Hierarchical Learning Machine Network Traffic Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions struggle to detect malware at line speeds due to increasing network data rates, leading to performance degradation and malware detection bottlenecks.
Innovation Solution
A classification system that utilizes a plurality of learning machines arranged in hierarchical levels to classify network traffic as malicious or benign at line speeds, employing regular expressions and features derived from traffic flow characteristics to detect complex malware and benign traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If software-based malware detection solutions are used, then detection accuracy is improved, but execution speed deteriorates and cannot keep up with line speeds
Solution Approach 1:
The patent replaces software-based malware detection with hardware-based detection using application-specific integrated circuits (ASICs). The ASIC implements a finite state machine that processes network traffic at line speed, substituting the mechanical/software processing system with a dedicated hardware system that achieves both high speed and accurate detection through specialized circuitry designed for this specific function.
2Adaptability or versatility
If software-only based solutions are used, then implementation flexibility is maintained, but malware detection capability at line speeds is lost
Solution Approach 1:
The patent changes the fundamental parameter of detection speed by transitioning from software processing to hardware implementation. The ASIC operates at line speed with deterministic performance characteristics, achieving productivity levels that software cannot match while maintaining adaptability through configurable detection rules and protocols implemented in the hardware logic.
3Reliability
If traditional malware detection systems are used, then detection coverage is improved, but network performance deteriorates due to detection bottlenecks
Solution Approach 1:
The patent replaces traditional software-based detection systems with hardware-based ASIC detection, eliminating the performance bottleneck. The dedicated hardware circuitry processes traffic at line speed without the overhead of software interpretation, maintaining comprehensive detection coverage while preserving full network throughput capacity.
Data Source
AI summary
This disclosure provides systems, methods and apparatuses for classifying traffic flow using a plurality of learning machines arranged in multiple hierarchical levels. A first learning machine may classify a first portion of the input stream as malicious based on a match with first classification rules, and a second learning machine may classify at least part of the first portion of the input stream as malicious based on a match with second classification rules. The at least part of the first portion of the input stream may be classified as malicious based on the matches in the first and second learning machines.


