DNS Pattern Application Identification for Encrypted Traffic Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large wireless networks supporting hundreds of user devices face congestion and lack visibility into encrypted multimedia applications, making it difficult for network administrators to prioritize and control network resources effectively, as traditional Application Level Gateway techniques are designed for unencrypted data and fail with cloud-based, encrypted VOIP applications.
Innovation Solution
An application identification system that uses DNS request and response patterns to map applications, employing media classification algorithms to identify multimedia sessions and control resource utilization, allowing network administrators to monitor and manage applications, even those using encrypted data, by implementing policies for prioritization and blocking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If traditional Application Level Gateway techniques are used to monitor network traffic, then visibility into unencrypted data is achieved, but encrypted cloud-based VOIP applications cannot be identified or controlled
Solution Approach 1:
The patent introduces DNS-based intermediaries (DNS requests and responses) as a mediator between the monitoring system and encrypted applications. By capturing and analyzing DNS traffic patterns before applications establish encrypted connections, the system gains visibility into encrypted application identities without needing to decrypt the actual application data streams.
Solution Approach 2:
The system performs preliminary identification of applications through DNS request pattern analysis before encrypted communication begins. By mapping DNS request patterns to application identities in advance, the system establishes a foundation for subsequent monitoring and control of encrypted applications without requiring real-time decryption capabilities.
2Loss of information
If network administrators implement comprehensive monitoring of all user devices, then complete visibility into network activities is achieved, but network congestion increases and management complexity rises
Solution Approach 1:
The patent extracts only the essential identifying information from DNS traffic patterns - specifically the relationship between DNS request patterns and application identities. By focusing solely on this extracted information rather than monitoring all network traffic in detail, the system achieves application-level visibility while maintaining network performance and simplifying management complexity.
Solution Approach 2:
The system creates simplified representations (copies) of application identities based on DNS pattern analysis rather than monitoring actual application data streams. This copying approach provides sufficient information for identification and control purposes without the overhead of comprehensive traffic monitoring, reducing both network congestion and management complexity.
3Adaptability or versatility
If cloud-based encrypted VOIP applications are allowed to operate freely, then application functionality is maintained, but network administrators cannot prioritize or control network resources
Solution Approach 1:
The patent establishes a feedback mechanism where DNS pattern analysis provides continuous information about active encrypted applications to the network controller. This feedback enables administrators to identify, prioritize, and control encrypted applications in real-time while maintaining their encrypted communication functionality, resolving the contradiction between supporting encryption and enabling control.
Data Source
AI summary
According to an example, an application initiating a communication session may be identified via a mapping of the application information with a pattern of interest included in a DNS server response corresponding to the application. Information regarding the communication session may be obtained and a determination may be made as to whether the communication session includes media data. If the communication session includes media data, control of the application and the communication session may be enabled via an interface.


