ML Network Flow Classification for Application Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches for securing enterprise IT infrastructure against mobile devices are inadequate, particularly in accurately identifying new or malicious applications due to high bandwidth consumption and diverse applications, leading to scalability issues and reduced accuracy in network flow classification.

Innovation Solution

An ML-based network flow classification system that uses unsupervised clustering to learn application signatures from network packets, allowing for real-time detection of new applications by determining the distance between network data flows and existing clusters, thereby enhancing accuracy and reducing computational resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network flow classification methods are used to identify applications, then security monitoring is provided, but accuracy deteriorates for new or malicious applications and computational resources increase excessively

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical/network-based classification methods (deep packet inspection, port analysis) with a machine learning-based system that automatically learns application signatures from network traffic patterns, achieving higher accuracy for new applications without proportional increases in computational complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the parameters used for classification from traditional network layer parameters (ports, protocols) to learned application-level signatures derived from traffic patterns, enabling accurate identification of new applications that don't fit traditional classification schemes

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If deep packet inspection and application fingerprinting are used to secure network infrastructure, then application visibility is improved, but bandwidth consumption increases and scalability deteriorates

Engineering Contradiction:
Improveapplication visibilityVSAvoidbandwidth consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential features needed for application identification from network traffic, using machine learning to learn signatures from key traffic patterns rather than inspecting entire packet contents, thereby maintaining application visibility while reducing bandwidth consumption

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary learning of application signatures during a training phase using historical traffic data, so that during operational phase, classification can be performed efficiently with minimal real-time bandwidth consumption for feature extraction

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10796243B2Network flow classification
Publication Date: 2020.10.06 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10796243B2 patent drawing
  • US10796243B2 patent drawing
  • US10796243B2 patent drawing

AI summary

Network flow classification can include clustering a network flow database into a number of at least one of applications and network flows. Network flow classification can include classifying the number of the at least one of applications and network flows.