Session-Based Traffic Analysis Using TCP Sequence Numbers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current high-cost and high-capacity traffic analysis systems for broadband networks are inefficient and costly to maintain, and traffic sample analysis methods often result in inaccurate measurements due to analyzing only a portion of traffic.
Innovation Solution
A session-based traffic analysis system that monitors one-way traffic using TCP protocol, extracts sequence and acknowledgement numbers, and calculates two-way traffic by updating initial and final values of these numbers, allowing for accurate analysis of total traffic using only a portion (about 1/3) of the network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If multiple high-cost and high-capacity traffic analysis systems are deployed to analyze entire upstream and downstream traffic, then traffic analysis accuracy is improved, but construction costs and maintenance costs increase significantly
Solution Approach 1:
The patent extracts only the necessary sequence numbers and acknowledgement numbers from TCP packets to calculate traffic amounts, rather than analyzing entire traffic flows. This extraction approach enables accurate traffic measurement using minimal data, eliminating the need for multiple high-cost analysis systems while maintaining measurement precision.
Solution Approach 2:
The patent creates a simplified representation of traffic data by copying only the essential TCP control information (sequence numbers and acknowledgement numbers) rather than copying complete traffic streams. This allows reconstruction of traffic statistics from minimal data samples, reducing system complexity while preserving analysis accuracy.
2Device complexity
If traffic sample analysis method is used to reduce costs, then construction and maintenance costs are reduced, but measurement accuracy deteriorates due to analyzing only partial traffic
Solution Approach 1:
The patent changes the measurement parameter from analyzing complete traffic streams to measuring TCP connection-oriented parameters (sequence numbers and acknowledgement numbers). This parameter transformation enables accurate traffic amount calculation from minimal packet data, achieving both cost reduction and maintained accuracy.
Solution Approach 2:
The patent replaces the mechanical approach of capturing and analyzing entire traffic flows with a computational approach using TCP protocol characteristics. By substituting comprehensive packet capture with intelligent extraction of control parameters, the system achieves accurate measurement from minimal data without requiring complex hardware infrastructure.
3Productivity
If only one-way traffic is analyzed to reduce data processing load, then processing efficiency is improved, but two-way traffic analysis accuracy is lost
Solution Approach 1:
The patent uses the feedback mechanism inherent in TCP protocols (acknowledgement numbers) to reconstruct two-way traffic information from one-way packet analysis. The acknowledgement numbers provide feedback about received data, enabling calculation of both transmission and reception amounts without requiring bidirectional packet capture.
Solution Approach 2:
The patent segments the traffic analysis task into extracting sequence numbers for transmission amount calculation and acknowledgement numbers for reception amount calculation. This segmentation allows independent processing of one-way packets to derive both directions of traffic information, improving processing efficiency while maintaining accuracy.
Data Source
AI summary
The present invention relates to a session-based traffic analysis system that may accurately analyze an amount of traffic for each transmission control protocol (TCP) connection using only one-way packets. The system may accurately analyze an amount of two-way traffic using only one-way connection information.


