Extended Packet Flow Description for Protocol-Aware Traffic Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current packet flow descriptions (PFDs) in communication networks lack clarity on applicable protocols, leading to inaccurate traffic detection and potential blocking of application traffic, and do not support combination of URL and IP address information for efficient fraud request detection.
Innovation Solution
Extending PFDs to include protocol matching criteria for domain names, such as DNS and TLS protocols, and allowing combination criteria for multiple PFDs, enabling more accurate traffic detection and handling by specifying protocols applicable to domain names and combining PFDs for logical AND operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If current PFD structure is used without protocol matching criteria, then device complexity is reduced and ease of operation is improved, but traffic detection accuracy deteriorates and application traffic may be incorrectly blocked
Solution Approach 1:
The PFD structure is segmented into distinct components: flow description elements (source/destination IP, ports, protocol) and domain name matching criteria with associated protocol matching criteria. This segmentation allows the system to add detailed protocol matching information without overwhelming the entire PFD structure, improving traffic detection accuracy while maintaining manageable complexity through modular organization.
Solution Approach 2:
The patent adds a new dimension to the PFD structure by introducing protocol matching criteria as a separate layer alongside traditional flow description elements. This dimensional expansion allows the system to match traffic based on multiple criteria (IP, port, protocol, domain name) simultaneously, significantly improving detection accuracy without requiring complete restructuring of the existing PFD framework.
2Reliability
If only one of URL, IP address or domain name is included in PFD, then device complexity is reduced, but fraud detection capability deteriorates
Solution Approach 1:
The patent merges multiple traffic identification criteria (URL, IP address, domain name) into a single unified PFD structure that supports combination criteria. This merging allows the system to evaluate multiple criteria together to detect fraud, improving reliability by cross-validating traffic against multiple parameters rather than relying on a single indicator.
Solution Approach 2:
The PFD structure functions as a composite information structure that combines different types of traffic identification data (URL patterns, IP addresses, domain names) with protocol matching criteria. This composite approach enables the system to leverage the strengths of each individual criterion type, creating a more robust fraud detection mechanism that is more reliable than any single criterion alone.
3Measurement precision
If PFD does not indicate applicable protocols for domain names, then ease of operation is improved and implementation is simpler, but traffic handling accuracy deteriorates leading to potential blocking of legitimate application traffic
Solution Approach 1:
The protocol matching criteria are segmented as a distinct component within the PFD structure, separated from but associated with domain name matching criteria. This segmentation allows the system to specify which protocols (DNS, TLS, etc.) should be matched for each domain name, improving traffic handling accuracy by preventing misclassification of protocol-specific traffic while maintaining clear, organized configuration.
4Measurement precision
If multiple PFDs are used without combination criteria, then adaptability to different traffic patterns is improved, but detection accuracy deteriorates due to lack of coordinated matching
Solution Approach 1:
The patent introduces combination criteria that merge multiple PFDs into a coordinated detection system. This merging allows the system to evaluate multiple PFDs together using logical operations (AND, OR), improving detection accuracy by ensuring that traffic matches the intended pattern across multiple criteria while maintaining the adaptability to handle diverse traffic patterns through flexible combination rules.
Data Source
AI summary
Various embodiments of the present disclosure provide a method for traffic detection. The method which may be performed by a first network node includes receiving a message from a second network node. The method further includes determining packet flow description information for traffic detection according to the message. The packet flow description information may indicate a combination criterion for two or more packet flow descriptions, and/or a protocol matching criterion for a domain name in a packet flow description. According to the embodiments of the present disclosure, the packet flow description definition can be extended to support more accurate traffic detection.


