Network Traffic Analysis via Signal Encoding of Intercepted Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication network monitoring technologies face challenges in detecting and analyzing traffic flow information, especially when message contents are encrypted, as they cannot obscure basic protocol mechanisms and dynamics such as packet source, destination, and interpacket gaps.
Innovation Solution
The method involves intercepting data chunks in communication networks using taps to obtain characteristic information like arrival times and source node identifiers, encoding this information into signals for further processing, allowing for the monitoring of traffic flow even when identifying information is encrypted.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If messages are encrypted to guard against unwanted traffic analysis, then message content security is improved, but traffic flow monitoring capability deteriorates
Solution Approach 1:
The patent segments traffic information into two distinct parts: encrypted message content and unencrypted metadata (arrival times, durations, source/destination identifiers). This segmentation allows the content to remain secure while the metadata remains accessible for monitoring purposes, resolving the contradiction between encryption security and traffic flow analysis capability.
Solution Approach 2:
The patent extracts specific characteristics (arrival times, durations, identifiers) from the encrypted message stream and separates them for dedicated monitoring. By taking out these metadata elements from the encrypted content, the system enables traffic flow analysis without compromising the security of the actual message content.
2Measurement precision
If detailed characteristic information is collected for accurate traffic analysis, then measurement precision is improved, but device complexity increases
Solution Approach 1:
The patent applies local quality by collecting detailed characteristic information (arrival times, durations, identifiers) only at specific monitoring points (taps) in the network, rather than requiring comprehensive analysis throughout the entire system. This localized approach to data collection achieves high measurement precision while minimizing overall system complexity.
Data Source
AI summary
A system acquires information about communication among wired or wireless nodes [110, 210] in a network [100, 200] by intercepting chunks of data in the network by a wired or wireless tap [120, 220] located among the wired or wireless nodes [110, 210] in the network. Characteristic information [400] about the intercepted chunks of data may be obtained. The characteristic information may include times of arrival [410] of the chunks of data at the wired or wireless tap [120, 220] and identifiers of wired or wireless source nodes [420] that sent the chunks of data. At least one signal may be constructed to represent the characteristic information over time.


