Network Traffic Fingerprinting via Directed Graph Random Walks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing application discovery tools in computer networks are costly, require manual intervention, and fail to identify traffic origins and classify arbitrary sequences of flows effectively, ignoring intermediate nodes and lacking the ability to model complex network dynamics.

Innovation Solution

A device obtains telemetry data to form a directed graph, simulates traffic through random walks, clusters trails, and generates an application fingerprint to identify traffic associated with specific applications, using machine learning techniques to classify and visualize network traffic patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual application discovery tools are used, then traffic identification accuracy may be improved, but operational complexity and cost increase significantly

Engineering Contradiction:
Improvetraffic identification accuracyVSAvoidmanual intervention requirement
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system performs automated application discovery by having the network infrastructure itself generate and analyze flow records. The approach uses self-organizing maps and machine learning algorithms that automatically classify traffic patterns without requiring manual configuration or intervention, enabling the system to identify applications autonomously while maintaining high accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical analysis methods with electronic data processing and machine learning algorithms. Instead of manual inspection and classification of network flows, the system uses computational algorithms including self-organizing maps, random forests, and other ML techniques to automatically analyze and classify traffic patterns, significantly reducing operational complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Difficulty of detecting and measuring

If comprehensive traffic analysis is performed to identify all applications, then application detection capability improves, but processing time and computational resources increase

Engineering Contradiction:
Improveapplication detection capabilityVSAvoidprocessing time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The system performs preliminary clustering of flow records using self-organizing maps before applying more complex classification algorithms. By pre-grouping similar traffic flows based on their characteristics, the system reduces the computational burden of subsequent analysis and enables faster identification of application patterns without sacrificing detection capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the traffic analysis process into multiple stages: initial flow record collection, clustering based on flow characteristics, pattern recognition, and final application identification. This segmented approach allows the system to process large volumes of traffic data efficiently by breaking down the complex analysis task into manageable steps that can be executed in parallel

Inventive Principle:
Principle #1Segmentation

3Productivity

If simple traffic classification methods are used, then processing speed improves, but ability to handle complex network dynamics deteriorates

Engineering Contradiction:
Improveprocessing speedVSAvoidcomplex network dynamics modeling
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system employs dynamic machine learning models including random forests and other adaptive algorithms that can adjust to changing network conditions in real-time. These models learn from incoming flow records and adapt their classification criteria based on observed traffic patterns, enabling the system to maintain high processing speed while effectively handling complex and evolving network dynamics

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent utilizes multiple flow parameters and characteristics (such as packet size, inter-arrival times, protocol types, and destination ports) to create a comprehensive traffic profile. By analyzing changes in these parameters over time and across different flows, the system can distinguish between various applications even when they use similar protocols, maintaining both speed and adaptability

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11044168B2Fingerprinting application traffic in a network
Publication Date: 2021.06.22 CISCO TECHNOLOGY INC
  • US11044168B2 patent drawing
  • US11044168B2 patent drawing
  • US11044168B2 patent drawing

AI summary

In one embodiment, a device obtains telemetry data regarding a plurality of traffic flows in a network. The device forms a directed graph based on the telemetry data, wherein nodes of the graph represent devices in the network. The device simulates traffic for one or more of the devices by performing random walks starting at a particular node on the directed graph to generate a set of trails, each trail representing a sequence of one or more flows. The device clusters the set of trails to form one or more clusters. The device generates an application fingerprint for an application based on one of the one or more clusters. The device uses the application fingerprint to identify traffic in the network as associated with the application.