Network Traffic Classification Using Intention Inference Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network traffic monitoring techniques fail to distinguish between primary and support services, especially with the increasing use of HTTPS, leading to a lack of visibility into user intent and accurate traffic classification, which is crucial for network management and policy enforcement.

Innovation Solution

The implementation of intention inference and traffic association techniques, which identify a primary/core domain and group related network flows using machine learning classifiers and Bag of Domains (BoDs) to create models of traffic activity, enabling real-time classification and management of network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional network traffic monitoring techniques are used, then network traffic can be monitored at basic level, but accurate classification and visibility into user intent cannot be achieved

Engineering Contradiction:
Improvetraffic classification accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments network traffic into distinct categories (primary service traffic, support service traffic, background traffic) and processes each segment separately using different analysis methods. This allows accurate classification of primary services while simplifying handling of support and background traffic through automated grouping mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary classification system that acts as a mediator between raw network traffic data and management decisions. This intermediary layer uses machine learning models and traffic association techniques to translate complex traffic patterns into actionable classifications, improving accuracy without requiring end systems to become more complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If HTTPS encryption is widely adopted, then user privacy and security are improved, but visibility into user intent and traffic classification deteriorates

Engineering Contradiction:
Improveuser privacy and securityVSAvoidvisibility into user intent
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs preliminary classification of traffic flows before encryption obscures content details. By analyzing traffic patterns, timing, size, and metadata before HTTPS encryption fully masks the content, the system captures essential classification information while maintaining user privacy during actual communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial decryption or inspection only when necessary for classification purposes, rather than attempting to fully decrypt all HTTPS traffic. This selective approach maintains user privacy for the majority of traffic while obtaining sufficient information for accurate classification of primary services.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If multiple services are co-located on the same platform, then resource utilization is improved, but distinction between primary and support services becomes difficult

Engineering Contradiction:
Improveresource utilizationVSAvoidservice distinction accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies different analysis methods and quality standards to different traffic types within the same network infrastructure. Primary service traffic receives detailed analysis with multiple validation methods, while support and background traffic use simplified classification criteria, allowing accurate service distinction without uniformly increasing complexity across all traffic handling.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes key parameters such as traffic timing patterns, packet size distributions, and flow duration metrics to distinguish primary services from support services even when they share the same infrastructure. By monitoring how these parameters change over time and across different service types, the system maintains accurate classification despite co-location.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10250465B2Network traffic monitoring and classification
Publication Date: 2019.04.02 CISCO TECHNOLOGY INC
  • US10250465B2 patent drawing
  • US10250465B2 patent drawing
  • US10250465B2 patent drawing

AI summary

Presented herein are network traffic/flow monitoring techniques for identifying a primary/core domain that is representative of the service being accessed by a series/set of network flows, and grouping networking traffic flows that result from the user's accessing of the core domain. In one example, a plurality of core domains each corresponding to a primary web service configured to be directly accessed by network flows via one or more networks is identified. For each of the plurality of core domains, one or more models of traffic activity resulting from access to the corresponding primary web service by a network flow is generated. Based on the models of traffic activity, real-time network traffic flows are associated to a selected one of the core domains.