Encrypted Traffic Monitoring via Timing-Based Packet Acknowledgment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring systems cannot estimate the amount of acknowledged application data when network traffic is transported using an encrypted transport protocol, as information in packet headers is inaccessible without decryption.

Innovation Solution

A computer-implemented method and system that processes bidirectional network traffic with encrypted application data using an encrypted transport protocol, estimating the size of encrypted application data in packets, assigning timing criteria, and acknowledging selected packets to estimate the amount of encrypted application data transported in opposing directions based on observed packets during a selected time interval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If decryption is performed to access packet header information, then measurement precision of acknowledged data is improved, but device complexity and security requirements worsen

Engineering Contradiction:
Improvemeasurement precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces timing criteria as an intermediary mechanism to indirectly determine acknowledged data amounts without decrypting packets. By analyzing timing relationships between packet transmissions and acknowledgments, the system infers acknowledgment information through temporal patterns rather than direct header inspection, thus avoiding decryption complexity while maintaining measurement capability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If packet headers are not decrypted, then device complexity is reduced, but loss of information occurs

Engineering Contradiction:
Improvedevice complexityVSAvoidloss of information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent replaces the mechanical approach of directly reading encrypted header fields with a temporal analysis mechanism. By substituting cryptographic decryption with timing-based inference, the system recovers acknowledgment information through observational patterns in packet timing rather than direct access to encrypted data, eliminating the need for decryption while preserving measurement capability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If timing criteria are assigned to all packets, then measurement precision is improved, but loss of time increases

Engineering Contradiction:
Improvemeasurement precisionVSAvoidloss of time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies timing criteria selectively rather than universally to all packets. By assigning timing analysis only to packets that meet specific thresholds or conditions, the system achieves sufficient measurement precision for acknowledged data while avoiding the time overhead of analyzing every single packet in the network flow

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20180324074A1System and method for estimating an amount of acknowledged application data transmitted by encrypted transport
Publication Date: 2018.11.08 NETSCOUT SYSTEMS INC
  • US20180324074A1 patent drawing
  • US20180324074A1 patent drawing
  • US20180324074A1 patent drawing

AI summary

A system and computer-implemented method to process bidirectional network traffic having encrypted application data and using an encrypted transport protocol. The method includes estimating a size of encrypted application data in respective packets of the bidirectional network traffic, wherein the packets of the bidirectional network traffic are transported in opposing directions. The method further includes assigning timing criteria to respective application packets transported in the opposing directions that were determined to include a threshold amount of encrypted application data, the timing criteria being based on a time of observation at an observation point of the corresponding application packet, and acknowledging, for respective packets of the application packets, selected application packets that were selected based on the timing criteria assigned to the respective application packets. The method further includes estimating an amount of encrypted application data transported in at least one of the opposing directions based on a sum of the estimated size of the encrypted application data in the respective acknowledged packets transported in the at least one of the opposing directions that were observed during a selected time interval.