Rogue Traffic Detection via Flow Statistics and Authorized Engine Lists

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in identifying the cause of unexpected packet loss and misclassification of packets due to rogue applications or intermediate entities that exceed bandwidth limits or mislabel packets, leading to dropped or out-of-contract traffic, which requires manual and time-consuming data log analysis.

Innovation Solution

A system and method for detecting rogue traffic using flow statistics by verifying packet data against a list of authorized media engines, generating notifications for incorrect verifications, and potentially blocking or rerouting traffic to prevent packet loss, while also providing reports and automated corrections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual data log analysis is used to identify packet loss causes, then measurement precision can be achieved, but loss of time occurs due to time-consuming search through logs

Engineering Contradiction:
Improvepacket loss cause identification accuracyVSAvoidtime for manual data log analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically analyzes flow statistics and identifies rogue traffic sources without requiring manual intervention. The call admission control mechanism autonomously processes packet data, compares it against authorized media engine lists, and generates notifications about detected rogue traffic, eliminating the need for manual log analysis while maintaining identification accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical analysis of data logs with automated electronic processing. The system electronically compares flow statistics against authorized media engine lists, automatically detects anomalies, and generates digital notifications, substituting the manual search process with automated computer-based detection mechanisms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If call admission control mechanism is used to manage traffic, then productivity is improved through automated traffic planning, but device complexity increases due to additional monitoring and verification requirements

Engineering Contradiction:
Improveautomated traffic management efficiencyVSAvoidcomplexity of traffic monitoring system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The flow collector serves multiple functions: it collects flow statistics, monitors packet data, verifies against authorized media engine lists, detects rogue traffic, and generates notifications. By consolidating these functions into a single multi-functional system, the patent reduces overall device complexity while maintaining automated traffic management productivity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces a flow collector as an intermediary component that sits between the traffic monitoring system and the call admission control mechanism. This intermediary aggregates and pre-processes flow statistics, reducing the processing burden on other system components and simplifying the overall architecture while maintaining automated management capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If rogue applications mark packets as belonging in the audio queue, then adaptability of traffic classification is improved, but reliability deteriorates as packets are misclassified and dropped

Engineering Contradiction:
Improvetraffic classification flexibilityVSAvoidpacket delivery reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system continuously monitors flow statistics and compares them against authorized media engine lists to detect rogue traffic patterns. When rogue applications attempt to misclassify packets, the system detects the anomaly through feedback from the flow collector and generates notifications, enabling real-time detection and response to maintain packet delivery reliability while allowing legitimate traffic classification flexibility

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8917602B2System and method for detecting rogue traffic using flow statistics with a list of authorized engines
Publication Date: 2014.12.23 EXTREME NETWORKS INC
  • US8917602B2 patent drawing
  • US8917602B2 patent drawing
  • US8917602B2 patent drawing

AI summary

Disclosed herein are systems, methods, and non-transitory computer-readable storage media for determining rogue traffic using flow statistics and a list of authorized media engines. A system configured according to this disclosure receives data associated with a group of packets in a media queue, such as the source network address where the packets originated, the destination network address for the packets, and an indication of an associated queue for the packets. The system then verifies the data received by comparing the source network address to a list of network addresses of known media engines. The system further verifies that the indication of an associated queue for the packets is correct for the packets. Should the system detect failure in the verification of known media engines or the verification of indication of associated queues, the system generates a notification.