IP Library Granted Patent US 9,100,309
Granted Patent B2
US 9,100,309 · App. 14/025,098 · Granted Aug 4, 2015

Identification and classification of web traffic inside encrypted network tunnels

Inventors: Mihai Christodorescu (Briarcliff Manor, NY); Xin Hu (White Plains, NY); Douglas L. Schales (Ardsley, NY); Reiner Sailer (Scarsdale, NY); Marc Ph. Stoecklin (Bern, CH); Ting Wang (Elsmford, NY); Andrew M. White (Chapel Hill, NC)
Assignee: International Business Machines Corporation
H04L43/0876G06N5/003G06N5/022G06N99/005H04L63/029H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,100,309
App. No.
14/025,098
Granted
Aug 4, 2015
Kind
B2
Abstract

The present principles are directed to identifying and classifying web traffic inside encrypted network tunnels. A method includes analyzing network traffic of unencrypted data packets to detect packet traffic, timing, and size patterns. The detected packet, timing, and size traffic patterns are correlated to at least a packet destination and a packet source of the unencrypted data packets to create at least one of a training corpus and a model built from the training corpus. The at least one of the corpus and model is stored in a memory device. Packet traffic, timing, and size patterns of encrypted data packets are observed. The observed packet traffic, timing, and size patterns of the encrypted data packets are compared to at least one of the training corpus and the model to classify the encrypted data packets with respect to at least one of a predicted network host and predicted path information.

Claims (14)

1. A system, comprising:

a feature extractor for analyzing network traffic of unencrypted data packets to detect packet traffic patterns, packet timing patterns, and packet size patterns therein;

a modeling engine for correlating the detected packet traffic patterns, the detected packet timing patterns, and the detected packet size patterns to at least a packet destination and a packet source of the unencrypted data packets to create at least one of a training corpus and a model built from the training corpus; and

a memory for storing the at least one of the training corpus and the model,

wherein the feature extractor observes packet traffic patterns, packet timing patterns, and packet size patterns of encrypted data packets, and

wherein the system further comprises a prediction engine for comparing the observed packet traffic patterns, the observed packet timing patterns, and the observed packet size patterns of the encrypted data packets to at least one of the training corpus and the model to classify the encrypted data packets with respect to at least one of a predicted network host and predicted path information for the encrypted data packets.

2. The system of claim 1 , wherein the detected packet traffic patterns, the detected packet timing patterns, and the detected packet size patterns are altered to mimic corresponding features of encrypted data.

3. The system of claim 1 , wherein the at least one the training corpus and the model is created using at least one random forest.

4. The system of claim 3 , wherein the at least one of the training corpus and the model is created using a multi-label classification scheme with respect to the at least one random forest, where each label is a prefix of a path for a particular resource or a suffix of a domain name.

5. The system of claim 3 , wherein the at least one random forest comprises a plurality of random forests each having different parameters respectively associated therewith, the method further comprises selecting a best random forest from among the plurality of random forests based on predetermined criteria, and wherein the best random forest is used to provide the at least one of the predicted host name and the predicted path information for the encrypted data packets.

6. The system of claim 5 , wherein the predetermined criteria comprises selecting as the best random forest whichever one of the plurality of random forests has a greatest number of votes for a given label.

7. The system of claim 1 , wherein the at least one of the predicted network host and the predicted path information is determined based on a ranking of possible labels for each of a plurality of input hypertext transfer protocol request and response pairs comprised in the encrypted data packets.

8. The system of claim 1 , wherein the at least one of the predicted network host and the predicted path information is determined based on a mapping of real-valued weights to possible labels for each of a plurality of input hypertext transfer protocol request and response pairs comprised in the encrypted data packets.

9. The system of claim 1 , wherein said modeling engine considers sub-domains and resource paths of the unencrypted data packets when performing the correlating.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2013
From: CHRISTODORESCU, MIHAI; HU, XIN; SCHALES, DOUGLAS L.; SAILER, REINER; STOECKLIN, MARC PH.; WANG, TING; WHITE, ANDREW M.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 031193/0624 →
Continuity (2)
Continuation 13862601 · Apr 15, 2013
Related Publication 20140310517A1 · Oct 16, 2014