P2P Traffic Management via Application Identifier Tagging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods are inadequate for effectively detecting and controlling P2P traffic, particularly encrypted P2P packets, due to variations in technical standards and the difficulty in inspecting encrypted traffic, leading to network congestion and security vulnerabilities.
Innovation Solution
A P2P traffic management system utilizing P2P flow agents and security gateways that monitor and control encrypted P2P traffic by adding application identifiers to packets and using these identifiers to apply policies for selective passage, bandwidth restriction, or packet discard, without requiring payload or header analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If P2P traffic is monitored and controlled using existing methods, then network security and traffic management are improved, but the processing overhead and time consumption increase significantly
Solution Approach 1:
The patent applies preliminary action by embedding flow agents within P2P applications that pre-identify and tag packets with application identifiers before transmission. This preliminary tagging enables security gateways to recognize and control P2P traffic without performing time-consuming payload or header analysis, thus improving network security while minimizing processing time overhead
Solution Approach 2:
The patent extracts the essential identifying feature (application identifier) from P2P traffic and separates it from the encrypted payload. By extracting only the necessary identification information and transmitting it alongside encrypted data, the system achieves effective traffic control without requiring decryption or deep packet inspection, reducing processing time while maintaining security
2Measurement precision
If encrypted P2P packets are inspected using signature analysis, then detection accuracy is improved, but the cost and time for signature development and analysis increase
Solution Approach 1:
The patent introduces an intermediary mechanism (flow agent) that bridges the gap between encrypted P2P traffic and security monitoring. The flow agent adds application identifiers as intermediary tags that enable accurate detection without requiring signature analysis of the encrypted payload, eliminating the need for time-consuming signature development while maintaining high detection accuracy
Solution Approach 2:
The patent extracts the application identifier from the P2P traffic flow and separates it from the encrypted data stream. This extraction enables security gateways to identify and control traffic based on the identifier alone, achieving precise detection without the need for resource-intensive signature matching against encrypted content
3Difficulty of detecting and measuring
If P2P traffic is controlled by analyzing packet headers and payloads, then detection capability is improved, but the device complexity and processing overhead increase
Solution Approach 1:
The patent extracts only the essential application identifier information from P2P traffic and transmits it separately from the encrypted payload. This extraction simplifies the detection mechanism at security gateways, which only need to read the identifier tag rather than perform complex analysis of packet headers and payloads, reducing device complexity while maintaining detection capability
Solution Approach 2:
The flow agent performs preliminary identification and tagging of P2P packets with application identifiers before they reach the security gateway. This preliminary action simplifies the gateway's task to mere identifier matching rather than complex packet analysis, reducing processing overhead and system complexity while preserving detection capability
4Productivity
If network equipment processes large amounts of P2P traffic, then traffic throughput is maintained, but processing capabilities are consumed and network congestion occurs
Solution Approach 1:
The patent extracts minimal identification information (application identifier) from P2P traffic and transmits it alongside encrypted data. This allows network equipment to process and control traffic based on the lightweight identifier without requiring resource-intensive decryption or deep packet inspection, maintaining high traffic throughput while minimizing processing capability consumption
Solution Approach 2:
The patent changes the parameter used for traffic identification from complex payload content to a simple application identifier tag. This parameter change enables network equipment to efficiently process large volumes of P2P traffic using lightweight identifier matching, maintaining high throughput while reducing processing energy consumption and preventing network congestion
Data Source
AI summary
The invention relates to a P2P traffic management apparatus and method. A P2P flow agent monitors an executed application program to extract a P2P application program, adds application identifiers to packets generated by the application program according to a set policy, and transmits the packets. In this case, a P2P security gateway monitors the inflowing packets from the P2P flow agent to extract packets having the application identifiers, uses the extracted application identifiers to inquire and acquire a related policy, and controls the packets according to the acquired policy.


