Masked Traffic Analysis for Faster In-Path Security Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security protection devices face performance bottlenecks in processing increasing network traffic, affecting user experience, particularly in in-path deployments, due to the high resource consumption in detecting suspicious and unknown traffic.
Innovation Solution
A traffic processing method involving local statistical analysis by protection devices to identify frequent key data, followed by data masking to generate a local masking result, which is shared with a security service server to create a global masking result, enhancing detection performance while preserving privacy by analyzing masked data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a protection device performs comprehensive security detection on all traffic in in-path deployment, then network security is improved, but processing performance deteriorates and the device becomes a bottleneck
Solution Approach 1:
The patent segments the detection system into two parts: a lightweight local statistical detection component that runs on the protection device, and a comprehensive global detection component that runs on a remote server. This allows the protection device to handle frequent simple checks locally while offloading complex analysis to the server, resolving the contradiction between comprehensive security and processing performance
Solution Approach 2:
The patent implements preliminary action by performing statistical analysis on traffic data in advance and generating masking results before actual traffic detection. The protection device uses pre-computed masking results to quickly identify trusted traffic patterns, avoiding the need for real-time comprehensive analysis and thus maintaining high processing performance while ensuring security
2Measurement precision
If a protection device performs additional security detection on suspicious traffic, then detection accuracy is improved, but processing time increases
Solution Approach 1:
The patent applies partial action by performing only statistical masking detection on all traffic, and reserving additional comprehensive security detection only for traffic that does not match the masking results. This selective approach maintains high detection accuracy for suspicious traffic while minimizing processing time for the majority of trusted traffic
Solution Approach 2:
The patent enables skipping of additional security detection for traffic that matches the masking results. By identifying trusted traffic patterns through statistical analysis, the system allows these packets to rush through without undergoing time-consuming additional security checks, thus reducing overall processing time while maintaining detection accuracy
Data Source
AI summary
A method includes: A protection device obtains a local statistical result, where the local statistical result indicates frequent key data in first traffic, the local statistical result includes a plurality of entries, each of the plurality of entries includes one piece of key data and a corresponding count value, and the first traffic is traffic that passes, in a first time segment, through a network location in which the protection device is applied; the protection device replaces the key data of each entry in the local statistical result with masked data corresponding to the key data, to obtain a local masking result; and the protection device sends the local masking result to a security service server.


