Stream Fingerprinting for Network Traffic Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for identifying network traffic, such as using well-known ports and application decoders, are inefficient and prone to misidentification, especially for applications that do not consistently use standard ports or engage in malicious activities, and require excessive processing resources due to the need for multiple decoders for each possible application.
Innovation Solution
The use of stream fingerprints, which are unique characteristics of data packet streams, such as endpoint initiation and content, stored in a database for matching, allowing for identification of applications without relying on specific ports and reducing the need for multiple decoders, with a stream fingerprint device processing data in parallel with network communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If multiple application decoders are used to identify different applications, then identification accuracy improves, but device complexity and processing resources increase
Solution Approach 1:
The patent creates a universal stream fingerprinting system that can identify multiple applications through a single device. Instead of having separate decoders for each application, one stream fingerprinting device analyzes packet streams and matches them against a database of application fingerprints, enabling multi-application identification with a single multi-functional system
Solution Approach 2:
The patent uses fingerprint templates that represent characteristic patterns of application packet streams. These fingerprint copies are stored in a database and matched against actual packet streams, allowing identification without needing the actual application decoder for each protocol
2Measurement precision
If stream fingerprinting is implemented, then identification accuracy for non-standard port applications improves, but processing time for analyzing packet streams increases
Solution Approach 1:
The patent pre-computes and stores application fingerprints in a database before actual traffic analysis. These fingerprints contain pre-analyzed characteristic patterns of application packet streams, so during runtime, the system only needs to match incoming streams against these pre-prepared templates rather than analyzing everything from scratch
Solution Approach 2:
The system analyzes only the most characteristic portions of packet streams that are sufficient for identification. Rather than examining every packet in complete detail, the stream fingerprinting device extracts and matches key identifying features, performing partial analysis that is adequate for the identification task
3Ease of operation
If port-based identification is used, then ease of operation improves, but reliability of identification deteriorates for applications using non-standard ports
Solution Approach 1:
The patent replaces the mechanical/port-based identification system with a content-based fingerprinting system. Instead of relying on fixed port numbers as identifiers, the system analyzes the actual content and patterns of packet streams, substituting superficial port-based matching with deeper content-based analysis that is more reliable for identifying actual applications
Data Source
AI summary
Techniques for identifying stream fingerprints are provided. A stream of data packets may be received. In one aspect, a stream fingerprint may be determined based on the stream of data packets. An application associated with the stream may be determined based on the stream fingerprint. In another aspect, a stream may be partially matched while a fully matched stream fingerprint has not been determined. As additional packets are received, the stream may become fully matched.


