Bursty Flow Profiling for Encrypted Network Performance Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network performance monitoring and optimization techniques are challenged by the encryption of endpoint names in DNS requests and end-to-end encryption, making it difficult to identify and classify data traffic, particularly in environments with both traditional and bursty data transfers.

Innovation Solution

A method using machine learning to detect bursty data transfers, infer flow burst and pause profiles, and manage networks accordingly, employing a neural network to classify and optimize data transport policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network monitoring techniques use DNS spying and reverse-matching to identify endpoints, then data traffic classification is accurate, but the technique becomes obsolete with TLS 1.3 encryption

Engineering Contradiction:
Improvedata traffic classification accuracyVSAvoidcompatibility with encrypted protocols
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary approach by using packet behavior patterns as a mediator between the monitor and the encrypted data. Instead of directly analyzing encrypted payload content, the system observes metadata patterns (timing, sequencing, size distributions) that reveal traffic characteristics without decrypting the actual data, thus maintaining classification accuracy while adapting to encryption protocols like TLS 1.3

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If Deep Packet Inspection is used to monitor data traffic, then traffic analysis is comprehensive, but the technique becomes obsolete with end-to-end encryption

Engineering Contradiction:
Improvetraffic analysis capabilityVSAvoidencryption obsolescence
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the useful information from the encrypted data by taking out only the metadata and behavioral patterns that can be observed without decryption. The system extracts timing information, packet size distributions, sequencing patterns, and flow characteristics from the packet headers and timing data, separating these observable features from the encrypted payload content, thereby maintaining analysis capability while respecting encryption

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If network monitoring relies on identifying endpoint entities, then data transfer optimization is effective, but it fails when entities use encrypted connections

Engineering Contradiction:
Improvedata transfer optimizationVSAvoidendpoint identity information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent changes the parameters used for identification from static endpoint identities to dynamic behavioral parameters. Instead of relying on fixed endpoint labels that are obscured by encryption, the system uses temporal parameters (timing patterns, inter-packet delays), statistical parameters (packet size distributions, throughput variations), and sequential parameters (flow patterns, connection establishment sequences) to characterize and identify traffic types and optimize delivery

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If traditional performance measurement is used, then continuous data transfer is monitored accurately, but bursty data transfer performance cannot be measured

Engineering Contradiction:
Improvecontinuous transfer measurementVSAvoidbursty transfer measurement capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the measurement system adaptive to varying data transfer patterns. The system dynamically adjusts measurement parameters and aggregation methods based on observed traffic characteristics, switching between continuous monitoring modes for steady flows and burst detection modes for intermittent transfers. This allows accurate measurement of both continuous and bursty data transfers using a single unified framework

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250254088A1Network performance monitoring and optimization using bursty data delivery measurement
Publication Date: 2025.08.07 OPANGA NETWORKS INC
  • US20250254088A1 patent drawing
  • US20250254088A1 patent drawing
  • US20250254088A1 patent drawing

AI summary

Managing a data communication network comprises detecting a bursty data transfer, inferring, using machine learning, a flow burst and pause profile of the bursty data transfer using measurements of the bursty data transfer, and managing the data communication network according to the flow burst and pause profile. Managing the data communication network may include managing the bursty data transfer, managing other data transfers, or both according to the flow burst and pause profile. By using the flow burst and pause profile, the desired performance for the burst data transfer may be more readily achieved and the resources of the data communication network may be more efficiently used.