Session-Level Packet Inspection for Application Identity Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network devices face challenges in accurately determining the number of simultaneous network-enabled applications or application instances operating on a host, leading to difficulties in preventing excessive connections that can raise security concerns and interfere with quality of service management.
Innovation Solution
Implementing packet inspection methods at the session level to identify and differentiate data streams associated with applications, allowing for policy enforcement and resource management by tracking session identities and controlling network actions based on predefined thresholds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single application opens multiple data streams, then the application functionality is enhanced, but the ability to accurately determine the number of simultaneous applications operating on a host deteriorates
Solution Approach 1:
The patent segments the problem of counting applications by introducing session-level identification. Instead of counting individual data streams or connections, the system segments the network traffic into distinct sessions, where each session is assigned a unique session identity. This allows multiple data streams from the same application to be grouped under a single session, enabling accurate application-level counting while preserving the application's ability to open multiple streams for enhanced functionality.
2Ease of operation
If packet inspection is performed at individual connection level, then connection tracking is simplified, but the ability to enforce application-level policies deteriorates
Solution Approach 1:
The patent introduces a new dimension of abstraction by moving from connection-level inspection to session-level inspection. The session layer acts as an intermediate dimension that aggregates multiple connections into a single policy-enforceable entity. This dimensional shift allows the system to maintain simple connection tracking while enabling sophisticated application-level policy enforcement, as policies can now be applied to the session level which encompasses all connections from a single application.
3Productivity
If multiple connections are allowed per host, then network resource utilization is improved, but security risks and quality of service management difficulties increase
Solution Approach 1:
The patent introduces session identity as an intermediary mechanism between the host and the network device. This session identity acts as a mediator that allows the network device to track and control applications without directly inspecting each individual connection. The session-level abstraction serves as an intermediary layer that enables secure and manageable multi-connection environments by providing a unified control point for policy enforcement, thereby maintaining security and QoS management reliability while allowing improved network resource utilization through multiple connections.
Data Source
AI summary
Network devices, computer-readable media, and other embodiments associated with packet inspection are described. Packet inspection may be performed on data packets associated with a session, where a session can include multiple data channels and associated control channels that have been bound together. A session may be associated with an identity. Various policies may be associated with that identity. As packet inspection occurs, it can be determined whether policies are being violated on a per identity basis. If a policy is being violated, then an action may be selectively performed. The action performed may affect a single channel in the session or may affect the whole session. Different identities may have different policies. Example actions include dropping a session, throttling a session, monitoring a session, controlling the number of channels associated with a session, dropping a channel, throttling a channel, monitoring a channel, and other actions.


