Hierarchical Learning Machine Network Traffic Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions struggle to detect malware at line speeds due to increasing network data rates, leading to performance degradation and malware detection bottlenecks.

Innovation Solution

A classification system that utilizes a plurality of learning machines arranged in hierarchical levels to classify network traffic as malicious or benign at line speeds, employing regular expressions and features derived from traffic flow characteristics to detect complex malware and benign traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If software-based malware detection solutions are used, then detection accuracy is improved, but execution speed deteriorates and cannot keep up with line speeds

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidexecution speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent replaces software-based malware detection with hardware-based detection using application-specific integrated circuits (ASICs). The ASIC implements a finite state machine that processes network traffic at line speed, substituting the mechanical/software processing system with a dedicated hardware system that achieves both high speed and accurate detection through specialized circuitry designed for this specific function.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If software-only based solutions are used, then implementation flexibility is maintained, but malware detection capability at line speeds is lost

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidmalware detection throughput
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent changes the fundamental parameter of detection speed by transitioning from software processing to hardware implementation. The ASIC operates at line speed with deterministic performance characteristics, achieving productivity levels that software cannot match while maintaining adaptability through configurable detection rules and protocols implemented in the hardware logic.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional malware detection systems are used, then detection coverage is improved, but network performance deteriorates due to detection bottlenecks

Engineering Contradiction:
Improvemalware detection coverageVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces traditional software-based detection systems with hardware-based ASIC detection, eliminating the performance bottleneck. The dedicated hardware circuitry processes traffic at line speed without the overhead of software interpretation, maintaining comprehensive detection coverage while preserving full network throughput capacity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12225034B2Network traffic classification system
Publication Date: 2025.02.11 REDBERRY SYSTEMS INC
  • US12225034B2 patent drawing
  • US12225034B2 patent drawing
  • US12225034B2 patent drawing

AI summary

This disclosure provides systems, methods and apparatuses for classifying traffic flow using a plurality of learning machines arranged in multiple hierarchical levels. A first learning machine may classify a first portion of the input stream as malicious based on a match with first classification rules, and a second learning machine may classify at least part of the first portion of the input stream as malicious based on a match with second classification rules. The at least part of the first portion of the input stream may be classified as malicious based on the matches in the first and second learning machines.