Automated Network Traffic Classification via Statistical Signature Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network application control technologies face challenges in classifying unknown network traffic, as they require manual signature generation and application, leading to blanket policies or delayed escalation, which are inefficient and require detective work to determine whether to allow or block unclassified traffic.

Innovation Solution

A method and system that detect unknown network traffic, generate a signature for it, and provide a policy recommendation on whether to allow or block, while updating the database with the new signature for future matching, using a firewall and management computer to analyze and classify traffic based on patterns and statistical characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If pattern matching based traffic classification is used, then network traffic can be controlled based on application type, but new network-enabled applications cannot be classified because signatures must be manually generated and assigned

Engineering Contradiction:
Improveability to classify new applicationsVSAvoidmanual signature generation process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically generating signatures for unknown applications through statistical analysis of traffic patterns. The signature generation process is automated without requiring manual intervention, allowing the system to adapt to new applications dynamically. The system analyzes traffic characteristics, generates statistical signatures, and updates the classification database autonomously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by proactively analyzing unknown traffic and generating signatures before manual intervention is required. Instead of waiting for manual signature creation, the system pre-generates statistical signatures through automated analysis of traffic patterns, enabling immediate classification of new applications.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If blanket allow or deny policies are applied to unclassified traffic, then all unknown traffic can be controlled uniformly, but the approach is inefficient and requires detective work to determine appropriate policies

Engineering Contradiction:
Improvepolicy application simplicityVSAvoidtime to determine policy
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system implements feedback by automatically analyzing unknown traffic patterns and generating policy recommendations based on the analysis results. The feedback loop continuously monitors traffic characteristics, generates statistical signatures, and provides policy recommendations, eliminating the need for manual detective work while maintaining operational simplicity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces the mechanical process of manual detective work with automated statistical analysis and machine learning algorithms. The automated system analyzes traffic patterns, generates signatures, and recommends policies, substituting human investigative efforts with computational processes that are both faster and more scalable.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If custom generated signatures are created based on traditional firewall characteristics, then some unclassified traffic can be controlled, but the process still requires manual intervention and escalation to vendors for accurate signatures

Engineering Contradiction:
Improvetraffic classification accuracyVSAvoidtime for manual escalation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically generating accurate statistical signatures without requiring escalation to vendors. The automated analysis of traffic patterns and generation of statistical signatures eliminates the need for manual intervention and external vendor support, reducing time loss while maintaining high classification accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system applies parameter changes by transitioning from traditional firewall characteristics to statistical analysis of traffic patterns. By changing the classification parameters from static port/protocol matching to dynamic statistical signatures, the system achieves more accurate classification while eliminating manual escalation processes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8516586B1Classification of unknown computer network traffic
Publication Date: 2013.08.20 TREND MICRO INC
  • US8516586B1 patent drawing
  • US8516586B1 patent drawing
  • US8516586B1 patent drawing

AI summary

A network application control system is employed to classify unknown computer network traffic. The system includes a firewall computer with a network filter that filters network traffic generated by endpoint computers running local processes. The system may also include a management computer with an endpoint management server that manages endpoint agents running in the endpoint computers. Unknown network traffic is analyzed to generate a pattern matching signature and a policy recommendation. The policy recommendation may be applied to subsequently received network traffic matching the signature.