Network Device Application Identification via VPN Tunnel Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

It is challenging to identify and control applications executing on network devices that send or receive network traffic, making application-specific control of network traffic difficult or impossible.

Innovation Solution

Establishing a Virtual Private Network (VPN) tunnel on the network device to monitor and analyze Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) traffic, allowing for the identification of executing applications and taking security actions based on their classification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If application identification is performed by monitoring and analyzing traffic payload data, then application-specific control capability is improved, but device complexity and power consumption increase

Engineering Contradiction:
Improveapplication-specific control capabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a VPN tunnel as an intermediary component that sits between the applications and the network. This tunnel intercepts and monitors TCP and UDP traffic without requiring direct integration with each application, thereby enabling application identification while maintaining a clear separation between the monitoring mechanism and the applications themselves. This resolves the contradiction by providing adaptability through traffic analysis without proportionally increasing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts payload data from monitored TCP and UDP traffic packets to identify applications. By extracting only the necessary payload information rather than analyzing entire traffic streams or requiring full application access, the system achieves application-specific control capability while limiting the complexity increase to only what is necessary for extraction and analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If all TCP and UDP traffic is routed through a VPN tunnel for monitoring, then application identification accuracy is improved, but network overhead and processing time increase

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent monitors all TCP and UDP traffic through the VPN tunnel to ensure comprehensive application identification accuracy. While this may seem like excessive action, the system is designed to process only the necessary payload data from each packet rather than performing full packet inspection or analysis, thereby achieving high identification accuracy while minimizing the time penalty associated with monitoring all traffic.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If payload data is extracted and analyzed locally on the network device, then application identification speed is improved, but power consumption increases

Engineering Contradiction:
Improveapplication identification speedVSAvoidpower consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent implements a system where the network device performs self-service by automatically monitoring, extracting payload data from traffic, and identifying applications through local analysis. This self-service capability enables rapid application identification without requiring constant external assistance, thereby improving identification speed while the system is designed to be energy-efficient in its local processing operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10666616B2Application identification and control in a network device
Publication Date: 2020.05.26 CA TECH INC
  • US10666616B2 patent drawing
  • US10666616B2 patent drawing
  • US10666616B2 patent drawing

AI summary

Application identification and control in a network device. In one embodiment, a method may include establishing, at a network device, a Virtual Private Network (VPN) tunnel through which all Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) traffic sent from or received at the network device is routed. The method may also include monitoring, at the network device, all TCP and UDP traffic sent from or received at the network device through the VPN tunnel. The method may further include extracting, at the network device, payload data from the monitored TCP and UDP traffic. The method may also include analyzing the extracted payload data to identify applications executing on the network device that sent or received the monitored TCP and UDP traffic. The method may further include taking, at the network device, a security action on the network device based on the identified applications.