Traffic Flow Classifiers Using Statistical Feature Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional traffic flow classification methods, such as port number-based classification and deep packet inspection, are becoming less accurate and practical due to the growth of non-standard applications and the inability to classify encrypted traffic, raising privacy concerns and complexity issues.
Innovation Solution
The development of machine learning-based traffic flow classifiers that classify traffic flows in real-time using features like data packet size and inter-arrival time, eliminating the need for port number or payload information, and are protocol and payload independent, promoting low computational complexity and cost.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If port number-based classification or deep packet inspection is used, then traffic flow classification can be achieved, but accuracy deteriorates with non-standard applications and encrypted traffic
Solution Approach 1:
The patent changes the classification parameters from traditional port numbers and payload content to statistical features of traffic flows including packet size distribution, inter-arrival time distribution, and flow duration. These parameter changes enable accurate classification of encrypted and non-standard applications without relying on application-specific markers.
Solution Approach 2:
The patent replaces traditional mechanical classification methods (port number matching, deep packet inspection) with a machine learning-based statistical analysis system. This substitution uses algorithms to analyze traffic flow patterns and classify flows automatically, improving both accuracy and adaptability to new applications.
2Measurement precision
If deep packet inspection is used to classify encrypted traffic, then classification capability is improved, but computational complexity and cost increase
Solution Approach 1:
The patent extracts only the necessary statistical features (packet size, inter-arrival time, flow duration) from traffic flows for classification purposes, rather than performing full deep packet inspection. This extraction approach maintains classification capability while significantly reducing computational complexity by focusing only on essential characteristics.
3Reliability
If data packet marking is used for QoS management, then QoS requirements can be identified, but markings may be modified or bleached during transmission
Solution Approach 1:
The patent performs preliminary classification of traffic flows into QoS categories before transmission based on statistical analysis. By classifying flows upfront and applying QoS policies at the flow level rather than individual packet markings, the system ensures QoS requirements are maintained throughout transmission without relying on fragile packet markings that can be modified.
4Ease of manufacture
If conventional classification methods are used, then implementation is simpler, but they cannot handle encrypted traffic and raise privacy concerns
Solution Approach 1:
The patent enables the traffic classification system to serve itself by automatically analyzing statistical patterns of traffic flows without requiring external information about application protocols or payload content. This self-service approach allows the system to handle encrypted traffic effectively while maintaining implementation simplicity through automated statistical analysis.
Data Source
AI summary
A method for traffic flow classification in a communication network includes (1) identifying a traffic flow in communication network traffic, (2) extracting features of the traffic flow, and (3) using a machine learning model, classifying the traffic flow at least partially based on the features of the traffic flow. The features of the traffic flow include, for example, a distribution of packet size values of a sliding window sample of the traffic flow, a distribution of inter-arrival time values of a sliding window sample of the traffic flow, standard deviation of data packet size, average of data packet size, standard deviation of data packet inter-arrival time, and average of data packet inter-arrival time.


