Network Mapping Engine Identifies Applications via Traffic Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networks, identifying and mapping applications to specific devices is challenging due to encrypted data packets and lack of application name or type information, making it difficult to determine affected applications and clients during changes or maintenance.

Innovation Solution

A system that analyzes network traffic patterns and configuration data to identify applications without needing application names, using a mapping engine to associate data traffic patterns with network infrastructure elements and generate an overlay for displaying data flow, enabling notifications and data management policy recommendations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is performed to identify application contents, then application identification accuracy is improved, but encryption prevents identification and increases processing complexity

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mapping system that creates associations between network devices and applications without requiring direct inspection of encrypted packet contents. The mapping engine acts as a mediator that correlates device identifiers with application identifiers through side-channel information, thereby maintaining application identification accuracy while avoiding the complexity of decrypting and inspecting encrypted traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If network devices forward data packets using only IP addresses and port numbers, then routing efficiency is improved, but application identification capability deteriorates

Engineering Contradiction:
Improverouting efficiencyVSAvoidapplication identification capability
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent implements preliminary action by pre-establishing a mapping between network devices and applications before data transmission occurs. The mapping engine proactively correlates device identifiers with application identifiers and stores this information for rapid retrieval during routing operations. This allows network devices to maintain efficient forwarding based on IP addresses and port numbers while simultaneously preserving application identification capability through the pre-computed mapping.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If application mapping is implemented to identify affected applications during network changes, then network change management is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork change managementVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the mapping engine to automatically discover, correlate, and maintain device-application mappings without requiring manual configuration or intervention. The system autonomously monitors network traffic patterns, identifies relationships between devices and applications, and updates the mapping database dynamically. This automation improves network change management capability while minimizing the increase in system complexity by eliminating manual mapping processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11528206B2Identifying and mapping applications to devices in a network
Publication Date: 2022.12.13 ORDR INC
  • US11528206B2 patent drawing
  • US11528206B2 patent drawing
  • US11528206B2 patent drawing

AI summary

Techniques for identifying and mapping applications to devices in a network are disclosed. A system monitors data transmitted on a network to identify a plurality of data traffic patterns in the network. Based on the plurality of data traffic patterns, the system identifies a plurality of applications associated with respective subsets of the data, the plurality of applications including a first and a second application. The system determines that a particular network infrastructure element, among the plurality of network infrastructure elements, processes data associated with the first application. The system stores a mapping between the particular network infrastructure element and the first application.