PEER TO PEER TRAFFIC CONTROL METHOD AND SYSTEM
A system, apparatus, and method for controlling peer to peer traffic at a network gateway or server. Suspected peer to peer traffic is identified heuristically and collected for content analysis. Content digital fingerprint pattern matching software is received from a remote server. Peer to peer traffic is selectively disposed of.
1 . A method comprising the steps of
receiving and storing at least one peer to peer fingerprint pattern;
matching a packet with a peer to peer fingerprint pattern; and
disposing of the packet according to a peer to peer service policy.
2 . The method of claim 1 further comprising the process of receiving a list of selected sources.
3 . The method of claim 2 further comprising the process
for selecting a source of peer to peer application traffic comprising
scanning all packets transmitted from a source within a first network to a destination within a second network;
recording destination IP address and port number for each source; and
if the number of ports per destination IP exceeds a certain threshold,
matching a packet with a peer to peer fingerprint pattern.
4 . The method of claim 2 further comprising the process for selecting a source of peer to peer application traffic comprising
scanning all packets transmitted from a source within a first network to a destination within a second network;
recording destination IP address and port number for each source; and
if the number of destination IP per unit time the source sends to exceeds a certain threshold,
matching a packet with a peer to peer fingerprint pattern.
5 . The method of claim 2 further comprising the process for selecting a source of peer to peer application traffic comprising
scanning all packets transmitted from a source within a first network to a destination within a second network;
computing the number of destination IP per unit time the source sends to;
recording destination IP address and port number for each source; and
if at least one of the number of ports per destination IP exceeds a first threshold, and
the number of destination IP per unit time the source send to exceeds a second threshold, matching a packet with a peer to peer fingerprint pattern.
6 . The method of claim 5 further comprising the step of passing packets sent to standard ports associated with documented client server applications without further examination of destination IP addresses.
7 . The method of claim 1 wherein a peer to peer fingerprint pattern is tangibly embodied as an executable module adapted to control a processor at the kernel level of access returning a match or no-match with a certain peer to peer application.
8 . The method of claim 1 wherein a peer to peer fingerprint pattern is tangibly embodied as an executable module adapted to control a processor at the user level of access returning a match or no-match with a certain peer to peer application.
9 . A system and method for controlling peer to peer traffic at a network gateway is comprised of
means for reading port and IP addresses on a packet traversing the gateway;
means for receiving at least one peer to peer fingerprint pattern;
means for receiving a list of selected sources within the first network;
means for disposing of packets; and
means for matching a packet with a peer to peer fingerprint pattern.
10 . The method of claim 9 wherein disposing of peer to peer packet traffic comprises dropping the packet.
11 . The method of claim 9 wherein disposing of peer to peer packet traffic comprises rejecting the packet.
12 . The method of claim 9 wherein disposing of peer to peer packet traffic comprises redirecting the packet.
13 . The method of claim 9 wherein disposing of peer to peer packet traffic comprises recording the packet.
14 . The method of claim 9 wherein disposing of peer to peer packet traffic comprises forwarding the packet.
15 . The method of claim 9 wherein selected peer to peer traffic is transmitted for a certain source.
16 . The system of claim 9 wherein the means comprise a processor in a gateway attaching a first network to a second network.
17 . The system of claim 9 wherein the means comprise a processor in a cache server within a first network redirecting packets to a second network.
18 . A process for selecting a source of potential peer to peer application traffic for further analysis comprising
scanning all packets transmitted from a source within a first network to at least one destination within a second network;
recording destination IP address and port number for a source; and
if the number of ports per destination IP exceeds a certain threshold,
adding the source to a list of potential peer to peer application sources.
19 . The process of claim 18 further comprising the step of matching a packet with a peer to peer fingerprint pattern.
20 . A process for selecting a source of potential peer to peer application traffic for further analysis comprising
scanning all packets transmitted from a source within a first network to a destination within a second network;
recording destination IP address and port number for a source; and
if the number of destination IP per unit time the source sends to exceeds a certain threshold, adding the source to a list of potential peer to peer application sources.
21 . The process of claim 20 further comprising the step of matching a packet with a peer to peer fingerprint pattern.
22 . A process for selecting a source of potential peer to peer application traffic for further analysis comprising
scanning all packets transmitted from a source within a first network to a destination within a second network;
matching a packet with a peer to peer fingerprint pattern; and if a packet matches a peer to peer fingerprint pattern, adding the source to a list of potential peer to peer application sources.