DNS-Based Network Flow Classification for Encrypted Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing deep packet inspection (DPI) techniques for classifying network flows are resource-intensive, time-consuming, and ineffective for encrypted traffic, making it difficult to manage and prioritize network connections efficiently.

Innovation Solution

A method and network device that classify network flows based on DNS requests by analyzing domain names to determine service classifications, applying network management policies without deep packet inspection, and utilizing a centralized or local service directory to quickly and efficiently manage network connections, including encrypted traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection (DPI) techniques are used for classifying network flows, then classification accuracy can be improved, but resource consumption increases and processing time increases

Engineering Contradiction:
Improveclassification accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the necessary information (domain names from DNS requests) needed for classification, rather than inspecting the entire packet content. This selective extraction approach maintains classification accuracy for application identification while significantly reducing processing overhead and resource consumption compared to full DPI techniques.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs classification actions in advance by intercepting DNS requests before the actual data transfer occurs. By classifying traffic based on domain names resolved in DNS queries, the system prepares classification decisions beforehand, avoiding the need for resource-intensive real-time DPI during active data transmission.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If deep packet inspection (DPI) techniques are used for classifying network flows, then classification accuracy can be improved, but processing time increases

Engineering Contradiction:
Improveclassification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the domain name information from DNS requests, which is the critical element needed for application classification. This focused extraction eliminates the time-consuming process of analyzing entire packet payloads, achieving fast classification with sufficient accuracy for network management purposes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs classification during the DNS resolution phase, which occurs naturally before data transfer. By leveraging this preliminary timing, the system establishes classification decisions early in the connection lifecycle, avoiding time losses during active data transmission and enabling faster response for short-lived connections.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If deep packet inspection (DPI) techniques are used for classifying network flows, then classification capability can be maintained, but effectiveness for encrypted traffic deteriorates

Engineering Contradiction:
Improveclassification capabilityVSAvoideffectiveness for encrypted traffic
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent extracts classification information from DNS request domain names, which are transmitted in plaintext during the DNS query phase. This approach bypasses the encryption problem entirely by obtaining application identification data before encrypted communication begins, making the system effective for both encrypted and unencrypted traffic without requiring decryption capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9887881B2DNS-assisted application identification
Publication Date: 2018.02.06 CISCO TECHNOLOGY INC
  • US9887881B2 patent drawing
  • US9887881B2 patent drawing
  • US9887881B2 patent drawing

AI summary

Techniques are disclosed for classifying a network flow based on a domain name system (DNS) request. Embodiments receive a first DNS request associated with establishing a network flow with a remote service. Here, the first DNS request specifies a domain name associated with the remote service. The domain name is analyzed in order to determine a first classification for the remote service. The first classification is selected from a plurality of classifications. Embodiments then determine a network management policy to apply to the network flow, based on the determined first classification.