Deep Packet Inspection for Application-Based Network Flow Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for identifying network flows in computer networks based on applications are challenging, especially in cloud environments and content distribution networks, due to the need for manual mapping of 5-tuples to applications, which is disruptive and inconvenient.

Innovation Solution

An out-of-band network packet monitoring system that automatically maps applications to network flows using deep packet inspection and application signature databases, enabling faster identification and filtering of network traffic based on applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual mapping of 5-tuples to applications is used, then network operators can identify applications, but the process is challenging, disruptive, and inconvenient

Engineering Contradiction:
Improveease of application identificationVSAvoidcomplexity of mapping setup
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically identifying applications through deep packet inspection and signature matching without requiring manual mapping configuration. The network packet monitoring system autonomously maps applications to 5-tuples by analyzing packet contents against stored signatures, eliminating the need for operators to manually set up mappings.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual mapping process with automated computer-based deep packet inspection. Instead of operators manually configuring mappings, the system uses automated signature matching algorithms that inspect packet contents, extract application identifiers, and automatically associate applications with 5-tuples.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If deep packet inspection is used to automatically identify applications, then application identification becomes faster and more efficient, but network traffic analysis complexity increases

Engineering Contradiction:
Improvespeed of application identificationVSAvoidcomplexity of packet analysis
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary action by pre-storing application signatures and characteristics in a database before actual packet analysis occurs. When packets arrive, the system quickly matches them against pre-existing signatures rather than analyzing everything from scratch, enabling fast identification while managing complexity through pre-computed reference data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the approach from analyzing all packet parameters manually to focusing on specific signature parameters that uniquely identify applications. By transforming the analysis focus to key signature parameters (protocol types, port ranges, packet patterns) rather than all possible packet fields, the system achieves faster identification with reduced analytical complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250300939A1Managing network flows based on applications
Publication Date: 2025.09.25 ARISTA NETWORKS INC
  • US20250300939A1 patent drawing
  • US20250300939A1 patent drawing
  • US20250300939A1 patent drawing

AI summary

Some embodiments provide a method that receives a policy to filter traffic from a network. The policy specifies the traffic to be filtered in terms of an application name of an application that generates the traffic to be filtered. Data packets from the network are received. Packet information in the received data packets generated by the application based on the application name are identified. A mapping between the application name and the identified packet information is forwarded to a first set of monitoring tools. The received data packets are processed by using the identified packet information to identify data packets generated by the application in the network from among the received data packets and forwarding the identified data packets to a second set of monitoring tools based on the policy.