Network Traffic Classification via Application Flow Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods lack effective solutions for identifying and classifying network traffic flows generated by different application-layer protocols, which is crucial for quality of service engineering, traffic control, and network security, especially for resource-intensive applications like P2P, and for enterprise networks to monitor and manage network activities.
Innovation Solution
A method and system that classify network traffic by obtaining application distribution data, extracting tokens from flows using a computer processor, and generating identification rules based on context information to locate tokens, enabling the classification of network traffic using these rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional network traffic analysis methods are used, then network traffic can be monitored, but accurate identification and classification of application-layer protocol flows cannot be achieved
Solution Approach 1:
The system performs preliminary controlled execution of applications to capture their network flows before actual network monitoring. This preliminary action creates a reference database of application-specific flow patterns, enabling accurate identification during actual network traffic analysis without requiring complex real-time analysis algorithms.
Solution Approach 2:
The system creates copies of application flows through controlled execution in a test environment. These copied flows serve as templates or signatures that are then matched against actual network traffic. This copying approach enables reliable classification by comparing unknown flows against known flow patterns from controlled executions.
2Adaptability or versatility
If comprehensive network traffic analysis is performed to identify all application flows, then better network control is achieved, but system complexity and computational resources increase
Solution Approach 1:
The system segments the network traffic analysis problem into two distinct phases: (1) controlled execution phase where applications are run in isolation to capture their flow patterns, and (2) matching phase where captured flows are compared against the reference database. This segmentation reduces system complexity by separating the complex flow capture process from the simpler pattern matching process.
Solution Approach 2:
The system introduces an intermediary component - the controlled execution environment - that acts as a mediator between the actual network traffic and the analysis system. This intermediary captures and preprocesses flow data, transforming complex raw network traffic into structured flow patterns that are easier to analyze and classify, thereby reducing overall system complexity.
Data Source
AI summary
A method for classifying network traffic in a network. The method includes obtaining, from an application distribution source, an application distribution data set of comprising information associated with distributing an application from the pre-determined application distribution source, extracting, based on a pre-determined extraction criterion, a token from the application distribution data set of the application, obtaining, from the network traffic, a plurality of flows generated by the application, extracting, in response to detecting the token in a flow of the plurality of flows, context information associated with the token in the flow, and generating an identification rule of the application based on the token and the context information, wherein the identification rule describes one or more rule steps to locate the token in the flow, wherein the network traffic is classified using at least the identification rule.


