Encrypted Traffic Analysis Using Ciphertext Features for Service Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network traffic analysis technologies face challenges in accurately identifying applications and services, especially in Internet Protocol encryption scenarios, due to hidden plaintext features, and struggle with distinguishing between common service traffic generated by multiple applications.
Innovation Solution
A traffic analysis method that utilizes ciphertext features such as sequence, length, and transmission direction of encrypted packets, combined with machine learning algorithms to identify services and applications, and attributes common service traffic by distinguishing between start, exclusive, and common services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Internet Protocol encryption technologies are used to protect traffic, then security and privacy are improved, but application identification accuracy deteriorates due to hidden plaintext features
Solution Approach 1:
The patent changes the parameters used for identification from plaintext features to ciphertext features. Specifically, it extracts features such as packet length, inter-packet time intervals, packet sequence numbers, and transmission direction from encrypted traffic, and uses these transformed parameters for application identification, thereby maintaining identification accuracy while preserving encryption security
Solution Approach 2:
The patent introduces an intermediary layer of feature extraction that operates on encrypted packets without decrypting them. This intermediary process extracts meaningful patterns from ciphertext (such as timing patterns, size patterns, and sequence patterns) that serve as proxies for traditional plaintext features, enabling identification while maintaining security
2Adaptability or versatility
If fine-grained service identification is performed to distinguish different services within applications, then service management capability is improved, but identification difficulty increases due to encrypted traffic and similar service patterns
Solution Approach 1:
The patent segments the identification process into multiple stages: first identifying the application layer, then identifying specific services within that application, and finally attributing common services to their source applications. This segmentation breaks down the complex fine-grained identification task into manageable steps, reducing overall difficulty while improving service management capability
3Measurement precision
If common service traffic is attributed to specific applications for accurate charging and monitoring, then network management precision is improved, but traffic analysis complexity increases due to similar traffic patterns from multiple applications
Solution Approach 1:
The patent employs feedback mechanisms where identification results from previously analyzed packets are used to inform and refine the analysis of subsequent packets. The system learns from patterns in the traffic stream and adjusts its attribution decisions based on accumulated evidence, improving precision while managing complexity through adaptive rather than purely deterministic analysis
Data Source
AI summary
This application provides a traffic analysis method and apparatus, and a computer system. The method includes: obtaining a plaintext feature and a ciphertext feature of a packet in traffic, where the ciphertext feature includes a length feature of an encrypted field in the packet; and analyzing the traffic based on the plaintext feature and the ciphertext feature, to identify a service or an application to which the traffic belongs. The method may be used for service identification or application identification. The ciphertext feature is introduced in traffic analysis, so that traffic identification accuracy is improved in a packet encryption scenario. In addition, this application further provides a common service traffic attribution method and apparatus, and a computer system.


