Wireless Application Detection via Flow Scoring and Signature Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network operators face difficulties in detecting applications such as VoIP and video streaming services due to encryption and proprietary protocols, making it hard to provide customized plans for services like Social Networking Service (SNS) and mail services, as existing packet inspection methods struggle to distinguish between applications using standard protocols like RTP and SIP.

Innovation Solution

A method and apparatus for detecting applications in a wireless communication system by receiving and inspecting packets, detecting flows using predefined signatures, granting scores to each flow, summing scores for each application, and comparing the total score with a preset value to determine application detection, which allows for accurate identification even with encrypted or proprietary protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional packet inspection methods are used to detect applications, then detection cost is reduced, but detection accuracy deteriorates due to encryption and proprietary protocols

Engineering Contradiction:
Improvedetection costVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The application detection process is segmented into multiple independent flow detection stages, where each flow is detected separately using predefined signatures and granted independent scores. These segmented flow detections are then integrated through score summation to achieve accurate application identification without requiring complex inspection of encrypted payloads.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention changes the detection parameter from inspecting encrypted payload content to analyzing flow-level characteristics such as source/destination IPs, ports, and protocols. By shifting to these higher-level parameters that remain visible even when data is encrypted, the system maintains detection accuracy while reducing cost.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If deep packet inspection is performed to achieve high detection accuracy, then application identification improves, but device complexity increases

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidinspection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The complex inspection task is segmented into simpler sub-tasks: detecting individual flows using predefined signatures, granting scores to each flow, and summing scores to identify applications. This segmentation reduces device complexity by breaking down the monolithic deep packet inspection into manageable, less complex components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces an intermediary scoring mechanism that bridges flow detection and application identification. Instead of directly analyzing encrypted payloads, the system uses flow characteristics as an intermediary to infer application types, simplifying the inspection process while maintaining accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If flow-based detection with score summation is used, then detection accuracy improves for encrypted protocols, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Predefined flow signatures and scoring criteria are prepared in advance before actual packet inspection begins. This preliminary preparation allows the system to quickly match incoming flows against known patterns without performing complex real-time analysis, reducing processing time while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs partial inspection by analyzing only the necessary flow characteristics (IP addresses, ports, protocols) rather than inspecting the entire packet content. This partial action approach achieves sufficient detection accuracy for encrypted protocols while minimizing processing time by avoiding unnecessary deep inspection of payload data.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9749200B2Method and apparatus for detecting application
Publication Date: 2017.08.29 SAMSUNG ELECTRONICS CO LTD
  • US9749200B2 patent drawing
  • US9749200B2 patent drawing
  • US9749200B2 patent drawing

AI summary

Provided is a method for detecting an application in a wireless communication system. The method includes receiving and inspecting a packet; detecting flows from the packet using a predefined signature; granting a score to each of the detected flows, and summing the granted scores by integrating the detected flows for each application; comparing the summed score of the flows integrated for each application with a preset value; and determining that an application is detected, if the summed score is greater than the preset value.