Traffic Flow Identification Using Terminal-Side Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current traffic flow identification methods face challenges in accurately identifying the type of traffic flow due to limitations in deep packet inspection technology and low precision with deep/dynamic flow inspection methods.

Innovation Solution

A method and apparatus for traffic flow identification that involves collecting packet header statistics within a preset time window and using a traffic flow identification model to determine the type of traffic flow, considering terminal-side information and packet header statistics to improve identification precision.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection (DPI) technology is used to generate traffic flow identification model by analyzing application layer protocol payload content, then identification precision can be improved, but the system becomes vulnerable to encryption attacks and device complexity increases

Engineering Contradiction:
Improveidentification precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the traffic flow identification process into two independent modules: packet header inspection (data link layer/network layer/transport layer) and terminal-side information analysis (device attributes, application layer characteristics). This segmentation avoids the need for complex deep packet inspection of encrypted payload content while maintaining identification precision through multi-dimensional feature analysis.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If deep/dynamic flow inspection (DFI) technology is used to generate traffic flow identification model based on packet header information, then device complexity is reduced, but identification precision deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoididentification precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent merges packet header inspection results with terminal-side information (device attributes, application layer characteristics, user behavior patterns) to create a comprehensive identification model. This combination compensates for the limitations of simple packet header analysis by incorporating multiple dimensions of traffic flow characteristics, thereby improving identification precision without requiring complex deep packet inspection.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If terminal-side information is fully considered in traffic flow identification, then identification rate is improved, but information processing complexity increases

Engineering Contradiction:
Improveidentification rateVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-collecting and organizing terminal-side information (device attributes, application layer characteristics, user behavior patterns) into structured data before the actual identification process. This preprocessing step creates ready-to-use feature sets that can be quickly integrated with packet header information during traffic flow identification, reducing real-time processing complexity while maintaining high identification rates.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3972200B1Service flow identification method
Publication Date: 2025.04.23 HUAWEI TECH CO LTD
  • EP3972200B1 patent drawingFigure 1~2
  • EP3972200B1 patent drawingFigure 3
  • EP3972200B1 patent drawingFigure 4

AI summary

This application provides a traffic flow identification method and apparatus, and a model generation method and apparatus. The traffic flow identification method includes: A first device obtains a to-be-identified traffic flow, collects statistics about packet header information in the to-be-identified traffic flow in a preset time window, to obtain to-be-identified packet header statistics information, and obtains to-be-identified terminal-side information based on the to-be-identified traffic flow. Further, the first device determines a type of the to-be-identified traffic flow based on the to-be-identified terminal-side information and the to-be-identified packet header statistics information by using a traffic flow identification model. Therefore, the first device can fully consider, by using the traffic flow identification model, attribute information of a device associated with the traffic flow, to improve an identification rate of the type of the traffic flow, and ensure an identification effect of the type of the traffic flow.