Traffic Controller for Unauthorized P2P Application Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unauthorized Peer-to-Peer (P2P) applications pose significant challenges to network security in corporate environments by occupying bandwidth, processing power, and storage resources, and can evade conventional firewalls and Network Address Translation (NAT) devices, making it difficult to control their activities and protect sensitive information.
Innovation Solution
A method and apparatus for detecting and controlling unauthorized applications by identifying potential P2P applications, modeling their configuration information, and selectively blocking communications and resource access through a traffic analyzer integrated with a firewall, which includes a P2P Traffic Analyzer (PTA) and Controlled P2P Clients (CCs) to gather and enforce application characteristic information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional firewalls and NAT devices are used to protect corporate networks, then network security is maintained, but unauthorized P2P applications can still evade detection and control
Solution Approach 1:
The system performs preliminary actions by modeling unauthorized P2P applications before they fully operate on the network. The traffic analyzer monitors and models application behavior patterns, peer contact lists, and resource access requests in advance, enabling the firewall to block these applications before they can cause significant harm or expose sensitive information.
Solution Approach 2:
The patent introduces an intermediary system consisting of a traffic analyzer and firewall that sits between the corporate network and unauthorized P2P applications. This intermediary monitors traffic patterns, extracts application configuration information, and selectively blocks communications to peer contacts and requests for access to resources, thereby preventing P2P applications from evading detection.
2Ease of operation
If P2P applications are allowed to operate freely on the network, then user communication and file sharing are enabled, but network bandwidth and processing power are occupied by unauthorized applications
Solution Approach 1:
The system applies local quality by differentiating between authorized and unauthorized P2P applications. The traffic analyzer identifies specific characteristics of unauthorized applications (such as peer contact patterns and resource access behavior) and applies selective blocking only to those specific patterns, while allowing legitimate P2P communication to continue uninterrupted.
Solution Approach 2:
The patent implements partial action by blocking only the specific traffic related to unauthorized P2P applications rather than blocking all P2P traffic or all network traffic. The firewall selectively blocks communications with identified peer contacts and requests for access to specific resources, thereby maintaining network productivity while preventing the harmful effects of unauthorized applications.
3Reliability
If P2P applications use encryption and random port numbers to evade detection, then application privacy and communication security are improved, but network monitoring and control become more difficult
Solution Approach 1:
The patent replaces traditional mechanical inspection methods (packet filtering based on port numbers and headers) with a modeling approach that analyzes application behavior patterns. The traffic analyzer monitors traffic patterns, peer contact lists, and resource access requests to build a model of unauthorized application behavior, enabling detection even when encryption and random port numbers are used.
Solution Approach 2:
The system employs feedback mechanisms where the traffic analyzer continuously monitors network traffic, extracts application configuration information, and updates the model of unauthorized P2P applications. This feedback loop enables the system to adapt to changing encryption methods and port number assignments, maintaining detection capability while preserving application communication security.
4Reliability
If P2P applications are blocked at the firewall level, then network security is improved, but legitimate P2P communication and user access are also restricted
Solution Approach 1:
The patent applies local quality by implementing fine-grained control over P2P traffic. The traffic analyzer identifies specific characteristics of unauthorized applications (peer contact patterns, resource access behavior) and the firewall applies blocking only to those specific characteristics, thereby maintaining network security while preserving access to legitimate P2P applications.
Solution Approach 2:
The system implements dynamic control by continuously monitoring network traffic and updating the model of unauthorized P2P applications. The firewall rules are dynamically adjusted based on the modeled behavior patterns, allowing the system to adapt to new unauthorized applications while maintaining consistent protection of the corporate network.
Data Source
AI summary
A traffic controller is provided which integrates black-box tests of unauthorized applications to extract application characteristics from associated Internet traffic, exploits the networking information learned by host clients, actively scans and controls hosts on the corporate network, and dynamically configures a corporate firewall to block traffic to and from critical application network elements. As a result, the traffic controller effectively manages unauthorized applications and their associated traffic in a corporate environment.


