Dynamic Traffic Mirroring for Application Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network systems lack comprehensive and integrated control mechanisms to manage network usage across all users and devices, especially in scenarios where users access networks from alternate or unknown devices, and struggle to identify and enforce policies effectively, particularly with applications that evade fingerprinting like encrypted Bittorrent and Skype.

Innovation Solution

The implementation of an application identification function using a scoring system that combines signature-based and heuristic processing, along with dynamic traffic mirroring, to accurately identify applications running on the network, and a policy-based approach to enforce network policies dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional network control mechanisms are used, then basic network access control is possible, but comprehensive control across all users and devices is lacking

Engineering Contradiction:
Improvenetwork control capabilityVSAvoidcontrol mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network control system is segmented into multiple functional components: application identification function, traffic mirroring function, policy enforcement function, and scoring function. Each component handles a specific aspect of network control, enabling comprehensive monitoring and management while maintaining modularity and ease of implementation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network appliance is introduced as an intermediary device that receives mirrored traffic from network infrastructure devices, performs application identification and scoring, and communicates policy decisions back to the network. This intermediary enables comprehensive control without requiring complex modifications to existing network devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users access networks from alternate or unknown devices, then network flexibility is improved, but identification and policy enforcement become difficult

Engineering Contradiction:
Improvedevice access flexibilityVSAvoidapplication identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system creates copies of network traffic through dynamic traffic mirroring to a network appliance for analysis. This allows identification of applications running on unknown or alternate devices without interfering with the original traffic flow or requiring direct access to the source device.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system uses multiple identification parameters including traffic patterns, protocols, ports, and behavioral characteristics to identify applications. By analyzing multiple parameters simultaneously and combining them through a scoring system, the system achieves high identification accuracy even when devices are unknown or alternate.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If fingerprinting methods are used to identify applications, then application detection is possible, but encrypted applications like Bittorrent and Skype evade detection

Engineering Contradiction:
Improveapplication detection capabilityVSAvoiddetection reliability for encrypted apps
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system employs dynamic traffic mirroring that adapts based on network conditions and identification needs. The mirroring is dynamic in that it can selectively mirror traffic from specific sources or types, and the application identification process is dynamic, continuously analyzing traffic patterns and updating identification confidence scores.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The application identification approach combines multiple identification methods into a composite system: signature-based identification, heuristic analysis, traffic pattern recognition, and scoring mechanisms. This composite approach ensures that even if encrypted applications evade individual detection methods, they can still be identified through the combined analysis of multiple parameters.

Inventive Principle:
Principle #40Composite materials

4Measurement precision

If comprehensive traffic monitoring is implemented, then application identification accuracy is improved, but network bandwidth consumption increases

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidbandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system extracts only the necessary traffic copies for analysis by implementing selective dynamic mirroring. Instead of monitoring all network traffic comprehensively, the system extracts and mirrors only the specific traffic flows that require application identification, reducing bandwidth consumption while maintaining identification accuracy for targeted applications.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9130826B2System and related method for network monitoring and control based on applications
Publication Date: 2015.09.08 EXTREME NETWORKS INC
  • US9130826B2 patent drawing
  • US9130826B2 patent drawing
  • US9130826B2 patent drawing

AI summary

A network architecture system that expands the control network administrators have on existing networks. The system provides application identification and usage data by user, by device and network location. Dynamic traffic mirroring of the system allows for the efficient use of a tool to identify computer applications running on the network. The system includes the ability to embed the tool where needed rather than pervasively based on the use of the dynamic mirroring to bring the packets to the tool. The architecture implemented functions allow the ability to start small with a single application identification tool added to a network management server, examine flows from throughout the network (via mirroring) and upgrade policy control based on real application identification data and usage, then grow to pervasive deployment where virtually all new flows could be identified and controlled via policy. This architecture enables substantially complete application visibility and control.