IP Library Granted Patent US 7,778,194
Granted Patent B1
US 7,778,194 · App. 10/917,952 · Granted Aug 17, 2010

Examination of connection handshake to enhance classification of encrypted network traffic

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,778,194
App. No.
10/917,952
Granted
Aug 17, 2010
Kind
B1
Abstract

Methods, apparatuses and systems directed to the classification of encrypted network traffic. In one implementation, the present invention facilitates the classification of network traffic that has been encrypted according to a dynamically-created encryption mechanism involving a handshake between two end-systems, such as the SSL and TLS protocols. In one implementation, the present invention observes and analyzes attributes of the handshake between two nodes to enhance the classification of network traffic. In one embodiment, the enhanced classification mechanisms described herein operate seamlessly with other Layer 7 traffic classification mechanisms that operate on attributes of the packets themselves. Implementations of the present invention can be incorporated into a variety of network devices, such as traffic monitoring devices, packet capture devices, firewalls, and bandwidth management devices.

Claims (46)

1. A method facilitating classification of data flows traversing a computer network, comprising

detecting, at a network device, a handshake in a data flow between a first node and a second node, wherein the handshake comprises an exchange of messages including information useful to establish an encrypted connection between the first node and the second node, wherein the information includes a digital certificate;

classifying, using the network device, the data flow based on an encrypted connection protocol identified in the exchange of messages;

examining, using the network device, the messages corresponding to the handshake relative to at least one handshake attribute and examining the digital certificate to identify one or more digital certificate attributes, wherein the one or more digital certificate attributes are contained in the digital certificate; and

further classifying, using the network device, the data flow into a network-application-specific traffic classification based at least in part on at least one digital certificate attribute of the one or more digital certificate attributes.

2. The method of claim 1 wherein the digital certificate comprises a common name; and wherein the digital certificate attribute comprises the common name of the digital certificate.

3. The method of claim 1 wherein the handshake is a SSL protocol handshake.

4. The method of claim 1 wherein the handshake is a TLS protocol handshake.

5. A method facilitating classification of data flows traversing a computer network, comprising

detecting, at a network device, a handshake in a data flow between a first node and a second node, wherein the handshake comprises an exchange of messages that establishes an encrypted connection between the first node and the second node, wherein one or more of the messages includes a digital certificate;

classifying, using the network device, the data flow based on an encrypted connection protocol identified during the handshake;

examining, using the network device, the digital certificate to identify one or more handshake attributes, wherein at least one handshake attribute of the one or more handshake attributes is an attribute of the digital certificate, wherein the one or more digital certificate attributes are contained in the digital certificate; and

further classifying, using the network device, the data flow into a network-application-specific traffic classification based at least in part on at least one handshake attribute in the monitoring step.

6. The method of claim 5 wherein the classifying step comprises

matching the data flow to a traffic class from a plurality of traffic classes, wherein at least one traffic class in the plurality of traffic classes is defined at least in part by a handshake attribute.

7. An apparatus comprising

a packet processor operative to

detect data flows in network traffic traversing a communications path, the data flows each comprising at least one packet;

parse at least one packet associated with a data flow into a flow specification, a traffic classification engine operative to

classify the data flow based on an encrypted connection protocol identified during a handshake between a first host and a second host;

identify handshake packets of the data flow, wherein one or more of the handshake packets includes a digital certificate; and

examine the digital certificate for one or more handshake attributes, wherein at least one handshake attribute is an attribute contained in the digital certificate;

further classify the data flow by matching the data flow against a plurality of traffic classes, at least one of the traffic classes defined by the attribute of the digital certificate;

having found a matching traffic class, associate the flow specification corresponding to the data flow with a traffic class from the plurality of traffic classes.

8. The apparatus of claim 7 wherein at least one of the plurality of traffic classes is defined by one or more matching attributes, wherein said matching attributes are explicitly presented in the packets associated with the data flows.

9. The apparatus of claim 8 wherein said flow specification contains, and wherein the one or more matching attributes include, at least one instance of any one of the following: a protocol family designation, a direction of packet flow designation, a protocol type designation, a pair of hosts, a pair of ports, a pointer to a MIME type, a digital certificate common name, and a pointer to an application-specific attribute.

10. The apparatus of claim 7 wherein said flow specification contains at least one instance of any one of the following: a protocol family designation, a direction of packet flow designation, a protocol type designation, a pair of hosts, a pair of ports, a pointer to a MIME type, a digital certificate common name, and a pointer to an application-specific attribute.

11. The apparatus of claim 7 further comprising

a flow control module operative to apply bandwidth utilization controls to the data flows based on the traffic class associated with the data flows.

12. The apparatus of claim 7 wherein the digital certificate comprises a common name; and wherein the handshake attribute comprises the common name of the digital certificate.

13. The apparatus of claim 7 wherein the handshake packets are formatted according to the SSL protocol.

14. The apparatus of claim 7 wherein the handshake packets are formatted according to the TLS protocol.

15. A method facilitating classification of data flows, comprising

detecting, at a network device, a data flow in network traffic traversing a communications path, the data flows each comprising at least one packet;

parsing, using the network device, explicit attributes at least one packet associated with the data flow into a flow specification,

detecting, at the network device, a handshake in a data flow between a first node and a second node, wherein the handshake comprises an exchange of messages including information useful to establish an encrypted connection between the first node and the second node, wherein the information includes a digital certificate;

classifying, using the network device, the data flow based on an encrypted connection protocol identified during the handshake;

examining, using the network device, the messages corresponding to the handshake to identify the digital certificate;

examining, using the network device, the digital certificate to identify one or more handshake attributes;

further classifying, using the network device, the data flow by matching the flow specification against a first plurality of traffic classes, wherein at least one of the first plurality of traffic classes is defined in part by a handshake attribute that is an attribute contained in the digital certificate,

having found a matching traffic class, associating the flow specification corresponding to the data flow with a traffic class from the first plurality of traffic classes.

16. The method of claim 15 wherein the flow specification contains at least one instance of any one of the following: a protocol family designation, a direction of packet flow designation, a protocol type designation, a pair of hosts, a pair of ports, a pointer to a MIME type, and a pointer to an application-specific attribute.

17. The method of claim 15 wherein said flow specification contains, and wherein the one or more matching attributes include, at least one instance of any one of the following: a protocol family designation, a direction of packet flow designation, a protocol type designation, a pair of hosts, a pair of ports, a pointer to a MIME type, and a pointer to an application-specific attribute.

18. The method of claim 15 wherein the digital certificate comprises a common name; and wherein the handshake attribute comprises the common name of the digital certificate.

19. The method of claim 15 wherein the handshake is a SSL protocol handshake.

20. The method of claim 15 wherein the handshake is a TLS protocol handshake.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0144 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2011
From: PACKETEER, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 027307/0603 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2004
From: YUNG, WENG-CHIN
To: PACKETEER, INC.
Reel/Frame 015689/0391 →