Network Traffic Classification Using Node Behavior Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network traffic classification mechanisms struggle to effectively manage and control traffic based on conditions orthogonal to explicit packet attributes, such as node behavior and network loading conditions, leading to inefficiencies and vulnerabilities, especially in the face of Denial-of-Service attacks and rapidly changing virus signatures.

Innovation Solution

The development of methods and systems that classify network traffic based on node behavior and observed metrics, allowing for the creation of matching rules and policies to manage bandwidth and security, integrated with existing Layer 7 traffic classification mechanisms, enabling seamless operation across various network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network traffic classification is based on explicit packet attributes only, then classification is simple and fast, but it cannot effectively manage traffic based on node behavior and network conditions

Engineering Contradiction:
Improvetraffic classification capabilityVSAvoidclassification mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extends traffic classification from traditional explicit packet attributes to include implicit attributes by observing node behavior patterns and network path characteristics. This adds a new dimension to classification, enabling the system to classify traffic based on what nodes are doing rather than just what packets say they are, thereby improving adaptability without proportionally increasing complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces an intermediary observation mechanism that monitors node behavior and network conditions without directly interfering with packet flow. This intermediary layer captures implicit attributes and feeds them to the classification system, allowing enhanced classification capability while keeping the core packet processing path simple and efficient

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual configuration is used for traffic classification, then control precision is high, but time consumption and operational complexity increase

Engineering Contradiction:
Improvetraffic classification precisionVSAvoidconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent enables the network system to automatically observe, learn, and classify traffic based on node behavior patterns without requiring manual configuration. The system self-configures classification rules by monitoring network dynamics and identifying traffic patterns autonomously, achieving both high precision and rapid deployment

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors node behavior and classification accuracy, then automatically adjusts classification rules to improve precision over time. This closed-loop approach eliminates manual reconfiguration while maintaining or enhancing classification accuracy through adaptive learning

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional traffic classification is used, then existing systems remain compatible, but vulnerability to DoS attacks and virus propagation increases

Engineering Contradiction:
Improvenetwork securityVSAvoidDoS attack impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by proactively identifying and classifying malicious traffic patterns before they can cause harm. By observing node behavior characteristics such as abnormal connection rates, data transmission patterns, and path anomalies, the system preemptively blocks potential DoS attacks and virus propagation vectors

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent converts the challenge of diverse and evolving attack patterns into a benefit by using unsupervised learning to automatically adapt to new threats. Rather than requiring updates for each new attack type, the system learns to identify malicious behavior patterns autonomously, turning the ever-changing nature of attacks into an opportunity for continuous improvement

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS7545748B1Classification and management of network traffic based on attributes orthogonal to explicit packet attributes
Publication Date: 2009.06.09 CA TECH INC
  • US7545748B1 patent drawing
  • US7545748B1 patent drawing
  • US7545748B1 patent drawing

AI summary

Classification of network traffic based on conditions orthogonal to explicit attributes of packets in network traffic. In one implementation, classification of network traffic based on the behavior of one or more nodes associated with the network traffic. In one implementation, a mechanism is provided that allows for the creation of matching rule predicates that match to certain node behaviors of interest and cause the application of appropriate policies to the network traffic. In one implementation, the node behavior matching functionality can be combined to seamlessly operate in connection with other Layer 7 traffic classification mechanisms that operate on explicitly-presented attributes of the packets.