Correlating Network Traffic Across Opaque Endpoints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In complex networks, monitoring network traffic is hindered by opaque endpoints that obscure the source of network traffic, making it difficult for conventional network monitors to correlate and analyze traffic across different network segments, especially when modified by devices like firewalls or VPN gateways.
Innovation Solution
A network monitoring system that uses correlation models and metrics to associate external and internal network addresses, and employs techniques such as fingerprinting and timing pattern injection to correlate network flows across opaque endpoints, enabling the identification of related flows and transactions despite modifications made by traffic forwarding devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional network monitors are used to monitor network traffic, then the monitoring process is simple, but the ability to correlate traffic across opaque endpoints deteriorates
Solution Approach 1:
The patent introduces timing pattern injection as an intermediary mechanism between network traffic sources and opaque endpoints. By injecting distinctive timing patterns into packets before they traverse opaque endpoints, the system creates a mediator that preserves correlation information through otherwise obscuring devices, enabling accurate traffic correlation without complicating the monitoring process
Solution Approach 2:
The system changes the timing parameter of network packets by injecting distinctive timing patterns at specific intervals. This parameter modification allows correlated packets to be identified across opaque endpoints that would otherwise obscure traffic sources, improving measurement precision while maintaining operational simplicity
2Reliability
If opaque endpoints modify network traffic, then network security and traffic management are improved, but the ability to identify traffic sources deteriorates
Solution Approach 1:
The system performs preliminary action by injecting timing patterns into network packets before they reach opaque endpoints. This advance preparation ensures that correlation information is embedded in the traffic flow prior to modification by security devices, preserving source identification capability while allowing opaque endpoints to perform their security and management functions
Solution Approach 2:
The timing pattern injection creates a copy of correlation information that is independent of the original packet headers. This copied timing signature travels through opaque endpoints alongside the modified traffic, providing a redundant identification mechanism that survives endpoint modifications and enables traffic source tracking
3Measurement precision
If timing pattern injection is used to correlate flows, then traffic correlation accuracy is improved, but computational complexity increases
Solution Approach 1:
The system applies partial action by injecting timing patterns at selective intervals rather than continuously processing all traffic. This approach achieves sufficient correlation accuracy for monitoring purposes without the full computational overhead of analyzing every packet, balancing measurement precision with acceptable device complexity
Solution Approach 2:
The timing pattern injection operates periodically at predetermined intervals rather than continuously. This periodic operation reduces computational complexity by processing only representative samples of traffic while still maintaining accurate flow correlation, as the timing patterns provide sufficient information to identify traffic sources without exhaustive analysis
Data Source
AI summary
Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Two or more network segments coupled by a traffic forwarding device (TFD) may be monitored. External network addresses and internal network addresses may be determined based on encrypted network traffic exchanged between external endpoints and the TFD and internal network traffic exchanged between internal endpoints and the TFD. Metrics associated with the external network addresses or the internal network addresses may be determined based on the monitoring. Correlation scores may be provided for the external network addresses and the internal network addresses based on of a correlation model, the metrics, or the other metrics. If a correlation score associated with an external network address and an internal network address exceeds a threshold value, the external network address and the internal network address may be associated with each other based on the correlation score.


