Mobile Traffic Classification via Domain Name Probabilistic Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Securing mobile networks against malicious attacks and inefficient resource usage is challenging due to the large number of mobile software applications and the inability of existing methods to accurately identify specific applications causing security or performance issues, especially in large-scale networks.
Innovation Solution
A probabilistic model based on domain names is used to classify mobile traffic, allowing for efficient identification of mobile software applications and remedial actions, without the need for detailed packet inspection across large networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If detailed packet inspection is performed to identify mobile software applications, then measurement precision is improved, but device complexity and processing overhead increase significantly
Solution Approach 1:
The patent extracts only the essential identifying feature (domain names) from the complete packet data, avoiding the need to inspect entire packets. This selective extraction maintains application identification accuracy while dramatically reducing processing complexity and overhead.
Solution Approach 2:
The patent creates a simplified representation (copy) of application behavior through domain name patterns rather than analyzing complete packet contents. This copy captures the essential identifying characteristics while avoiding the computational burden of full packet inspection.
2Reliability
If comprehensive traffic analysis is performed across all mobile applications, then reliability of security detection is improved, but productivity of network operations decreases due to processing time
Solution Approach 1:
The patent extracts only the critical domain name information from traffic packets, discarding redundant data. This extraction maintains the ability to reliably identify applications and detect security threats while significantly improving processing throughput and network productivity.
Solution Approach 2:
The patent applies partial action by focusing only on the necessary portion of packet data (domain names) rather than performing exhaustive analysis of all packet contents. This partial approach maintains sufficient reliability for security detection while dramatically improving processing speed and productivity.
3Loss of information
If probabilistic modeling based on domain names is used to classify mobile traffic, then loss of information is reduced in identifying applications, but measurement precision may be compromised compared to full packet inspection
Solution Approach 1:
The patent creates a probabilistic model that copies the essential behavioral patterns of applications through domain name usage. This model captures sufficient information to accurately classify applications while avoiding the need to process complete packet data, thus reducing information loss without significantly compromising precision.
Solution Approach 2:
The patent changes the parameter of analysis from complete packet contents to specific domain name patterns. This parameter change reduces the dimensionality of data required while maintaining classification accuracy through probabilistic modeling of application behavior patterns.
Data Source
AI summary
A method, computer-readable medium, and apparatus for classifying mobile traffic for securing a network or a mobile user endpoint device are disclosed. For example, a method may include a processor for classifying mobile network traffic using a probabilistic model for a plurality of mobile software applications based on a distribution of domain names, detecting an anomaly associated with a mobile software application of the plurality of mobile software applications, and performing a remedial action to address the anomaly.


