Deep Packet Inspection for Network Traffic Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current deep packet inspection technologies face challenges in accurately identifying applications and protocols due to weak signatures, leading to false positives and negatives, which can result in wrongful actions such as misclassification of network traffic, causing latency or packet loss.
Innovation Solution
The system employs a deep packet inspection method that receives packets at an intermediate network node, determines if layer injection is possible, identifies applications or protocols using deep packet inspection, and performs routing modifications based on the identified information, utilizing a combination of analysis techniques like port, string match, and numerical properties to generate robust signatures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is used to identify applications and protocols, then network traffic classification capability is improved, but false positives and negatives increase due to weak signatures
Solution Approach 1:
The patent combines multiple analysis techniques (port analysis, string matching, numerical property analysis) into a unified deep packet inspection system. This merging of multiple detection methods creates more robust signatures that reduce false positives and negatives while maintaining high classification accuracy.
Solution Approach 2:
The inspection system uses composite signature structures that integrate multiple characteristics (port numbers, string patterns, numerical properties) similar to composite materials. This composite approach creates more reliable identification signatures that are less prone to false classifications.
2Productivity
If layer injection is performed at intermediate network nodes to modify routing, then routing optimization is improved, but system complexity increases
Solution Approach 1:
The system performs routing modifications at intermediate network nodes before packets reach their final destination. By injecting layer information and modifying routing decisions proactively at intermediate points, the system optimizes traffic flow without requiring complex end-to-end processing.
Solution Approach 2:
The patent introduces an intermediary mechanism at network nodes that facilitates routing modifications. This intermediary layer enables routing optimization by acting as a mediator between packet inspection and routing decisions, simplifying the overall system architecture while maintaining improved routing efficiency.
Data Source
AI summary
The disclosed embodiments include a system and method for modifying network traffic. For example, in one embodiment, the method includes receiving a packet at an intermediate network node at a network layer. The method determines at the intermediate network node whether layer injection can be performed at the intermediate network node. If layer injection can be performed at the intermediate network node, the method identifies at least one application or protocol associated with the packet using deep packet inspection. The method determines a routing modification based on the identified application protocol. The method then performs the routing modification on the packet.


