Encrypted Traffic Classification via Flow Parameter Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for identifying application types from encrypted traffic are inflexible and lack accuracy due to reliance on artificially generated encrypted traffic for training, which does not reflect real-world operational environments, and require extensive human intervention.
Innovation Solution
A system and method that trains a learning-based classification engine using unencrypted traffic to establish a mapping between IP flow parameters and application types, allowing for automated inference of application types from encrypted traffic by comparing extracted parameters with their unencrypted counterparts, with a focus on using real-time live traffic in production environments for training and qualification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If learning-based classification is trained using artificially generated encrypted traffic, then the classification engine can be trained and deployed, but the accuracy and flexibility are reduced due to not reflecting real-world operational environments
Solution Approach 1:
The patent applies preliminary action by training the classification engine in advance using a diverse set of encrypted traffic samples collected from multiple real-world sources (different networks, time periods, and conditions). This pre-training with comprehensive real-world data ensures the engine is already adapted to various operational environments before deployment, eliminating the need for retraining and maintaining both high accuracy and flexibility across different scenarios.
2Ease of manufacture
If manual methods are used to generate and label training data, then the training process can be completed, but extensive human intervention is required reducing automation
Solution Approach 1:
The patent implements self-service by enabling the system to automatically collect encrypted traffic samples from network probes, extract flow parameters, and generate training datasets without human intervention. The classification engine is automatically trained on this self-generated data, and the entire pipeline from data collection to model deployment is automated, eliminating the need for manual data labeling and training process management.
3Measurement precision
If Deep Packet Inspection is used to identify application types, then classification can be performed on unencrypted traffic, but it becomes ineffective when traffic is encrypted
Solution Approach 1:
The patent introduces an intermediary approach by using flow parameters (such as packet size, inter-arrival time, and traffic patterns) as intermediate features that can be extracted from encrypted traffic without decrypting it. These parameters serve as mediators that preserve application-specific characteristics even when the payload is encrypted, enabling the classification engine to identify application types based on behavioral patterns rather than content inspection.
Data Source
AI summary
The present relates to a method and a system for identifying an application type from encrypted traffic transported over an IP network. The method and system extract at least a portion of IP flow parameters from the encrypted traffic using at least one of specific target encryption types. Then, the method and system transmit the extracted IP flow parameters to a learning-based classification engine. The learning-based classification engine has been trained with unencrypted traffic. Then, the method and system infer at least one corresponding application type for the extracted IP flow parameters.


