Network Device Traffic Interception via Application ID Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network devices are unable to perform flow tapping of traffic based on application identifiers and uniform resource locators (URLs), leading to law enforcement authorities capturing and filtering all traffic, wasting resources and failing to capture malicious actors.
Innovation Solution
A network device that receives requests to install filters associated with application identifiers or URLs, generates packet copies, performs deep packet inspection, and forwards matching packets to content destination devices while preventing non-matching packets from being forwarded, thereby conserving resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If law enforcement authorities capture and filter all network traffic, then they can identify malicious traffic, but they waste computing resources and networking resources
Solution Approach 1:
The patent applies preliminary action by performing deep packet inspection and filtering at the network device level before traffic reaches the law enforcement analysis system. The network device proactively identifies and separates traffic matching filter criteria (application identifiers, URLs, IP addresses, ports, protocols) from the overall traffic flow, so that only relevant traffic is forwarded to content destination devices for analysis. This preliminary filtering action prevents the waste of resources on capturing and processing all traffic.
2Productivity
If network devices perform deep packet inspection to identify application identifiers and URLs, then they can selectively forward relevant traffic, but the device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the traffic filtering and inspection function into modular components within the network device. The deep packet inspection process is segmented into distinct stages: extracting packet data, identifying application identifiers and URLs, comparing against filter criteria, and making forwarding decisions. This segmentation allows the complex inspection process to be implemented as a series of manageable operations, reducing the perceived device complexity while maintaining high productivity in selective traffic forwarding.
Solution Approach 2:
The patent introduces an intermediary filtering mechanism at the network device that acts as a mediator between the network traffic flow and the law enforcement analysis system. This intermediary performs the deep packet inspection and applies filtering rules, effectively mediating which traffic reaches the content destination devices. This intermediary layer manages the complexity by handling all inspection logic centrally, allowing the rest of the network infrastructure to remain relatively simple.
3Reliability
If all traffic is captured for analysis, then no malicious actors are missed, but the quantity of traffic to be processed increases significantly
Solution Approach 1:
The patent applies local quality by making the traffic capture process selective rather than uniform. Instead of capturing all traffic with equal intensity, the system applies deep packet inspection with specific filter criteria (application identifiers, URLs, IP addresses, ports, protocols) to identify and capture only the locally relevant traffic that matches the criteria. This localized approach to traffic selection maintains reliability in capturing malicious traffic while dramatically reducing the total quantity of traffic data that needs to be processed and stored.
Data Source
AI summary
A network device may receive a request to install a filter associated with an application identifier or a uniform resource locator (URL), and may add, based on the request, information identifying the filter to a list of filters associated with the network device. The network device may receive a packet destined for an endpoint device, may generate a copy of the packet, and may cause the packet to be forwarded to the endpoint device. The network device may perform deep packet inspection of the copy to identify a packet application identifier or a packet URL, and may determine whether the packet application identifier or the packet URL matches the application identifier or the URL. The network device may cause the copy of the packet to be forwarded to a content destination device when the packet application identifier or the packet URL matches the application identifier or the URL.


