Wireless Application Detection via Flow Scoring and Signature Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network operators face difficulties in detecting applications such as VoIP and video streaming services due to encryption and proprietary protocols, making it hard to provide customized plans for services like Social Networking Service (SNS) and mail services, as existing packet inspection methods struggle to distinguish between applications using standard protocols like RTP and SIP.
Innovation Solution
A method and apparatus for detecting applications in a wireless communication system by receiving and inspecting packets, detecting flows using predefined signatures, granting scores to each flow, summing scores for each application, and comparing the total score with a preset value to determine application detection, which allows for accurate identification even with encrypted or proprietary protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If traditional packet inspection methods are used to detect applications, then detection cost is reduced, but detection accuracy deteriorates due to encryption and proprietary protocols
Solution Approach 1:
The application detection process is segmented into multiple independent flow detection stages, where each flow is detected separately using predefined signatures and granted independent scores. These segmented flow detections are then integrated through score summation to achieve accurate application identification without requiring complex inspection of encrypted payloads.
Solution Approach 2:
The invention changes the detection parameter from inspecting encrypted payload content to analyzing flow-level characteristics such as source/destination IPs, ports, and protocols. By shifting to these higher-level parameters that remain visible even when data is encrypted, the system maintains detection accuracy while reducing cost.
2Measurement precision
If deep packet inspection is performed to achieve high detection accuracy, then application identification improves, but device complexity increases
Solution Approach 1:
The complex inspection task is segmented into simpler sub-tasks: detecting individual flows using predefined signatures, granting scores to each flow, and summing scores to identify applications. This segmentation reduces device complexity by breaking down the monolithic deep packet inspection into manageable, less complex components.
Solution Approach 2:
The invention introduces an intermediary scoring mechanism that bridges flow detection and application identification. Instead of directly analyzing encrypted payloads, the system uses flow characteristics as an intermediary to infer application types, simplifying the inspection process while maintaining accuracy.
3Measurement precision
If flow-based detection with score summation is used, then detection accuracy improves for encrypted protocols, but processing time increases
Solution Approach 1:
Predefined flow signatures and scoring criteria are prepared in advance before actual packet inspection begins. This preliminary preparation allows the system to quickly match incoming flows against known patterns without performing complex real-time analysis, reducing processing time while maintaining high detection accuracy.
Solution Approach 2:
The system performs partial inspection by analyzing only the necessary flow characteristics (IP addresses, ports, protocols) rather than inspecting the entire packet content. This partial action approach achieves sufficient detection accuracy for encrypted protocols while minimizing processing time by avoiding unnecessary deep inspection of payload data.
Data Source
AI summary
Provided is a method for detecting an application in a wireless communication system. The method includes receiving and inspecting a packet; detecting flows from the packet using a predefined signature; granting a score to each of the detected flows, and summing the granted scores by integrating the detected flows for each application; comparing the summed score of the flows integrated for each application with a preset value; and determining that an application is detected, if the summed score is greater than the preset value.


