Network Traffic Classification via Host Probing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network traffic classification mechanisms struggle to accurately identify network applications, especially when data encryption or proprietary protocols obscure application-specific attributes, leading to misclassification and reduced granular control over network traffic.

Innovation Solution

A network traffic classification mechanism that probes hosts against network application profiles to classify data flows, using host probing to identify network applications even when explicit packet attributes are obscured or insufficient, and can be executed concurrently with other classification operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption or proprietary protocols are used to protect network traffic, then security and confidentiality are improved, but traffic classification accuracy deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic classification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary classification mechanism that operates between the encrypted traffic and the classification system. Instead of directly analyzing encrypted packets, the system uses intermediary methods such as flow-based classification, behavioral analysis, and metadata examination to classify traffic without decrypting the actual content, thus maintaining both security and classification accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent shifts the classification approach from analyzing packet content (one dimension) to analyzing multiple other dimensions including flow patterns, timing characteristics, source/destination addresses, port numbers, and behavioral attributes. This dimensional shift allows classification to occur without compromising encrypted content

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If deep packet inspection is used to classify encrypted traffic, then classification accuracy is improved, but processing overhead and performance deterioration increase

Engineering Contradiction:
Improveclassification accuracyVSAvoidnetwork throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial inspection by examining only specific portions and characteristics of traffic flows rather than performing complete deep packet inspection on all packets. The system inspects metadata, flow patterns, and behavioral attributes selectively, achieving sufficient classification accuracy without the full processing overhead of deep inspection of every packet

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary classification using readily available packet header information and flow characteristics before more intensive analysis is needed. By pre-classifying traffic based on obvious attributes, the system reduces the amount of traffic requiring deeper analysis, thereby maintaining throughput while improving overall classification efficiency

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7554983B1Probing hosts against network application profiles to facilitate classification of network traffic
Publication Date: 2009.06.30 CA TECH INC
  • US7554983B1 patent drawing
  • US7554983B1 patent drawing
  • US7554983B1 patent drawing

AI summary

Methods, apparatuses and systems directed to a network traffic classification mechanism that probes hosts against one or more network application profiles to facilitate identification of network applications corresponding to data flows traversing a network.