Network Traffic Profile Objects for Application Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring systems face challenges in accurately classifying applications and services due to changing host-based characteristics, which can be modified or obfuscated, leading to ineffective classification despite unchanged behavior.
Innovation Solution
A network monitoring engine that transforms monitored network traffic into profile objects, using metric profiles to identify malicious processes or applications by analyzing network behavior, and provides these profiles to a classifier engine for classification, enabling accurate identification and classification based on network activity rather than host-based characteristics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If host-based characteristics are used for classification, then classification can be performed using readily available process information, but classification accuracy deteriorates when characteristics are modified or obfuscated
Solution Approach 1:
The patent introduces network traffic as an intermediary medium for classification. Instead of directly analyzing host-based characteristics that may be obfuscated, the system monitors network packets transmitted by the process. This intermediary approach allows classification based on observable network behavior rather than trusted host-based attributes, resolving the contradiction between ease of classification and accuracy when characteristics are modified.
Solution Approach 2:
The patent replaces the mechanical system of host-based characteristic analysis with a network-based observation system. By substituting direct process inspection with network traffic monitoring, the system achieves more reliable classification that is not susceptible to host-based obfuscation or modification, thereby maintaining both operational simplicity and classification accuracy.
2Measurement precision
If network traffic monitoring is implemented, then classification accuracy improves by focusing on behavior, but system complexity increases
Solution Approach 1:
The patent extracts only the necessary network traffic features required for classification rather than monitoring and analyzing all possible network parameters. By selecting and monitoring only relevant characteristics such as destination ports, protocols, and traffic patterns associated with known malicious behaviors, the system achieves high classification accuracy while avoiding the complexity of comprehensive network analysis.
3Device complexity
If host-based characteristics are relied upon, then classification systems can operate with simpler architecture, but reliability decreases when characteristics change despite unchanged behavior
Solution Approach 1:
The patent uses network traffic as a mediator that reflects the actual behavior of processes regardless of their host-based characteristics. This intermediary layer provides a reliable basis for classification because network behavior cannot be easily changed without affecting the observable traffic patterns, thereby ensuring consistent and reliable classification even when host-based characteristics are modified.
Data Source
AI summary
Embodiments are directed to monitoring network traffic in a network. A network monitoring engine may be employed to monitor the network to provide metric profiles based on a plurality of characteristics associated with one or more network flows. The network monitoring engine may provide profile objects based on the metric profiles. The network monitoring engine may provide the profile objects to a classifier engine. The classifier engine provide trained activity models selected from a plurality of trained activity models that may be based on a ranked ordering of characteristics of the trained activity models and the profile objects. The classifier engine may provide classification results for the profile objects based on the trained activity models. And, the network monitoring engine may execute policies based on the classification results associated with the profile objects.


