P2P Network Detection via Target File Placement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting Peer-to-Peer network software applications on computer systems are inadequate, as they rely on creating software blueprints or monitoring protocols, which become outdated with new applications and encrypted communications, leaving organizations vulnerable to unauthorized file sharing and bandwidth consumption.

Innovation Solution

A system that creates a target file with unique identifying data and places it in folders on the target computer, then searches for this file on the Peer-to-Peer network to detect the presence of Peer-to-Peer software, allowing for automatic notification and blocking of unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If software blueprints or protocol monitoring methods are used to detect Peer-to-Peer network software, then detection capability is improved, but the methods become outdated with new applications and encrypted communications

Engineering Contradiction:
Improvedetection capabilityVSAvoidadaptability to new applications
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system places a target file on the monitored computer and leverages the Peer-to-Peer network's own search functionality to detect the file. This self-service approach uses the network's inherent mechanisms against itself, allowing detection of any application participating in the network regardless of its specific protocol or encryption method.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The target file acts as an intermediary object that mediates between the monitoring system and the Peer-to-Peer network. By placing a known file on the target system and searching for it through the network, the system creates a detectable marker that reveals the presence of Peer-to-Peer software without needing to understand or adapt to specific application protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional detection methods are used, then known applications can be identified, but encrypted communications and new applications cannot be detected

Engineering Contradiction:
Improvedetection accuracyVSAvoidencrypted communications
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The detection system uses the Peer-to-Peer network's own search and file-sharing mechanisms to detect encrypted communications. By placing a target file and observing whether it appears in network searches, the system reliably detects encrypted P2P traffic without needing to decrypt or analyze the encrypted content itself.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system creates a known copy of a target file and places it on the monitored system. By searching for this specific copy through the Peer-to-Peer network, the system can detect whether the file has been shared through encrypted P2P communications, providing reliable detection without compromising security.

Inventive Principle:
Principle #26Copying

3Measurement precision

If manual monitoring of network traffic is performed, then unauthorized file sharing can be detected, but bandwidth consumption increases and response time decreases

Engineering Contradiction:
Improveunauthorized sharing detectionVSAvoidnetwork bandwidth efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system extracts only the essential detection function from complex network monitoring by placing a single target file and searching for it through the Peer-to-Peer network. This extraction approach detects unauthorized sharing without requiring continuous monitoring of all network traffic, thereby maintaining bandwidth efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of monitoring and copying all network traffic for analysis, the system creates a single target file copy and uses the network's own search mechanisms to locate it. This approach provides accurate detection of unauthorized sharing while consuming minimal network bandwidth compared to comprehensive traffic monitoring.

Inventive Principle:
Principle #26Copying

Data Source

PatentUSRE47628E1System for identifying the presence of peer-to-peer network software applications
Publication Date: 2019.10.01 KROLL INFORMATION ASSURANCE LLC
  • USRE47628E1 patent drawing
  • USRE47628E1 patent drawing
  • USRE47628E1 patent drawing

AI summary

A system and method for detecting peer-to-peer network software operating on a target computer. A target file is created, and placed in one or more folders on the target computer. A search is issued on a Peer-to-Peer network for the target file. Peer-to-peer software is detected to be operating on the target computer in accordance with results of the search.