Network Device Classification Framework Using Encrypted Flow Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network operators face challenges in accurately identifying user devices accessing computer networks due to increased encryption and the variety of devices, leading to difficulties in providing quality of service and experience.

Innovation Solution

A system and method that classify devices using a framework of models to extract and derive flow attributes from network traffic, determining device type and platform without relying on HTTP User Agent information, and applying machine-learning techniques to classify devices based on real-time network performance metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional device identification methods are used, then device classification can be performed, but accuracy decreases with increased encryption and device variety

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidencryption resistance and device variety coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the device identification process into multiple independent classification models, each specializing in different device types or platforms. This segmentation allows each model to be optimized for specific device categories, improving overall identification accuracy while maintaining adaptability to various encryption levels and device varieties.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes classification parameters by selecting different models from the framework based on traffic flow characteristics. When encryption is detected or device variety increases, the system adjusts which models are activated and how they process flow attributes, enabling accurate classification across diverse encrypted and unencrypted device types.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If a comprehensive framework of models is implemented, then device classification accuracy improves, but system complexity increases

Engineering Contradiction:
Improvedevice classification accuracyVSAvoidclassification framework complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal classification framework where a single system handles multiple device types, platforms, and encryption levels through a standardized interface. The framework accepts various flow attributes as input and routes them to appropriate specialized models, providing multi-functional capability without proportionally increasing operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary classification framework that mediates between raw network traffic and device identification results. This framework layer manages the complexity by standardizing how different models receive and process flow attributes, simplifying the overall system architecture while maintaining high classification accuracy through coordinated model execution.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If flow attributes are extracted and derived in real-time, then device classification can be performed on encrypted traffic, but processing time increases

Engineering Contradiction:
Improveencrypted traffic classification capabilityVSAvoidclassification processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary extraction of flow attributes from network traffic before classification occurs. By pre-processing and organizing flow attributes including those from encrypted traffic, the system prepares data in advance for the classification models, reducing real-time processing time while maintaining reliable classification capability across encrypted and unencrypted traffic.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11882045B2System and method for classifying network devices
Publication Date: 2024.01.23 SANDVINE CORP
  • US11882045B2 patent drawing
  • US11882045B2 patent drawing
  • US11882045B2 patent drawing

AI summary

A method and system for classifying a device accessing a computer network. The method including: providing a framework of models configured to classify the device; reviewing a network traffic flow associated with a device; extracting flow attributes associated with a network traffic flow; deriving further flow attributes based on the extracted flow attributes; determining at least one model of the framework of models based on the derived flow attributes and extracted encrypted flow attributes; and classifying the device associated with the network traffic flow based on the at least one model. The system includes: a learning engine configured to provide a framework of models; a packet processing engine configured to review a network traffic flow associated with a device; a device classification engine configured to extract flow attributes, derive further flow attributes and determine at least one model; and a device information aggregator configured to classify the device.