Network Traffic Profile Objects for Application Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring systems face challenges in accurately classifying applications and services due to changing host-based characteristics, which can be modified or obfuscated, leading to ineffective classification despite unchanged behavior.

Innovation Solution

A network monitoring engine that transforms monitored network traffic into profile objects, using metric profiles to identify malicious processes or applications by analyzing network behavior, and provides these profiles to a classifier engine for classification, enabling accurate identification and classification based on network activity rather than host-based characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If host-based characteristics are used for classification, then classification can be performed using readily available process information, but classification accuracy deteriorates when characteristics are modified or obfuscated

Engineering Contradiction:
Improveease of classificationVSAvoidclassification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces network traffic as an intermediary medium for classification. Instead of directly analyzing host-based characteristics that may be obfuscated, the system monitors network packets transmitted by the process. This intermediary approach allows classification based on observable network behavior rather than trusted host-based attributes, resolving the contradiction between ease of classification and accuracy when characteristics are modified.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical system of host-based characteristic analysis with a network-based observation system. By substituting direct process inspection with network traffic monitoring, the system achieves more reliable classification that is not susceptible to host-based obfuscation or modification, thereby maintaining both operational simplicity and classification accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If network traffic monitoring is implemented, then classification accuracy improves by focusing on behavior, but system complexity increases

Engineering Contradiction:
Improveclassification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary network traffic features required for classification rather than monitoring and analyzing all possible network parameters. By selecting and monitoring only relevant characteristics such as destination ports, protocols, and traffic patterns associated with known malicious behaviors, the system achieves high classification accuracy while avoiding the complexity of comprehensive network analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If host-based characteristics are relied upon, then classification systems can operate with simpler architecture, but reliability decreases when characteristics change despite unchanged behavior

Engineering Contradiction:
Improvesystem complexityVSAvoidclassification reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent uses network traffic as a mediator that reflects the actual behavior of processes regardless of their host-based characteristics. This intermediary layer provides a reliable basis for classification because network behavior cannot be easily changed without affecting the observable traffic patterns, thereby ensuring consistent and reliable classification even when host-based characteristics are modified.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10382296B2Classifying applications or activities based on network behavior
Publication Date: 2019.08.13 EXTRAHOP NETWORKS INC
  • US10382296B2 patent drawing
  • US10382296B2 patent drawing
  • US10382296B2 patent drawing

AI summary

Embodiments are directed to monitoring network traffic in a network. A network monitoring engine may be employed to monitor the network to provide metric profiles based on a plurality of characteristics associated with one or more network flows. The network monitoring engine may provide profile objects based on the metric profiles. The network monitoring engine may provide the profile objects to a classifier engine. The classifier engine provide trained activity models selected from a plurality of trained activity models that may be based on a ranked ordering of characteristics of the trained activity models and the profile objects. The classifier engine may provide classification results for the profile objects based on the trained activity models. And, the network monitoring engine may execute policies based on the classification results associated with the profile objects.