Encrypted Traffic Classification via Flow Parameter Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for identifying application types from encrypted traffic are inflexible and lack accuracy due to reliance on artificially generated encrypted traffic for training, which does not reflect real-world operational environments, and require extensive human intervention.

Innovation Solution

A system and method that trains a learning-based classification engine using unencrypted traffic to establish a mapping between IP flow parameters and application types, allowing for automated inference of application types from encrypted traffic by comparing extracted parameters with their unencrypted counterparts, with a focus on using real-time live traffic in production environments for training and qualification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If learning-based classification is trained using artificially generated encrypted traffic, then the classification engine can be trained and deployed, but the accuracy and flexibility are reduced due to not reflecting real-world operational environments

Engineering Contradiction:
Improveclassification accuracyVSAvoidflexibility to real-world environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by training the classification engine in advance using a diverse set of encrypted traffic samples collected from multiple real-world sources (different networks, time periods, and conditions). This pre-training with comprehensive real-world data ensures the engine is already adapted to various operational environments before deployment, eliminating the need for retraining and maintaining both high accuracy and flexibility across different scenarios.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If manual methods are used to generate and label training data, then the training process can be completed, but extensive human intervention is required reducing automation

Engineering Contradiction:
Improvetraining process feasibilityVSAvoidautomation level
Core Design Contradiction:
Ease of manufactureVSExtent of automation

Solution Approach 1:

The patent implements self-service by enabling the system to automatically collect encrypted traffic samples from network probes, extract flow parameters, and generate training datasets without human intervention. The classification engine is automatically trained on this self-generated data, and the entire pipeline from data collection to model deployment is automated, eliminating the need for manual data labeling and training process management.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If Deep Packet Inspection is used to identify application types, then classification can be performed on unencrypted traffic, but it becomes ineffective when traffic is encrypted

Engineering Contradiction:
Improvetraffic classification precisionVSAvoidencryption impact
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary approach by using flow parameters (such as packet size, inter-arrival time, and traffic patterns) as intermediate features that can be extracted from encrypted traffic without decrypting it. These parameters serve as mediators that preserve application-specific characteristics even when the payload is encrypted, enabling the classification engine to identify application types based on behavioral patterns rather than content inspection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8539221B2Method and system for identifying an application type of encrypted traffic
Publication Date: 2013.09.17 GUAVUS INC
  • US8539221B2 patent drawing
  • US8539221B2 patent drawing
  • US8539221B2 patent drawing

AI summary

The present relates to a method and a system for identifying an application type from encrypted traffic transported over an IP network. The method and system extract at least a portion of IP flow parameters from the encrypted traffic using at least one of specific target encryption types. Then, the method and system transmit the extracted IP flow parameters to a learning-based classification engine. The learning-based classification engine has been trained with unencrypted traffic. Then, the method and system infer at least one corresponding application type for the extracted IP flow parameters.