Layered Application Detection Architecture for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in detecting and managing network-based applications that evade detection by using techniques such as non-standard protocols, dynamic port selection, and encryption, making it difficult for network administrators to identify and control poorly-behaved applications.

Innovation Solution

A layered approach to application detection using single, multiple, and custom inspection point engines that analyze network traffic to identify applications based on various data points, including IP addresses, packet headers, and custom processing logic, enabling rapid and accurate detection and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network administrators use traditional monitoring methods to detect network applications, then detection simplicity is maintained, but detection precision deteriorates due to evasion techniques like encryption and dynamic port selection

Engineering Contradiction:
Improveapplication detection precisionVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the detection system into multiple inspection points distributed throughout the network infrastructure. Each inspection point independently analyzes network traffic using lightweight agents or probes, breaking down the complex detection task into manageable segments that collectively achieve high detection precision without requiring a single monolithic complex system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as network proxies, firewalls, and traffic intermediaries that mediate between network applications and the detection system. These intermediaries capture and forward traffic metadata without requiring deep packet inspection, maintaining detection precision while avoiding the complexity of analyzing encrypted payloads

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network administrators implement comprehensive traffic inspection to identify poorly-behaved applications, then detection reliability improves, but network performance deteriorates due to processing overhead

Engineering Contradiction:
Improvedetection reliabilityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial inspection by focusing detection efforts on specific traffic patterns, protocols, or time periods rather than inspecting all network traffic uniformly. Inspection intensity is adjusted dynamically based on network conditions, application criticality, and detected anomaly levels, maintaining reliable detection of poorly-behaved applications while minimizing overall processing overhead

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary classification and filtering of network traffic before detailed inspection. Traffic is pre-categorized by protocol, application type, and risk level using lightweight heuristics, allowing the system to apply full inspection only to suspicious or high-priority traffic streams, thereby maintaining detection reliability without bottlenecking network throughput

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If network administrators use simple port-based filtering to control network traffic, then ease of operation is maintained, but adaptability deteriorates against applications using non-standard protocols and dynamic ports

Engineering Contradiction:
Improvepolicy enforcement adaptabilityVSAvoidpolicy management simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent transforms policy enforcement from static port-based rules to dynamic parameter-based controls. Policies are defined using multiple parameters including traffic patterns, protocol characteristics, application behavior metrics, and temporal patterns. The system automatically adjusts these parameters based on observed traffic and detected evasion techniques, enabling adaptable policy enforcement without requiring complex manual configuration

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamic policy adaptation where enforcement rules automatically adjust based on real-time network conditions and detected application behavior. The system learns from traffic patterns and automatically updates policy parameters to counter new evasion techniques, maintaining high adaptability while keeping policy management simple through automated decision-making algorithms

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8484338B2Application detection architecture and techniques
Publication Date: 2013.07.09 ACTIANCE INC
  • US8484338B2 patent drawing
  • US8484338B2 patent drawing
  • US8484338B2 patent drawing

AI summary

An application detection architecture and related techniques are provided for detecting, identifying, and managing network-based applications. In various embodiments, a combined layered approach to application detection and various application-detection techniques provide for quick assessments that move from simplest to complex for rapid detection of unauthorized or misbehaving applications in communication with one or more computer networks. This layering, in some embodiments, further provides scalability and speed for determining and implementing policies that may be applicable to detected network-based application, users, groups, or devices associated with unauthorized network-based applications sending or receiving data via a computer network.