Network Traffic Categorization via Embedding Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for determining network traffic categories face challenges such as scalability issues, adaptability problems due to evolving network patterns, privacy concerns, and difficulties with encrypted traffic, leading to inefficient resource utilization and incorrect network modifications.

Innovation Solution

A method utilizing machine learning models to categorize network traffic by transforming packet size data into embeddings, generating similarity metrics, creating graphs, and applying community detection models to identify traffic categories without prior knowledge of application categories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual catalogs or prior domain knowledge are used to determine network traffic categories, then network traffic categorization can be performed, but scalability issues arise and the system cannot adapt to evolving network patterns

Engineering Contradiction:
Improveadaptability to evolving network patternsVSAvoidcomplexity of manual catalog maintenance
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically generating network traffic categories through machine learning models without requiring manual catalog creation or maintenance. The models process network traffic data, generate embeddings, and automatically identify categories, enabling the system to adapt to evolving patterns autonomously

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes parameters by transforming network traffic data into embeddings through machine learning models, converting raw traffic characteristics into a format that reveals categorical patterns. This parameter transformation enables automatic category identification without manual intervention

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional network traffic categorization methods are used, then some level of categorization is achieved, but resource utilization becomes inefficient and incorrect network modifications occur

Engineering Contradiction:
Improveaccuracy of network traffic categorizationVSAvoidcomputing and networking resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system replaces traditional mechanical categorization methods with machine learning-based automatic classification. Instead of manual rule-based systems, the patent uses neural networks and embedding models to substitute and achieve more accurate categorization with optimized resource usage

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If application information is used to determine network traffic categories, then categorization accuracy improves, but privacy concerns arise and encrypted traffic cannot be handled

Engineering Contradiction:
Improveprecision of traffic category identificationVSAvoidprivacy violations and encryption limitations
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system extracts categorical information from network traffic data without extracting or requiring application-level information. By taking out only the necessary traffic pattern features and processing them through machine learning models, the system achieves accurate categorization while preserving privacy and working with encrypted traffic

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12284094B2Utilizing machine learning models for network traffic categorization
Publication Date: 2025.04.22 JUNIPER NETWORKS INC
  • US12284094B2 patent drawing
  • US12284094B2 patent drawing
  • US12284094B2 patent drawing

AI summary

A device may receive network traffic data that includes network traffic packet sizes, and may transform the network traffic data into transformed data. The device may process the transformed data, with a machine learning model, to generate an embedding, and may obtain a similarity metric for the embedding. The device may create a graph with nodes and edges based on the embedding and the similarity metric, and may process the graph, with a community detection model, to identify network traffic categories for the network traffic data. The device may perform one or more actions based on the network traffic categories.