Network Traffic Capture via Proxy Session Key Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Capturing and examining network traffic at high bitrates is challenging due to the inability to negotiate session keys with traffic sources and significant storage and computing demands for decryption.
Innovation Solution
A system comprising client devices, capture devices, and a proxy server that receives and stores specific encrypted or unencrypted traffic flows by using session keys communicated through a secure channel, allowing selective capture and discard of traffic flows based on flow information from the proxy server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all traffic flows are captured and stored for later decryption and analysis, then complete traffic analysis capability is achieved, but storage requirements and computing demands increase significantly
Solution Approach 1:
The proxy server performs preliminary action by intercepting traffic flows before they reach the capture device, examining their characteristics, and pre-selecting only those flows that match capture criteria. This preliminary filtering action prevents unnecessary storage of irrelevant traffic data, directly reducing storage requirements while maintaining the ability to analyze relevant traffic later.
Solution Approach 2:
The system extracts only the necessary components from the traffic flow processing - specifically, the proxy server extracts and examines traffic flow characteristics to identify which flows should be captured. This extraction approach separates the filtering function from the capture function, allowing the capture device to receive only pre-selected relevant traffic, thereby reducing storage requirements without compromising analysis capability.
2Reliability
If all traffic flows are captured for decryption and analysis, then complete examination capability is achieved, but computing power requirements increase significantly
Solution Approach 1:
The proxy server performs preliminary examination of traffic flows to determine which ones require decryption and analysis. By pre-identifying relevant flows before they reach the capture device, the system avoids the computational overhead of processing and potentially decrypting all traffic flows, thereby reducing computing power requirements while maintaining complete examination capability for relevant traffic.
Solution Approach 2:
The proxy server extracts and evaluates traffic flow characteristics to identify which flows warrant capture and decryption. This extraction of relevant information from all traffic allows the system to focus computational resources only on flows that meet capture criteria, significantly reducing the computing power needed for decryption and analysis while preserving complete examination capability for selected traffic.
3Measurement precision
If a proxy server intercepts and examines all traffic flows to select which to capture, then selective capture precision is improved, but device complexity increases
Solution Approach 1:
The system segments the traffic capture function into two distinct components: the proxy server that performs flow examination and selection, and the capture device that executes the actual capture based on proxy instructions. This segmentation allows the proxy server to focus on precise flow identification while the capture device handles only the capture operation, improving selection precision without requiring either component to be overly complex.
Solution Approach 2:
The proxy server acts as an intermediary between the traffic source and the capture device. It receives traffic flows, examines their characteristics, and based on this examination, selectively forwards instructions to capture specific flows. This intermediary role enables precise flow selection through examination while keeping the capture device itself relatively simple, as it only needs to execute capture instructions rather than perform complex analysis.
Data Source
AI summary
In certain embodiments, a method includes receiving, by a capture device, traffic flows transmitted by a plurality of client devices, each of the traffic flows being associated with one of the plurality of client devices and comprising encrypted data. The method further includes receiving, by the capture device, flow information communicated from a proxy server communicatively coupled to the capture device, the flow information comprising an identification of a particular traffic flow and a session key associated with the particular traffic flow. The method further includes storing, by the capture device, encrypted data of the particular traffic flow identified by the flow information supplied by the proxy server; storing, by the capture device, the session key associated with the particular traffic flow; and discarding, by the capture device, any of the plurality of received traffic flows not identified in the flow information received from the proxy server.


