without requiring complex manual configuration for each scenario.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where the application identification function continuously monitors network traffic, identifies applications, and provides identification results back to the network control manager. The control manager then adjusts policies based on this feedback and communicates enforcement decisions back to the network infrastructure. This closed-loop feedback mechanism enables automated adaptation and optimization of network control without requiring complex manual intervention.

Inventive Principle:
Principle #23Feedback

3Speed

If minimal data is used for application identification, then processing speed is maintained, but identification accuracy may be compromised

Engineering Contradiction:
Improveidentification speedVSAvoidapplication identification accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The application identification function implements partial action by analyzing only the most relevant and informative packets from each network flow rather than examining every packet in detail. The system identifies key identifying features from a subset of traffic data, which is sufficient for accurate application identification while maintaining high processing speed. This selective analysis approach balances the trade-off between speed and accuracy by focusing computational resources on the most critical identification tasks.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4002866A1A device and method to establish a score for a computer application
Publication Date: 2022.05.25 EXTREME NETWORKS INC
  • EP4002866A1 patent drawingFigure 1
  • EP4002866A1 patent drawingFigure 2
  • EP4002866A1 patent drawingFigure 3

AI summary

Functions are provided in a network system for policy-based dynamic mirroring for network traffic, such as for identifying characteristics of network traffic, adjusting network policies based on identified traffic characteristics, identifying computer applications running on the network. The functions monitor events, topology and status of the network and installs, enables, selects or changes traffic mirrors associated with the operation of one or more devices of the network. Traffic may be selectively mirrored. Portals may be selected for mirroring activity. Policies changed may be network policies as well as mirroring policies. Information obtained from frames having content associated with computer applications is examined and compared to information stored on the network (1520). An application identification engine of the function compares examined content with known application information and determines an indication of the likely computer application associated with the examined frames (1530). A network architecture system enables application identification and usage data, by user, by device and network location. The architecture enables substantially complete application visibility and control. Scores are generated to aid in the determination of the likely computer application associated with received frames. Designation information optionally includes an indication of the confidence in the designation. An optional step of the method (1500) is to weight the likely accuracy of the one or more indicators in the comparison.