IP Library Granted Patent US 9,973,473
Granted Patent B2
US 9,973,473 · App. 14/387,967 · Granted May 15, 2018

Methods, systems, and computer readable media for rapid filtering of opaque data traffic

Inventors: Andrew Maxwell White (Chapel Hill, NC); Fabian Monrose (Chapel Hill, NC); Srinivas Krishnan (Berkeley, CA); Phillip Andrew Porras (Cupertino, CA); Michael Donald Bailey (Ypsilanti, MI)
Assignee: THE UNIVERSITY OF NORTH CAROLINA AT CHAPEL HILL
H04L63/0245H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,973,473
App. No.
14/387,967
Granted
May 15, 2018
Kind
B2
Abstract

Methods, systems, and computer readable media for rapid filtering of opaque data traffic are disclosed. According to one method, the method includes receiving a packet containing a payload. The method also includes analyzing a portion of the payload for determining whether the packet contains compressed or encrypted data. The method further includes performing, if the packet contains compressed or encrypted data, at least one of sending the packet to an opaque traffic analysis engine for analysis, discarding the packet, logging the packet, or marking the packet.

Claims (26)

1. A method for rapid filtering of opaque data traffic, the method comprising:

at an opaque traffic filter (OTF) module implemented using software executed by a processor, wherein the processor includes a data acquisition and generation card (DAG), a graphics processing unit (GPU), or a general-purpose processor:

receiving a packet containing a payload;

analyzing a portion of the payload to determine whether the packet contains compressed or encrypted data, wherein analyzing the portion of the payload to determine whether the packet contains compressed or encrypted data includes using a null hypothesis indicating the portion of the payload is opaque data and an alternate hypothesis indicating that the portion of the payload is transparent data, wherein the alternate hypothesis uses a probability density indicating that a majority of byte values in the portion of the payload are ASCII values, wherein determining that the packet contains compressed or encrypted data includes determining that a byte value distribution of the portion of the packet supports the null hypothesis and fails to support the alternate hypothesis, wherein determining whether the packet contains compressed or encrypted data includes using at least one of a fixed sample-size hypothesis test or an autocorrelation function; and

performing in response to determining that the packet contains compressed or encrypted data, at least one of sending the packet to an opaque traffic analysis engine for analysis, discarding the packet, logging the packet, or marking the packet, wherein the receiving, the analyzing, and the performing are performed by the data acquisition and generation card (DAG), the graphics processing unit (GPU), or the general-purpose processor.

2. The method of claim 1 wherein receiving the packet includes observing and copying the packet from a plurality of packets traversing a link or node.

3. The method of claim 1 wherein the portion of the payload analyzed is less than or equal to the entire payload.

4. The method of claim 1 wherein the portion of the payload analyzed includes about 16 bytes or less than 16 bytes.

5. The method of claim 1 wherein determining that the portion of the payload includes uniformly distributed byte values indicates that the packet contains compressed or encrypted data.

6. The method of claim 1 wherein at least one of a sequential hypothesis test, the fixed sample-size hypothesis test, or the autocorrelation function is used in differentiating an encrypted packet and a compressed packet.

7. The method of claim 1 wherein the DAG, the GPU, or the general-purpose processor performs statistical hypothesis tests or statistical fingerprinting.

8. A system for rapid filtering of opaque data traffic, the system comprising:

a processor, wherein the processor includes a data acquisition and generation card (DAG), a graphics processing unit (GPU), or a general-purpose processor; and

an opaque traffic filter (OTF) module implemented using software executed by the processor, the OTF module configured to receive a packet containing a payload, to analyze a portion of the payload to determine whether the packet contains compressed or encrypted data, wherein analyzing the portion of the payload to determine whether the packet contains compressed or encrypted data includes using a null hypothesis indicating the portion of the payload is opaque data and an alternate hypothesis indicating that the portion of the payload is transparent data, wherein the alternate hypothesis uses a probability density indicating that a majority of byte values in the portion of the payload are ASCII values, wherein determining that the packet contains compressed or encrypted data includes determining that a byte value distribution of the portion of the packet supports the null hypothesis and fails to support the alternate hypothesis, wherein determining whether the packet contains compressed or encrypted data includes using at least one of a fixed sample-size hypothesis test or an autocorrelation function, and to perform, in response to determining that the packet contains compressed or encrypted data, at least one of sending the packet to an opaque traffic analysis engine for analysis, discarding the packet, logging the packet, or marking the packet.

9. The system of claim 8 wherein the system comprises a communications interface configured to observe and copy the packet from a plurality of packets traversing a link or node.

10. The system of claim 8 wherein the portion of the payload analyzed is less than or equal to the entire payload.

11. The system of claim 8 wherein the portion of the payload analyzed includes about 16 bytes or less than 16 bytes.

12. The system of claim 8 wherein determining that the portion of the payload includes uniformly distributed byte values indicates that the packet contains compressed or encrypted data.

13. The system of claim 8 wherein the OTF module is configured to use at least one of a sequential hypothesis test, the fixed sample-size hypothesis test, or the autocorrelation function in differentiating an encrypted packet and a compressed packet.

14. The system of claim 8 wherein the OTF module is configured to inform a packet inspection analysis engine when a session becomes opaque or transparent and/or when a packet of the session is examined that does not match an expected type for the session.

15. The system of claim 8 wherein the processor performs statistical hypothesis tests or statistical fingerprinting.

16. A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising:

at an opaque traffic filter (OTF) module implemented using software executed by a processor, wherein the processor includes a data acquisition and generation card (DAG), a graphics processing unit (GPU), or a general-purpose processor:

receiving a packet containing a payload;

analyzing a portion of the payload to determine whether the packet contains compressed or encrypted data, wherein analyzing the portion of the payload to determine whether the packet contains compressed or encrypted data includes using a null hypothesis indicating the portion of the payload is opaque data and an alternate hypothesis indicating that the portion of the payload is transparent data, wherein the alternate hypothesis uses a probability density indicating that a majority of byte values in the portion of the payload are ASCII values, wherein determining that the packet contains compressed or encrypted data includes determining that a byte value distribution of the portion of the packet supports the null hypothesis and fails to support the alternate hypothesis, wherein determining whether the packet contains compressed or encrypted data includes using at least one of a fixed sample-size hypothesis test or an autocorrelation function; and

performing, in response to determining that the packet contains compressed or encrypted data, at least one of sending the packet to an opaque traffic analysis engine for analysis, discarding the packet, logging the packet, or marking the packet, wherein the receiving, the analyzing, and the performing are performed by a data acquisition and generation card (DAG), a graphics processing unit (GPU), or a general-purpose processor.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S NAME ON THE ORIGINAL COVERSHEET PREVIOUSLY RECORDED ON REEL 034948 FRAME 0607. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 23, 2016
From: PORRAS, PHILLIP ANDREW
To: SRI INTERNATIONAL
Reel/Frame 038236/0496 →
CONFIRMATORY LICENSE Recorded Apr 6, 2015
From: UNIVERSITY OF NORTH CAROLINA, CHAPEL HILL
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 035366/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2015
From: PORRAS, PHILLIP ANDREW
To: SR INTERNATIONAL
Reel/Frame 034948/0607 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2015
From: WHITE, ANDREW MAXWELL; MONROSE, FABIAN; KRISHNAN, SRINIVAS
To: THE UNIVERSITY OF NORTH CAROLINA AT CHAPEL HILL
Reel/Frame 034948/0687 →
Continuity (2)
Provisional Application 61618648 · Mar 30, 2012
Related Publication 20150052601A1 · Feb 19, 2015