Dynamic Traffic Mirroring for Encrypted Application Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network systems lack comprehensive and integrated control mechanisms to manage access and usage across all users and devices, especially in scenarios where users access networks from alternate or unknown devices, and struggle to identify and enforce policies effectively, particularly with applications that evade fingerprinting like encrypted Bittorrent and Skype.
Innovation Solution
The implementation of an application identification function using a scoring system that combines signature-based and heuristic processing, along with dynamic traffic mirroring, to accurately identify applications running on the network, and a policy-based approach to enforce network policies dynamically, allowing for real-time adaptation and fine-grained control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional network control mechanisms are used, then network infrastructure management is maintained, but comprehensive control over all users and devices cannot be achieved
Solution Approach 1:
The patent introduces a network bridge as an intermediary device that sits between users and the network infrastructure. This bridge acts as a mediator that enforces security policies, identifies applications, and controls network access without requiring changes to the existing network infrastructure, thereby achieving comprehensive control while maintaining infrastructure simplicity.
Solution Approach 2:
The patent segments the network control function by separating the policy enforcement mechanism (network bridge) from the network infrastructure. This allows independent management of security policies and network resources, enabling comprehensive control over users and devices without complicating the overall network architecture.
2Measurement precision
If fingerprinting-based application identification is used, then common applications can be identified, but encrypted applications like Bittorrent and Skype cannot be reliably detected
Solution Approach 1:
The patent changes the identification parameters from relying solely on application fingerprints to using multiple parameters including SSL certificate analysis, network behavior patterns, and encrypted traffic characteristics. This multi-parameter approach enables accurate identification of both traditional and encrypted applications by analyzing different aspects of network traffic.
Solution Approach 2:
The patent combines multiple identification methods into a composite detection system that integrates SSL certificate verification, fingerprinting, and behavioral analysis. This composite approach ensures reliable detection of various application types including encrypted traffic by leveraging the strengths of each individual method.
3Stability of the object's composition
If static network policies are enforced, then policy consistency is maintained, but real-time adaptation to changing network conditions cannot be achieved
Solution Approach 1:
The patent implements dynamic network policies that can be modified in real-time based on network conditions, user behavior, and security threats. The network bridge continuously monitors traffic patterns and automatically adjusts policy enforcement, enabling both consistency through structured policy frameworks and adaptability through real-time modifications.
Solution Approach 2:
The patent incorporates feedback mechanisms where the network bridge continuously monitors network traffic and policy effectiveness, then uses this information to automatically adjust and optimize network policies. This closed-loop system maintains policy consistency while enabling real-time adaptation to changing conditions through data-driven decision making.
4Measurement precision
If comprehensive traffic monitoring is implemented, then application identification accuracy improves, but network bandwidth consumption increases
Solution Approach 1:
The patent extracts only the essential and most informative packets for analysis by the network bridge, rather than monitoring all network traffic comprehensively. This selective extraction approach maintains high application identification accuracy by focusing on key traffic characteristics while minimizing bandwidth consumption through intelligent sampling and filtering.
Data Source
AI summary
A function is provided in a network system for policy-based dynamic mirroring for network traffic. The function monitors events, topology and status of the network and installs, enables, selects or changes traffic mirrors associated with the operation of one or more devices of the network. The mirror policies are established based on network polices and/or rules. The mirror policies and the enablement, installation, selection or changing of them are based on multiple criteria. The function provides for the selection of traffic to mirror, how much of it to mirror, where to mirror it and when to stop the mirroring. The function may be established in network entry devices as well as core switching devices of the network. The function can select portals for the mirroring activity and can secure the mirroring.


