Traffic Controller for Unauthorized P2P Application Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized Peer-to-Peer (P2P) applications pose significant challenges to network security in corporate environments by occupying bandwidth, processing power, and storage resources, and can evade conventional firewalls and Network Address Translation (NAT) devices, making it difficult to control their activities and protect sensitive information.

Innovation Solution

A method and apparatus for detecting and controlling unauthorized applications by identifying potential P2P applications, modeling their configuration information, and selectively blocking communications and resource access through a traffic analyzer integrated with a firewall, which includes a P2P Traffic Analyzer (PTA) and Controlled P2P Clients (CCs) to gather and enforce application characteristic information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewalls and NAT devices are used to protect corporate networks, then network security is maintained, but unauthorized P2P applications can still evade detection and control

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection of unauthorized P2P applications
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary actions by modeling unauthorized P2P applications before they fully operate on the network. The traffic analyzer monitors and models application behavior patterns, peer contact lists, and resource access requests in advance, enabling the firewall to block these applications before they can cause significant harm or expose sensitive information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary system consisting of a traffic analyzer and firewall that sits between the corporate network and unauthorized P2P applications. This intermediary monitors traffic patterns, extracts application configuration information, and selectively blocks communications to peer contacts and requests for access to resources, thereby preventing P2P applications from evading detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If P2P applications are allowed to operate freely on the network, then user communication and file sharing are enabled, but network bandwidth and processing power are occupied by unauthorized applications

Engineering Contradiction:
Improveuser communication capabilityVSAvoidnetwork resource availability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system applies local quality by differentiating between authorized and unauthorized P2P applications. The traffic analyzer identifies specific characteristics of unauthorized applications (such as peer contact patterns and resource access behavior) and applies selective blocking only to those specific patterns, while allowing legitimate P2P communication to continue uninterrupted.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by blocking only the specific traffic related to unauthorized P2P applications rather than blocking all P2P traffic or all network traffic. The firewall selectively blocks communications with identified peer contacts and requests for access to specific resources, thereby maintaining network productivity while preventing the harmful effects of unauthorized applications.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If P2P applications use encryption and random port numbers to evade detection, then application privacy and communication security are improved, but network monitoring and control become more difficult

Engineering Contradiction:
Improveapplication communication securityVSAvoidmonitoring of encrypted traffic
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent replaces traditional mechanical inspection methods (packet filtering based on port numbers and headers) with a modeling approach that analyzes application behavior patterns. The traffic analyzer monitors traffic patterns, peer contact lists, and resource access requests to build a model of unauthorized application behavior, enabling detection even when encryption and random port numbers are used.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system employs feedback mechanisms where the traffic analyzer continuously monitors network traffic, extracts application configuration information, and updates the model of unauthorized P2P applications. This feedback loop enables the system to adapt to changing encryption methods and port number assignments, maintaining detection capability while preserving application communication security.

Inventive Principle:
Principle #23Feedback

4Reliability

If P2P applications are blocked at the firewall level, then network security is improved, but legitimate P2P communication and user access are also restricted

Engineering Contradiction:
Improvecorporate network securityVSAvoidP2P application accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing fine-grained control over P2P traffic. The traffic analyzer identifies specific characteristics of unauthorized applications (peer contact patterns, resource access behavior) and the firewall applies blocking only to those specific characteristics, thereby maintaining network security while preserving access to legitimate P2P applications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements dynamic control by continuously monitoring network traffic and updating the model of unauthorized P2P applications. The firewall rules are dynamically adjusted based on the modeled behavior patterns, allowing the system to adapt to new unauthorized applications while maintaining consistent protection of the corporate network.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8230513B2Method and apparatus for protecting networks from unauthorized applications
Publication Date: 2012.07.24 PULSELINK SYSTEMS LLC
  • US8230513B2 patent drawing
  • US8230513B2 patent drawing
  • US8230513B2 patent drawing

AI summary

A traffic controller is provided which integrates black-box tests of unauthorized applications to extract application characteristics from associated Internet traffic, exploits the networking information learned by host clients, actively scans and controls hosts on the corporate network, and dynamically configures a corporate firewall to block traffic to and from critical application network elements. As a result, the traffic controller effectively manages unauthorized applications and their associated traffic in a corporate environment.