Extended Packet Flow Description for Protocol-Aware Traffic Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current packet flow descriptions (PFDs) in communication networks lack clarity on applicable protocols, leading to inaccurate traffic detection and potential blocking of application traffic, and do not support combination of URL and IP address information for efficient fraud request detection.

Innovation Solution

Extending PFDs to include protocol matching criteria for domain names, such as DNS and TLS protocols, and allowing combination criteria for multiple PFDs, enabling more accurate traffic detection and handling by specifying protocols applicable to domain names and combining PFDs for logical AND operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current PFD structure is used without protocol matching criteria, then device complexity is reduced and ease of operation is improved, but traffic detection accuracy deteriorates and application traffic may be incorrectly blocked

Engineering Contradiction:
Improvetraffic detection accuracyVSAvoidPFD structure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The PFD structure is segmented into distinct components: flow description elements (source/destination IP, ports, protocol) and domain name matching criteria with associated protocol matching criteria. This segmentation allows the system to add detailed protocol matching information without overwhelming the entire PFD structure, improving traffic detection accuracy while maintaining manageable complexity through modular organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to the PFD structure by introducing protocol matching criteria as a separate layer alongside traditional flow description elements. This dimensional expansion allows the system to match traffic based on multiple criteria (IP, port, protocol, domain name) simultaneously, significantly improving detection accuracy without requiring complete restructuring of the existing PFD framework.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If only one of URL, IP address or domain name is included in PFD, then device complexity is reduced, but fraud detection capability deteriorates

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidPFD information requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple traffic identification criteria (URL, IP address, domain name) into a single unified PFD structure that supports combination criteria. This merging allows the system to evaluate multiple criteria together to detect fraud, improving reliability by cross-validating traffic against multiple parameters rather than relying on a single indicator.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The PFD structure functions as a composite information structure that combines different types of traffic identification data (URL patterns, IP addresses, domain names) with protocol matching criteria. This composite approach enables the system to leverage the strengths of each individual criterion type, creating a more robust fraud detection mechanism that is more reliable than any single criterion alone.

Inventive Principle:
Principle #40Composite materials

3Measurement precision

If PFD does not indicate applicable protocols for domain names, then ease of operation is improved and implementation is simpler, but traffic handling accuracy deteriorates leading to potential blocking of legitimate application traffic

Engineering Contradiction:
Improvetraffic handling accuracyVSAvoidPFD configuration simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The protocol matching criteria are segmented as a distinct component within the PFD structure, separated from but associated with domain name matching criteria. This segmentation allows the system to specify which protocols (DNS, TLS, etc.) should be matched for each domain name, improving traffic handling accuracy by preventing misclassification of protocol-specific traffic while maintaining clear, organized configuration.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If multiple PFDs are used without combination criteria, then adaptability to different traffic patterns is improved, but detection accuracy deteriorates due to lack of coordinated matching

Engineering Contradiction:
Improvedetection accuracyVSAvoidPFD flexibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces combination criteria that merge multiple PFDs into a coordinated detection system. This merging allows the system to evaluate multiple PFDs together using logical operations (AND, OR), improving detection accuracy by ensuring that traffic matches the intended pattern across multiple criteria while maintaining the adaptability to handle diverse traffic patterns through flexible combination rules.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12095669B2Method and apparatus for traffic detection
Publication Date: 2024.09.17 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12095669B2 patent drawing
  • US12095669B2 patent drawing
  • US12095669B2 patent drawing

AI summary

Various embodiments of the present disclosure provide a method for traffic detection. The method which may be performed by a first network node includes receiving a message from a second network node. The method further includes determining packet flow description information for traffic detection according to the message. The packet flow description information may indicate a combination criterion for two or more packet flow descriptions, and/or a protocol matching criterion for a domain name in a packet flow description. According to the embodiments of the present disclosure, the packet flow description definition can be extended to support more accurate traffic detection.