Application Protocol Recognition via Traffic Pattern Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication networks face difficulties in recognizing and identifying level 7 protocols within the OSI/ISO model, especially when they are encrypted or unknown, as current methods like deep packet inspection are ineffective when protocols are complex or unfamiliar to the network.
Innovation Solution
A communication system detects specific application protocols by analyzing message traffic patterns based on packet size, average packet rate, burstiness, and other features, using administrative rules to manage identified protocols, and employs a token-based system to control message traffic patterns, allowing for flexible mapping between packets and tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is used to detect application protocols, then protocol detection capability is improved for easy-to-decode and unencrypted protocols, but it becomes ineffective when protocols are encrypted, complex, or unknown to the network
Solution Approach 1:
The patent introduces an intermediary approach by using packet size analysis and traffic pattern recognition as a mediator between the network and encrypted/unknown protocols. Instead of directly inspecting packet content (which fails for encrypted protocols), the system uses packet size metadata and temporal patterns as intermediate indicators to infer protocol identity, thereby maintaining detection capability without requiring decryption or prior knowledge of the protocol
Solution Approach 2:
The patent changes the detection parameters from content-based inspection to metadata-based analysis. By focusing on packet size, inter-arrival time, and traffic patterns rather than packet payload content, the system adapts to work effectively with encrypted and unknown protocols while maintaining protocol detection capability
2Adaptability or versatility
If level 7 protocols are carried as payload information for less sophisticated protocols, then multi-level protocol functionality is achieved, but recognition of the carried protocols becomes difficult
Solution Approach 1:
The patent applies preliminary action by establishing a database of known packet size ranges and traffic patterns for different protocols before actual traffic analysis. This pre-characterization allows the system to quickly match observed traffic against known patterns without needing to deeply inspect or decode each packet, making it easier to recognize protocols carried at level 7 even when embedded in multi-level protocol structures
Data Source
AI summary
A communication system detects particular application protocols in response to their message traffic patterns, which might be responsive to packet size, average packet rate, burstiness of packet transmissions, or other message pattern features. Selected message pattern features include average packet rate, maximum packet burst, maximum future accumulation, minimum packet size, and maximum packet size. The system maintains a counter of packet tokens, each arriving at a constant rate, and maintains a queue of real packets. Each real packet is released from the queue when there is a corresponding packet token also available for release. Packet tokens overfilling the counter, and real packets overfilling the queue, are discarded. Users might add or alter application protocol descriptions to account for profiles thereof.


