Traffic Shape Obfuscation via Discarded Noise Packets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures, such as encryption, are insufficient as they do not prevent third-parties from obtaining metadata about network traffic patterns, which can be used to identify communication types and parties, posing security concerns.

Innovation Solution

The method involves detecting tunnel connections, analyzing the connection environment, and sending noise packets that are discarded by the network stack, thereby obfuscating traffic patterns without requiring additional hardware or software at the target node, using existing network protocols to obscure traffic metadata.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If encrypted transmissions are used, then data confidentiality is improved, but traffic pattern metadata remains exposed to third-parties

Engineering Contradiction:
Improvedata confidentialityVSAvoidtraffic pattern exposure
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary noise generation mechanism that mediates between the encrypted data transmission and the external network observers. The system generates synthetic noise packets that mimic legitimate traffic patterns, acting as a veil between the actual encrypted communications and third-party observers, thereby protecting traffic pattern metadata while maintaining data confidentiality

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes traffic parameters by injecting noise packets with varying sizes, intervals, and patterns that differ from actual communication patterns. This parameter manipulation creates artificial traffic variability that obscures the true communication patterns while the encrypted payload remains protected

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If noise packets are injected to obfuscate traffic patterns, then privacy protection is improved, but network bandwidth is consumed

Engineering Contradiction:
Improvetraffic pattern privacyVSAvoidnetwork bandwidth
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The system applies partial action by injecting only the minimum necessary noise packets required to achieve effective obfuscation. Rather than saturating the network with excessive noise, the system carefully calibrates the noise injection rate and packet characteristics to provide sufficient privacy protection while minimizing bandwidth consumption

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts noise packet parameters including size, frequency, and interval based on network conditions and observed traffic patterns. This adaptive parameter adjustment ensures effective privacy protection while optimizing bandwidth utilization by reducing noise when actual traffic is high and increasing it when traffic is low

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If packet handling techniques are used to discard noise packets, then deployment complexity is reduced, but network protocol compatibility must be maintained

Engineering Contradiction:
Improvedeployment complexityVSAvoidprotocol compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system leverages the network stack's inherent packet handling capabilities at the target node to automatically discard noise packets. By designing noise packets with characteristics that trigger standard network protocol rejection mechanisms (such as invalid TTL values or malformed headers), the system enables the network infrastructure itself to perform the filtering function without requiring additional software or hardware at the target node

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9973516B2Traffic shape obfuscation when using an encrypted network connection
Publication Date: 2018.05.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9973516B2 patent drawing
  • US9973516B2 patent drawing
  • US9973516B2 patent drawing

AI summary

According to one exemplary embodiment, a method for obfuscating a traffic pattern associated with a plurality of network traffic within a tunnel connection is provided. The method may include detecting the tunnel connection. The method may also include analyzing a connection environment associated with the detected tunnel connection. The method may then include determining a packet handling technique based on the analyzed connection environment, whereby the packet handling technique provides a way for creating a noise packet that will be discarded by a network stack at a target node or before the target node. The method may include determining a noise strategy based on the determined packet handling technique. The method may also include sending a plurality of noise packets into the tunnel connection based on the determined noise strategy to obfuscate the traffic pattern.