Encrypted Multi-Path TCP Traffic Analytics via Single-Path Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Encrypted network traffic analysis is challenging, especially in multi-path TCP scenarios, as it becomes difficult to obtain an aggregate view of traffic patterns across multiple paths, posing security monitoring and analysis challenges, particularly with heterogeneous networks like mobile devices using both cellular and Wi-Fi networks.

Innovation Solution

A method is introduced where the network device restricts multi-path TCP traffic to a single path in one direction, monitors this traffic, and estimates the multi-path traffic in the other direction using TCP acknowledgment header information to recreate traffic flow patterns, enabling effective encrypted traffic analytics without decrypting packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-path TCP is enabled to improve network performance and redundancy, then network throughput and reliability are improved, but traffic analysis capability deteriorates due to inability to obtain aggregate view of encrypted traffic patterns

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidtraffic analysis capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a network device as an intermediary that terminates MPTCP connections and converts them to single-path TCP connections. This mediator enables traffic analysis by creating a controlled observation point where aggregate traffic patterns can be monitored while still allowing multi-path communication to function between end systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the MPTCP traffic monitoring function from the actual multi-path communication. By separating the analysis function (performed on single-path converted traffic) from the communication function (maintained as multi-path), the system achieves both goals simultaneously without direct interference between them.

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If multi-path TCP is disabled to simplify traffic monitoring, then traffic analysis becomes easier, but network performance and redundancy are degraded

Engineering Contradiction:
Improvetraffic monitoring difficultyVSAvoidnetwork performance
Core Design Contradiction:
Difficulty of detecting and measuringVSProductivity

Solution Approach 1:

The network device acts as a mediator that maintains multi-path TCP functionality for performance while creating a simplified single-path representation for monitoring. This intermediary layer resolves the contradiction by providing both views simultaneously - the full multi-path capability for performance and the simplified single-path view for easy monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If enterprises disable multi-path TCP to avoid security risks from encrypted malware, then security monitoring is improved, but network throughput and fault tolerance are reduced

Engineering Contradiction:
Improvesecurity riskVSAvoidnetwork throughput
Core Design Contradiction:
Object-affected harmful factorsVSQuantity of substance

Solution Approach 1:

The network device serves as a security intermediary that terminates encrypted MPTCP connections and converts them to clear-text single-path TCP connections. This enables security scanning and traffic analysis of the converted connections while the original multi-path encrypted communication continues uninterrupted between end systems, thus maintaining throughput while enabling security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different quality treatments to different parts of the network communication. Multi-path encrypted communication is maintained at the end systems for performance, while the intermediary network device applies single-path clear-text conversion for security monitoring, creating local quality differentiation that resolves the contradiction.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11316871B2Encrypted traffic analytics over a multi-path TCP connection
Publication Date: 2022.04.26 CISCO TECHNOLOGY INC
  • US11316871B2 patent drawing
  • US11316871B2 patent drawing
  • US11316871B2 patent drawing

AI summary

Methods and systems to estimate encrypted multi-path TCP (MPTCP) network traffic include restricting traffic in a first direction (e.g., uplink) to a single path, and estimating traffic of multiple subflows of a second direction (e.g., downlink) based on traffic over the single path of the first direction. The estimating may be based on, without limitation, acknowledgment information of the single path, a sequence of acknowledgment numbers of the single path, an unencrypted initial packet sent over the single path as part of a secure tunnel setup procedure, TCP header information of the unencrypted initial packet (e.g., sequence number, acknowledgment packet, and/or acknowledgment packet length), and/or metadata of packets of the single path (e.g., regarding cryptographic algorithms, Diffie-Helman groups, and/or certificate related data).