Network Telemetry Byte Distribution Cryptographic Protocol Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Encrypted network traffic poses challenges for visibility and threat detection, as traditional methods like deep packet inspection are ineffective, making it difficult to detect encrypted data and cryptographic protocols, which are crucial for identifying malicious activities and data exfiltration.
Innovation Solution
Incorporating byte value distribution metrics and cryptographic protocol data into network telemetry systems, allowing switches to generate and transmit telemetry data that includes these metrics, which can be used to classify flows and detect malicious activities using machine learning classifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted data is used for network traffic, then security and privacy are improved, but visibility and threat detection capability deteriorate
Solution Approach 1:
The patent extracts cryptographic protocol data elements (CPDEs) from the encrypted network traffic streams. By capturing and analyzing these protocol elements during the encryption/decryption process, the system can detect security issues without needing to decrypt the actual application data, thus maintaining security while improving visibility.
Solution Approach 2:
The patent introduces CPDEs as intermediary data structures that mediate between the encrypted traffic and the detection system. These CPDEs contain cryptographic protocol information that can be analyzed to detect threats, serving as a bridge that allows monitoring of encrypted traffic without compromising the encryption integrity.
2Difficulty of detecting and measuring
If deep packet inspection is used to analyze network traffic, then threat detection capability is improved, but effectiveness on encrypted data deteriorates
Solution Approach 1:
Instead of attempting to inspect the encrypted payload through deep packet inspection, the system extracts cryptographic protocol data elements from the traffic streams. This extracted CPDE data can then be analyzed using machine learning classifiers to detect threats, making the detection method effective against encrypted data without requiring traditional DPI capabilities.
Solution Approach 2:
The patent replaces the mechanical deep packet inspection approach with a machine learning-based classification system that analyzes extracted cryptographic protocol data. This substitution enables effective threat detection on encrypted traffic by using AI/ML models trained on CPDE patterns rather than traditional packet inspection mechanisms.
3Loss of information
If network telemetry systems collect detailed traffic information, then analysis capability is improved, but data processing complexity increases
Solution Approach 1:
The patent extracts only the necessary cryptographic protocol data elements from the network traffic, filtering out unnecessary data. This selective extraction maintains essential analysis capability for detecting security issues while significantly reducing the volume and complexity of data that needs to be processed and stored.
Solution Approach 2:
The patent transforms the data representation by changing from raw network packet data to extracted CPDE parameters. This parameter transformation simplifies the data structure and makes it more suitable for machine learning analysis, reducing processing complexity while maintaining analytical effectiveness.
Data Source
AI summary
In one embodiment, a method includes receiving a traffic flow including a plurality of packets encrypted using a cryptographic protocol, determining cryptographic protocol data of the traffic flow, and transmitting telemetry data of the traffic flow including the cryptographic protocol data. In another embodiment, a method includes receiving telemetry data of a traffic flow including a plurality of packets encrypted using a cryptographic protocol, the telemetry data including cryptographic protocol data of the traffic flow, classifying the traffic flow based on the cryptographic protocol data using a machine learning classifier; and taking a remedial action with respect to the traffic flow based on the classification of the traffic flow.


