Correlation Fractal Dimension for Malicious Network Traffic Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malicious network traffic detection methods are inefficient in distinguishing between encrypted malicious and non-malicious traffic, particularly due to the limitations of deep packet inspection (DPI) in handling high entropy flows and encrypted communications, which often result in false positives and reduced detection rates.

Innovation Solution

The use of a correlation fractal dimension (CFD) evaluation method to identify malicious network traffic by comparing the CFD of network traffic with a reference measure, allowing for the differentiation between malicious and non-malicious communications, even in encrypted contexts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection (DPI) is used to detect malicious network traffic, then detection capability is improved, but processing overhead and false positives increase significantly

Engineering Contradiction:
Improvemalicious traffic detection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts and analyzes only specific portions of network traffic (handshake phases) rather than performing deep packet inspection on entire encrypted communications. This selective extraction maintains detection capability while dramatically reducing processing overhead by focusing computational resources on the unencrypted or less encrypted portions of traffic flows.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments network traffic analysis into distinct phases, particularly focusing on handshake portions of communications. By dividing the traffic analysis into manageable segments rather than processing entire data streams, the system achieves efficient malicious traffic identification with reduced computational complexity.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If deep packet inspection (DPI) is used to analyze encrypted network traffic, then detection accuracy is improved, but false positives increase due to high entropy flows

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent applies different analysis strategies to different portions of network traffic based on their local characteristics. Unencrypted handshake portions are analyzed using traditional DPI methods, while encrypted portions are handled through correlation fractal dimension analysis. This localized approach to different traffic portions maintains detection accuracy while reducing false positives from high entropy encrypted flows.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the detection parameter from traditional DPI metrics to correlation fractal dimension when analyzing encrypted traffic portions. This parameter transformation allows the system to identify malicious patterns in encrypted communications without being confounded by the high entropy that causes false positives in conventional DPI approaches.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If traditional traffic characterization methods are used, then processing efficiency is maintained, but ability to detect encrypted malicious traffic is reduced

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidencrypted malicious traffic detection
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces correlation fractal dimension analysis as an intermediary method between traditional DPI and encrypted traffic detection. This intermediary approach bridges the gap by providing a detection mechanism that works effectively on both unencrypted handshake portions and encrypted data portions, maintaining processing efficiency while improving detection of encrypted malicious traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10931689B2Malicious network traffic identification
Publication Date: 2021.02.23 BRITISH TELECOM PLC
  • US10931689B2 patent drawing
  • US10931689B2 patent drawing
  • US10931689B2 patent drawing

AI summary

A method for identifying malicious network traffic communicated via a computer network, the method including: evaluating a measure of a correlation fractal dimension for a portion of network traffic over a monitored network connection; comparing the measure of correlation fractal dimension with a reference measure of correlation fractal dimension for a corresponding portion of network traffic of a malicious network connection so as to determine if malicious network traffic is communicated over the monitored network connection.