Rogue Traffic Detection via Flow Statistics and Authorized Engine Lists
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network administrators face challenges in identifying the cause of unexpected packet loss and misclassification of packets due to rogue applications or intermediate entities that exceed bandwidth limits or mislabel packets, leading to dropped or out-of-contract traffic, which requires manual and time-consuming data log analysis.
Innovation Solution
A system and method for detecting rogue traffic using flow statistics by verifying packet data against a list of authorized media engines, generating notifications for incorrect verifications, and potentially blocking or rerouting traffic to prevent packet loss, while also providing reports and automated corrections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual data log analysis is used to identify packet loss causes, then measurement precision can be achieved, but loss of time occurs due to time-consuming search through logs
Solution Approach 1:
The system automatically analyzes flow statistics and identifies rogue traffic sources without requiring manual intervention. The call admission control mechanism autonomously processes packet data, compares it against authorized media engine lists, and generates notifications about detected rogue traffic, eliminating the need for manual log analysis while maintaining identification accuracy
Solution Approach 2:
The patent replaces manual mechanical analysis of data logs with automated electronic processing. The system electronically compares flow statistics against authorized media engine lists, automatically detects anomalies, and generates digital notifications, substituting the manual search process with automated computer-based detection mechanisms
2Productivity
If call admission control mechanism is used to manage traffic, then productivity is improved through automated traffic planning, but device complexity increases due to additional monitoring and verification requirements
Solution Approach 1:
The flow collector serves multiple functions: it collects flow statistics, monitors packet data, verifies against authorized media engine lists, detects rogue traffic, and generates notifications. By consolidating these functions into a single multi-functional system, the patent reduces overall device complexity while maintaining automated traffic management productivity
Solution Approach 2:
The system introduces a flow collector as an intermediary component that sits between the traffic monitoring system and the call admission control mechanism. This intermediary aggregates and pre-processes flow statistics, reducing the processing burden on other system components and simplifying the overall architecture while maintaining automated management capabilities
3Adaptability or versatility
If rogue applications mark packets as belonging in the audio queue, then adaptability of traffic classification is improved, but reliability deteriorates as packets are misclassified and dropped
Solution Approach 1:
The system continuously monitors flow statistics and compares them against authorized media engine lists to detect rogue traffic patterns. When rogue applications attempt to misclassify packets, the system detects the anomaly through feedback from the flow collector and generates notifications, enabling real-time detection and response to maintain packet delivery reliability while allowing legitimate traffic classification flexibility
Data Source
AI summary
Disclosed herein are systems, methods, and non-transitory computer-readable storage media for determining rogue traffic using flow statistics and a list of authorized media engines. A system configured according to this disclosure receives data associated with a group of packets in a media queue, such as the source network address where the packets originated, the destination network address for the packets, and an indication of an associated queue for the packets. The system then verifies the data received by comparing the source network address to a list of network addresses of known media engines. The system further verifies that the indication of an associated queue for the packets is correct for the packets. Should the system detect failure in the verification of known media engines or the verification of indication of associated queues, the system generates a notification.


