Cloud Monitoring for Encrypted OTT Application Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques are inefficient in identifying and processing over-the-top (OTT) application data, particularly when it is transmitted over a VPN tunnel, due to its encrypted nature, making it difficult for network operators to monitor and track OTT applications effectively.

Innovation Solution

A network monitoring system that utilizes a cloud computing environment to identify OTT applications without parsing the encrypted payload, by generating Adaptive Session Intelligence (ASI) data sets and using active agents to store and analyze OTT identifying information, allowing for real-time monitoring and performance analysis of OTT applications across VPN tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If OTT application data is transmitted over a VPN tunnel with encrypted payload, then transmission security is improved, but identification and monitoring capability deteriorates

Engineering Contradiction:
Improvetransmission securityVSAvoididentification capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the data packet into multiple components: encrypted payload (which maintains security) and unencrypted header/metadata portions (which contain identification information). By analyzing only the non-encrypted segments such as IP headers, port numbers, and protocol information, the system can identify OTT applications without decrypting the payload, thus resolving the contradiction between security and identifiability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary classification system that acts as a mediator between the encrypted data flow and the monitoring system. This intermediary uses machine learning models trained on packet metadata patterns to identify OTT applications indirectly, without requiring direct access to or decryption of the encrypted payload. The intermediary translates encrypted traffic characteristics into identifiable application signatures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If conventional packet inspection methods are used to identify OTT applications, then identification accuracy is improved, but processing speed deteriorates

Engineering Contradiction:
Improveidentification accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-training machine learning classification models offline using extensive datasets of packet metadata from various OTT applications. These pre-trained models capture the characteristic patterns of different applications in their metadata. During live monitoring, the pre-trained models quickly classify new packets by comparing their metadata against the stored patterns, achieving both high accuracy and fast processing speeds without requiring real-time decryption or deep packet inspection.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If encrypted payload parsing is attempted to identify OTT applications, then identification completeness is improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improveidentification completenessVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts and utilizes the identification information that exists outside the encrypted payload, specifically in the packet headers, metadata, and control plane information. By taking out and analyzing only the necessary identification elements from the packet structure, the system achieves complete identification of OTT applications without the need to parse or decrypt the encrypted payload, thereby reducing system complexity and computational overhead while maintaining identification completeness.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3484102B1Cloud computing environment system for automatically determining over-the-top applications and services
Publication Date: 2020.09.30 NETSCOUT SYSTEMS INC
  • EP3484102B1 patent drawingFigure 1
  • EP3484102B1 patent drawingFigure 2
  • EP3484102B1 patent drawingFigure 3A~3B

AI summary

A cloud computing system for determining Over-The-Top (OTT) applications includes a cloud computing environment partitioned into a plurality of partitions. The cloud partitions include at least a first wireless network operator's cloud, a second wireless network operator's cloud and a shared partition configured to receive and store information uniquely identifying OTT applications supported by at least one of the first and second wireless network operators. The system further includes a plurality of active agents. Each active agent receives a list of OTT service platforms supported by a corresponding wireless network operator. The received list includes a plurality of URLs associated with various applications that are delivered by the OTT service platforms. The active agent(s) connect to the plurality of URLs to determine information uniquely identifying each of the OTT applications and to store the information in the shared partition of the cloud computing environment.