Network Traffic Rule Extraction via Activity Matrix Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current traffic analysis tools fail to identify underlying rules governing network traffic, making it difficult to manage and troubleshoot complex networks, especially in the presence of malicious activities like bot scans, due to their focus on traffic volume rather than structural patterns.
Innovation Solution
A traffic evaluator system that extracts communication rules from packet trace data to monitor, diagnose, and detect intrusions, capable of identifying patterns across multiple hosts, protocols, and applications without prior information, and dynamically generates rules based on real-time data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional traffic analysis tools focus on traffic volume, then they can identify heavy hitters, but they fail to identify the structure implicit in network traffic
Solution Approach 1:
The patent segments network traffic analysis into multiple dimensions: traffic volume metrics, temporal patterns, spatial relationships, and protocol characteristics. By dividing the analysis into these segments, the system can identify both heavy hitters and the underlying structural patterns that govern traffic flow, resolving the contradiction between measurement precision and productivity.
Solution Approach 2:
The patent transitions from analyzing traffic solely in the volume dimension to incorporating temporal, spatial, and protocol dimensions. This multi-dimensional approach reveals hidden structures in network traffic, enabling precise identification of traffic patterns and improving network management efficiency simultaneously.
2Adaptability or versatility
If networks are built from multiple applications, protocols, and servers, then network functionality increases, but administrative tracking becomes overwhelming
Solution Approach 1:
The patent implements a universal traffic evaluation system that handles multiple applications, protocols, and server types through a single unified framework. This multi-functional approach maintains network versatility while simplifying administrative tracking by providing consistent monitoring and analysis across diverse network components.
Solution Approach 2:
The patent introduces an intermediary traffic evaluation layer that sits between the complex network infrastructure and administrators. This intermediary automatically collects, analyzes, and presents traffic information, reducing the complexity of administrative tracking while preserving full network functionality.
3Reliability
If conventional techniques such as scripting cron jobs and correlating server logs are used, then some network monitoring is achieved, but the approach is tedious and does not scale
Solution Approach 1:
The patent implements a self-service traffic evaluation system that automatically collects data from network components, processes traffic patterns, and generates insights without requiring manual scripting or log correlation. This automated approach maintains reliable network monitoring while achieving scalability across large and complex networks.
Solution Approach 2:
The patent replaces the mechanical approach of manual scripting and log correlation with an automated electronic traffic evaluation system. This substitution eliminates tedious manual processes while maintaining monitoring reliability and enabling the system to scale efficiently across expanding networks.
Data Source
AI summary
The claimed subject matter provides a system and/or a method that facilitates managing a network by mining a communication rule. An analysis engine can employ a packet trace within a network in order to provide timing information, wherein the network includes at least one of a host, a protocol, or an application. A traffic evaluator can extract a communication rule for the network based upon an activity matrix generated from the timing information in which the activity matrix includes at least one of a row of a time window for the packet trace and a column for a flow in the packet trace.


