ML-Based Multi-Use Application Classification for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in effectively distinguishing and managing 'multi-use' applications, which can exhibit various behaviors and potentially be used maliciously, making it difficult to create comprehensive and up-to-date security policies.

Innovation Solution

A computer system that learns application behavior by observing network activity, automatically identifies multi-use behavior, and enforces security policies to adapt to new applications, using machine learning to predict whether applications are single-use or multi-use based on their communication patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fixed list of multi-use applications is created based on experience, then initial security policy coverage is improved, but the list becomes out-of-date quickly as new applications are created

Engineering Contradiction:
Improvesecurity policy coverageVSAvoidability to handle new applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic classification system that continuously learns and updates application behavior patterns through machine learning. Instead of relying on a static fixed list, the system adapts to new applications by observing their communication patterns and automatically updating the multi-use application classification, ensuring both reliability and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-updating through automated machine learning processes that continuously analyze network traffic and application behavior. The classification model automatically retrain s itself with new data, eliminating the need for manual updates and ensuring the system remains current with newly created applications while maintaining accurate security policy coverage.

Inventive Principle:
Principle #25Self-service

2Reliability

If security policies are created for all possible application behaviors, then comprehensive security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments applications into distinct categories (single-use vs. multi-use) based on their behavior patterns. This segmentation allows the system to apply different security policies to different categories, managing complexity by treating similar applications uniformly while maintaining comprehensive security coverage through targeted classification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of application classification from static vendor-defined categories to dynamic behavior-based categories. By using machine learning to analyze communication patterns and automatically adjust classification parameters, the system achieves comprehensive security coverage without manual policy management complexity.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If manual classification of applications is performed, then accuracy for known applications is improved, but the process cannot keep up with constantly new applications

Engineering Contradiction:
Improveclassification accuracyVSAvoidclassification speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces manual mechanical classification processes with an automated machine learning system. The machine learning model automatically analyzes application communication patterns and performs classification without human intervention, achieving both high accuracy through pattern recognition and high productivity through automation, keeping pace with constantly new applications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements continuous feedback loops where classification results and network traffic data are fed back into the machine learning model for ongoing refinement. This feedback mechanism allows the system to maintain high classification accuracy by continuously learning from new data while operating at automated speeds that can handle constant application proliferation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11553003B2Automated software capabilities classification model that identifies multi-use behavior of new applications on a network
Publication Date: 2023.01.10 ZSCALER INC
  • US11553003B2 patent drawing
  • US11553003B2 patent drawing
  • US11553003B2 patent drawing

AI summary

A computer system automatically learns which application behavior constitutes “multi-use” behavior by observing the behavior of applications on a network. The system uses this learned knowledge to automatically identify multi-use behavior in new applications that appear on the network. When the system enforces security policies against applications on the network, it identifies whether particular behavior of such applications violates any of the security policies. In this way, the system adapts automatically to new behavior of applications on the network over time in order to increase network security.