Traffic Flow Classifiers Using Statistical Feature Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional traffic flow classification methods, such as port number-based classification and deep packet inspection, are becoming less accurate and practical due to the growth of non-standard applications and the inability to classify encrypted traffic, raising privacy concerns and complexity issues.

Innovation Solution

The development of machine learning-based traffic flow classifiers that classify traffic flows in real-time using features like data packet size and inter-arrival time, eliminating the need for port number or payload information, and are protocol and payload independent, promoting low computational complexity and cost.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If port number-based classification or deep packet inspection is used, then traffic flow classification can be achieved, but accuracy deteriorates with non-standard applications and encrypted traffic

Engineering Contradiction:
Improveclassification accuracyVSAvoidcompatibility with non-standard applications
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent changes the classification parameters from traditional port numbers and payload content to statistical features of traffic flows including packet size distribution, inter-arrival time distribution, and flow duration. These parameter changes enable accurate classification of encrypted and non-standard applications without relying on application-specific markers.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical classification methods (port number matching, deep packet inspection) with a machine learning-based statistical analysis system. This substitution uses algorithms to analyze traffic flow patterns and classify flows automatically, improving both accuracy and adaptability to new applications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If deep packet inspection is used to classify encrypted traffic, then classification capability is improved, but computational complexity and cost increase

Engineering Contradiction:
Improveclassification capabilityVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary statistical features (packet size, inter-arrival time, flow duration) from traffic flows for classification purposes, rather than performing full deep packet inspection. This extraction approach maintains classification capability while significantly reducing computational complexity by focusing only on essential characteristics.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If data packet marking is used for QoS management, then QoS requirements can be identified, but markings may be modified or bleached during transmission

Engineering Contradiction:
ImproveQoS managementVSAvoidmarking integrity
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent performs preliminary classification of traffic flows into QoS categories before transmission based on statistical analysis. By classifying flows upfront and applying QoS policies at the flow level rather than individual packet markings, the system ensures QoS requirements are maintained throughout transmission without relying on fragile packet markings that can be modified.

Inventive Principle:
Principle #10Preliminary action

4Ease of manufacture

If conventional classification methods are used, then implementation is simpler, but they cannot handle encrypted traffic and raise privacy concerns

Engineering Contradiction:
Improveimplementation simplicityVSAvoidencrypted traffic handling
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent enables the traffic classification system to serve itself by automatically analyzing statistical patterns of traffic flows without requiring external information about application protocols or payload content. This self-service approach allows the system to handle encrypted traffic effectively while maintaining implementation simplicity through automated statistical analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11979328B1Traffic flow classifiers and associated methods
Publication Date: 2024.05.07 CABLE TELEVISION LAB INC
  • US11979328B1 patent drawing
  • US11979328B1 patent drawing
  • US11979328B1 patent drawing

AI summary

A method for traffic flow classification in a communication network includes (1) identifying a traffic flow in communication network traffic, (2) extracting features of the traffic flow, and (3) using a machine learning model, classifying the traffic flow at least partially based on the features of the traffic flow. The features of the traffic flow include, for example, a distribution of packet size values of a sliding window sample of the traffic flow, a distribution of inter-arrival time values of a sliding window sample of the traffic flow, standard deviation of data packet size, average of data packet size, standard deviation of data packet inter-arrival time, and average of data packet inter-arrival time.