Automated Network Traffic Classification via Statistical Signature Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network application control technologies face challenges in classifying unknown network traffic, as they require manual signature generation and application, leading to blanket policies or delayed escalation, which are inefficient and require detective work to determine whether to allow or block unclassified traffic.
Innovation Solution
A method and system that detect unknown network traffic, generate a signature for it, and provide a policy recommendation on whether to allow or block, while updating the database with the new signature for future matching, using a firewall and management computer to analyze and classify traffic based on patterns and statistical characteristics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If pattern matching based traffic classification is used, then network traffic can be controlled based on application type, but new network-enabled applications cannot be classified because signatures must be manually generated and assigned
Solution Approach 1:
The system performs self-service by automatically generating signatures for unknown applications through statistical analysis of traffic patterns. The signature generation process is automated without requiring manual intervention, allowing the system to adapt to new applications dynamically. The system analyzes traffic characteristics, generates statistical signatures, and updates the classification database autonomously.
Solution Approach 2:
The system performs preliminary action by proactively analyzing unknown traffic and generating signatures before manual intervention is required. Instead of waiting for manual signature creation, the system pre-generates statistical signatures through automated analysis of traffic patterns, enabling immediate classification of new applications.
2Ease of operation
If blanket allow or deny policies are applied to unclassified traffic, then all unknown traffic can be controlled uniformly, but the approach is inefficient and requires detective work to determine appropriate policies
Solution Approach 1:
The system implements feedback by automatically analyzing unknown traffic patterns and generating policy recommendations based on the analysis results. The feedback loop continuously monitors traffic characteristics, generates statistical signatures, and provides policy recommendations, eliminating the need for manual detective work while maintaining operational simplicity.
Solution Approach 2:
The system replaces the mechanical process of manual detective work with automated statistical analysis and machine learning algorithms. The automated system analyzes traffic patterns, generates signatures, and recommends policies, substituting human investigative efforts with computational processes that are both faster and more scalable.
3Reliability
If custom generated signatures are created based on traditional firewall characteristics, then some unclassified traffic can be controlled, but the process still requires manual intervention and escalation to vendors for accurate signatures
Solution Approach 1:
The system performs self-service by automatically generating accurate statistical signatures without requiring escalation to vendors. The automated analysis of traffic patterns and generation of statistical signatures eliminates the need for manual intervention and external vendor support, reducing time loss while maintaining high classification accuracy.
Solution Approach 2:
The system applies parameter changes by transitioning from traditional firewall characteristics to statistical analysis of traffic patterns. By changing the classification parameters from static port/protocol matching to dynamic statistical signatures, the system achieves more accurate classification while eliminating manual escalation processes.
Data Source
AI summary
A network application control system is employed to classify unknown computer network traffic. The system includes a firewall computer with a network filter that filters network traffic generated by endpoint computers running local processes. The system may also include a management computer with an endpoint management server that manages endpoint agents running in the endpoint computers. Unknown network traffic is analyzed to generate a pattern matching signature and a policy recommendation. The policy recommendation may be applied to subsequently received network traffic matching the signature.


