Network Telemetry Byte Distribution Cryptographic Protocol Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Encrypted network traffic poses challenges for visibility and threat detection, as traditional methods like deep packet inspection are ineffective, making it difficult to detect encrypted data and cryptographic protocols, which are crucial for identifying malicious activities and data exfiltration.

Innovation Solution

Incorporating byte value distribution metrics and cryptographic protocol data into network telemetry systems, allowing switches to generate and transmit telemetry data that includes these metrics, which can be used to classify flows and detect malicious activities using machine learning classifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted data is used for network traffic, then security and privacy are improved, but visibility and threat detection capability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidvisibility
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extracts cryptographic protocol data elements (CPDEs) from the encrypted network traffic streams. By capturing and analyzing these protocol elements during the encryption/decryption process, the system can detect security issues without needing to decrypt the actual application data, thus maintaining security while improving visibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces CPDEs as intermediary data structures that mediate between the encrypted traffic and the detection system. These CPDEs contain cryptographic protocol information that can be analyzed to detect threats, serving as a bridge that allows monitoring of encrypted traffic without compromising the encryption integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If deep packet inspection is used to analyze network traffic, then threat detection capability is improved, but effectiveness on encrypted data deteriorates

Engineering Contradiction:
Improvethreat detection capabilityVSAvoideffectiveness on encrypted data
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

Instead of attempting to inspect the encrypted payload through deep packet inspection, the system extracts cryptographic protocol data elements from the traffic streams. This extracted CPDE data can then be analyzed using machine learning classifiers to detect threats, making the detection method effective against encrypted data without requiring traditional DPI capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical deep packet inspection approach with a machine learning-based classification system that analyzes extracted cryptographic protocol data. This substitution enables effective threat detection on encrypted traffic by using AI/ML models trained on CPDE patterns rather than traditional packet inspection mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Loss of information

If network telemetry systems collect detailed traffic information, then analysis capability is improved, but data processing complexity increases

Engineering Contradiction:
Improveanalysis capabilityVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary cryptographic protocol data elements from the network traffic, filtering out unnecessary data. This selective extraction maintains essential analysis capability for detecting security issues while significantly reducing the volume and complexity of data that needs to be processed and stored.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms the data representation by changing from raw network packet data to extracted CPDE parameters. This parameter transformation simplifies the data structure and makes it more suitable for machine learning analysis, reducing processing complexity while maintaining analytical effectiveness.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240007774A1Network Telemetry with Byte Distribution and Cryptographic Protocol Data Elements
Publication Date: 2024.01.04 CISCO TECHNOLOGY INC
  • US20240007774A1 patent drawing
  • US20240007774A1 patent drawing
  • US20240007774A1 patent drawing

AI summary

In one embodiment, a method includes receiving a traffic flow including a plurality of packets encrypted using a cryptographic protocol, determining cryptographic protocol data of the traffic flow, and transmitting telemetry data of the traffic flow including the cryptographic protocol data. In another embodiment, a method includes receiving telemetry data of a traffic flow including a plurality of packets encrypted using a cryptographic protocol, the telemetry data including cryptographic protocol data of the traffic flow, classifying the traffic flow based on the cryptographic protocol data using a machine learning classifier; and taking a remedial action with respect to the traffic flow based on the classification of the traffic flow.