Network Device Application Identification via VPN Tunnel Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
It is challenging to identify and control applications executing on network devices that send or receive network traffic, making application-specific control of network traffic difficult or impossible.
Innovation Solution
Establishing a Virtual Private Network (VPN) tunnel on the network device to monitor and analyze Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) traffic, allowing for the identification of executing applications and taking security actions based on their classification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If application identification is performed by monitoring and analyzing traffic payload data, then application-specific control capability is improved, but device complexity and power consumption increase
Solution Approach 1:
The patent introduces a VPN tunnel as an intermediary component that sits between the applications and the network. This tunnel intercepts and monitors TCP and UDP traffic without requiring direct integration with each application, thereby enabling application identification while maintaining a clear separation between the monitoring mechanism and the applications themselves. This resolves the contradiction by providing adaptability through traffic analysis without proportionally increasing device complexity.
Solution Approach 2:
The patent extracts payload data from monitored TCP and UDP traffic packets to identify applications. By extracting only the necessary payload information rather than analyzing entire traffic streams or requiring full application access, the system achieves application-specific control capability while limiting the complexity increase to only what is necessary for extraction and analysis.
2Measurement precision
If all TCP and UDP traffic is routed through a VPN tunnel for monitoring, then application identification accuracy is improved, but network overhead and processing time increase
Solution Approach 1:
The patent monitors all TCP and UDP traffic through the VPN tunnel to ensure comprehensive application identification accuracy. While this may seem like excessive action, the system is designed to process only the necessary payload data from each packet rather than performing full packet inspection or analysis, thereby achieving high identification accuracy while minimizing the time penalty associated with monitoring all traffic.
3Productivity
If payload data is extracted and analyzed locally on the network device, then application identification speed is improved, but power consumption increases
Solution Approach 1:
The patent implements a system where the network device performs self-service by automatically monitoring, extracting payload data from traffic, and identifying applications through local analysis. This self-service capability enables rapid application identification without requiring constant external assistance, thereby improving identification speed while the system is designed to be energy-efficient in its local processing operations.
Data Source
AI summary
Application identification and control in a network device. In one embodiment, a method may include establishing, at a network device, a Virtual Private Network (VPN) tunnel through which all Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) traffic sent from or received at the network device is routed. The method may also include monitoring, at the network device, all TCP and UDP traffic sent from or received at the network device through the VPN tunnel. The method may further include extracting, at the network device, payload data from the monitored TCP and UDP traffic. The method may also include analyzing the extracted payload data to identify applications executing on the network device that sent or received the monitored TCP and UDP traffic. The method may further include taking, at the network device, a security action on the network device based on the identified applications.


