Signature Selection for Network Traffic Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in accurately identifying and isolating anomalous content in packets, leading to high false positives and collateral damage, as common signatures can be present in both malicious and benign traffic.
Innovation Solution
A method and apparatus that utilize complexity and frequency scores, along with code analysis, to select and prioritize signatures for identifying potentially malicious content, reducing false positives by determining the best signature to use for identifying similar packets in a traffic stream.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If common signatures are used to identify anomalous content, then detection capability is improved, but false positives increase and collateral damage occurs
Solution Approach 1:
The patent changes the parameters for signature selection by introducing complexity scores and frequency scores. Instead of using common signatures alone, the system evaluates signatures based on their complexity (information content) and frequency of occurrence, selecting signatures that balance detectability with specificity to reduce false positives
Solution Approach 2:
The patent replaces simple mechanical signature matching with a more sophisticated system that uses statistical analysis and scoring mechanisms. The system substitutes direct signature matching with a multi-criteria evaluation process that considers complexity and frequency to determine the best signatures for identification
2Measurement precision
If multiple signatures are used for comprehensive coverage, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-calculating complexity scores and frequency scores for signatures before they are used for detection. The system performs preliminary analysis to rank and prioritize signatures, allowing for efficient selection without requiring complex real-time processing during actual packet inspection
Solution Approach 2:
The patent segments the signature evaluation process into distinct components: complexity scoring and frequency scoring. This segmentation allows the system to handle multiple signatures systematically by evaluating them through separate, manageable criteria rather than processing all signatures simultaneously as a single complex task
Data Source
AI summary
A method and apparatus is described to select a representative signature for use in identifying content in a packet stream. The method may comprise receiving the packet stream and obtaining content from a data payload of the packet. Thereafter, a plurality of signatures is identified from the content and a complexity score or a frequency score is determined based on the content. A signature of the plurality of signatures is then selected as the representative signature based on the complexity score or the frequency score.


