Encrypted Multi-Path TCP Traffic Analytics via Single-Path Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Encrypted network traffic analysis is challenging, especially in multi-path TCP scenarios, as it becomes difficult to obtain an aggregate view of traffic patterns across multiple paths, posing security monitoring and analysis challenges, particularly with heterogeneous networks like mobile devices using both cellular and Wi-Fi networks.
Innovation Solution
A method is introduced where the network device restricts multi-path TCP traffic to a single path in one direction, monitors this traffic, and estimates the multi-path traffic in the other direction using TCP acknowledgment header information to recreate traffic flow patterns, enabling effective encrypted traffic analytics without decrypting packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-path TCP is enabled to improve network performance and redundancy, then network throughput and reliability are improved, but traffic analysis capability deteriorates due to inability to obtain aggregate view of encrypted traffic patterns
Solution Approach 1:
The patent introduces a network device as an intermediary that terminates MPTCP connections and converts them to single-path TCP connections. This mediator enables traffic analysis by creating a controlled observation point where aggregate traffic patterns can be monitored while still allowing multi-path communication to function between end systems.
Solution Approach 2:
The patent segments the MPTCP traffic monitoring function from the actual multi-path communication. By separating the analysis function (performed on single-path converted traffic) from the communication function (maintained as multi-path), the system achieves both goals simultaneously without direct interference between them.
2Difficulty of detecting and measuring
If multi-path TCP is disabled to simplify traffic monitoring, then traffic analysis becomes easier, but network performance and redundancy are degraded
Solution Approach 1:
The network device acts as a mediator that maintains multi-path TCP functionality for performance while creating a simplified single-path representation for monitoring. This intermediary layer resolves the contradiction by providing both views simultaneously - the full multi-path capability for performance and the simplified single-path view for easy monitoring.
3Object-affected harmful factors
If enterprises disable multi-path TCP to avoid security risks from encrypted malware, then security monitoring is improved, but network throughput and fault tolerance are reduced
Solution Approach 1:
The network device serves as a security intermediary that terminates encrypted MPTCP connections and converts them to clear-text single-path TCP connections. This enables security scanning and traffic analysis of the converted connections while the original multi-path encrypted communication continues uninterrupted between end systems, thus maintaining throughput while enabling security monitoring.
Solution Approach 2:
The patent applies different quality treatments to different parts of the network communication. Multi-path encrypted communication is maintained at the end systems for performance, while the intermediary network device applies single-path clear-text conversion for security monitoring, creating local quality differentiation that resolves the contradiction.
Data Source
AI summary
Methods and systems to estimate encrypted multi-path TCP (MPTCP) network traffic include restricting traffic in a first direction (e.g., uplink) to a single path, and estimating traffic of multiple subflows of a second direction (e.g., downlink) based on traffic over the single path of the first direction. The estimating may be based on, without limitation, acknowledgment information of the single path, a sequence of acknowledgment numbers of the single path, an unencrypted initial packet sent over the single path as part of a secure tunnel setup procedure, TCP header information of the unencrypted initial packet (e.g., sequence number, acknowledgment packet, and/or acknowledgment packet length), and/or metadata of packets of the single path (e.g., regarding cryptographic algorithms, Diffie-Helman groups, and/or certificate related data).


