Network Proxy Detection via Symmetric Traffic Relationships

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting network proxies are ineffective in identifying proxies that use evasion or obfuscation techniques, such as running on arbitrary ports or using encryption, and are also costly and difficult to deploy.

Innovation Solution

The solution involves analyzing network transmission data to detect symmetric relationships between data transmissions, specifically looking for reflexivity, size symmetry, and port re-use, to identify potential proxy servers within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If active scanning is used to detect proxies, then detection capability is improved, but network noise and false alarms increase significantly

Engineering Contradiction:
Improveproxy detection capabilityVSAvoidnetwork noise and false alarms
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent replaces active mechanical scanning with passive observation of network traffic patterns. Instead of actively probing hosts to detect proxies, the system passively monitors and analyzes existing network traffic for symmetric relationship patterns, eliminating the noise and false alarms generated by active scanning while maintaining detection capability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces symmetric relationship patterns as an intermediary indicator for proxy detection. Rather than directly detecting proxies through active scanning, the system uses passive observation of symmetric traffic relationships between hosts as a mediator to infer the presence of proxies, reducing direct interference with network operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-generated harmful factors

If passive scanning is used to avoid noise, then network disturbance is reduced, but deployment complexity increases due to requirement for widely spread sensors

Engineering Contradiction:
Improvenetwork disturbanceVSAvoidsensor deployment complexity
Core Design Contradiction:
Object-generated harmful factorsVSDevice complexity

Solution Approach 1:

The patent makes the proxy detection system universal by enabling any host in the network to serve as a detection point. Each host can independently analyze traffic patterns and detect proxies, eliminating the need for specially deployed widely spread sensors while maintaining passive, low-disturbance operation across the entire network

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If proxy ports are shielded or moved to arbitrary ports, then proxy security is improved, but detectability by traditional methods decreases

Engineering Contradiction:
Improveproxy securityVSAvoidproxy detectability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent exploits the asymmetric nature of proxy traffic patterns. While proxies may use arbitrary ports for communication, the traffic relationships they create exhibit asymmetric patterns - the proxy host communicates with both the internal host and external host in specific patterns that differ from normal direct communication, allowing detection despite port obfuscation

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The patent shifts detection from the traditional port-based dimension to the relationship-based dimension. Instead of detecting proxies through their port numbers or protocol signatures, the system analyzes the dimensional relationships between multiple hosts and traffic flows, detecting proxies through their positional and relational patterns in the network topology rather than their surface-level communication characteristics

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS7475420B1Detecting network proxies through observation of symmetric relationships
Publication Date: 2009.01.06 CA TECH INC
  • US7475420B1 patent drawing
  • US7475420B1 patent drawing
  • US7475420B1 patent drawing

AI summary

Detecting network proxies through the observation of symmetric relationships is disclosed. Network transmission data is analyzed to detect symmetric relationships between network data transmissions. A symmetric relationship is detected with respect to a first network data transmission sent by a first node to a second node if the second node is observed to send or have sent to a third node a second network data transmission that satisfies a prescribed first criterion that it is anticipated the second network data transmission would satisfy if it were used to forward to the third node at least part of the data comprising the first network data transmission. For each symmetric relationship found, further analysis is performed to determine if the second node is configured to serve as a proxy.