Encrypted Traffic Analysis Using Ciphertext Features for Service Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network traffic analysis technologies face challenges in accurately identifying applications and services, especially in Internet Protocol encryption scenarios, due to hidden plaintext features, and struggle with distinguishing between common service traffic generated by multiple applications.

Innovation Solution

A traffic analysis method that utilizes ciphertext features such as sequence, length, and transmission direction of encrypted packets, combined with machine learning algorithms to identify services and applications, and attributes common service traffic by distinguishing between start, exclusive, and common services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Internet Protocol encryption technologies are used to protect traffic, then security and privacy are improved, but application identification accuracy deteriorates due to hidden plaintext features

Engineering Contradiction:
Improvetraffic securityVSAvoidapplication identification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent changes the parameters used for identification from plaintext features to ciphertext features. Specifically, it extracts features such as packet length, inter-packet time intervals, packet sequence numbers, and transmission direction from encrypted traffic, and uses these transformed parameters for application identification, thereby maintaining identification accuracy while preserving encryption security

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary layer of feature extraction that operates on encrypted packets without decrypting them. This intermediary process extracts meaningful patterns from ciphertext (such as timing patterns, size patterns, and sequence patterns) that serve as proxies for traditional plaintext features, enabling identification while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If fine-grained service identification is performed to distinguish different services within applications, then service management capability is improved, but identification difficulty increases due to encrypted traffic and similar service patterns

Engineering Contradiction:
Improveservice management capabilityVSAvoidservice identification difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the identification process into multiple stages: first identifying the application layer, then identifying specific services within that application, and finally attributing common services to their source applications. This segmentation breaks down the complex fine-grained identification task into manageable steps, reducing overall difficulty while improving service management capability

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If common service traffic is attributed to specific applications for accurate charging and monitoring, then network management precision is improved, but traffic analysis complexity increases due to similar traffic patterns from multiple applications

Engineering Contradiction:
Improvetraffic attribution precisionVSAvoidtraffic analysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent employs feedback mechanisms where identification results from previously analyzed packets are used to inform and refine the analysis of subsequent packets. The system learns from patterns in the traffic stream and adjusts its attribution decisions based on accumulated evidence, improving precision while managing complexity through adaptive rather than purely deterministic analysis

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11425047B2Traffic analysis method, common service traffic attribution method, and corresponding computer system
Publication Date: 2022.08.23 HUAWEI TECH CO LTD
  • US11425047B2 patent drawing
  • US11425047B2 patent drawing
  • US11425047B2 patent drawing

AI summary

This application provides a traffic analysis method and apparatus, and a computer system. The method includes: obtaining a plaintext feature and a ciphertext feature of a packet in traffic, where the ciphertext feature includes a length feature of an encrypted field in the packet; and analyzing the traffic based on the plaintext feature and the ciphertext feature, to identify a service or an application to which the traffic belongs. The method may be used for service identification or application identification. The ciphertext feature is introduced in traffic analysis, so that traffic identification accuracy is improved in a packet encryption scenario. In addition, this application further provides a common service traffic attribution method and apparatus, and a computer system.