IP Library › Granted Patent US 11,509,539
Granted Patent B2
US 11,509,539 · App. 16/758,209 · Granted Nov 22, 2022

Traffic analysis apparatus, system, method, and program

Inventors: Takanori Iwai (Tokyo, JP); Anan Sawabe (Tokyo, JP)
Assignee: NEC CORPORATION
H04L41/142H04L1/002H04L43/08H04L47/24G16Y10/75
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,539
App. No.
16/758,209
Granted
Nov 22, 2022
Kind
B2
Abstract

A traffic analysis apparatus includes: a first means that estimates a state sequence from time-series data of communication traffic based on a hidden Markov model, and groups, into one group, a plurality of patterns with resembling state transitions in the state sequence to perform extraction of a state sequence, with taking the plurality of patterns grouped into one group as one state; and a second means that determines an application state corresponding to the time-series data based on the state sequence extracted by the first means and predetermined application characteristics.

Claims (41)

1. A traffic analysis apparatus, comprising:

a processor; and

a memory in circuit communication with the processor,

wherein the processor, when executing program instructions stored on the memory;

estimates a state sequence from time-series data of communication traffic based on a continuous hidden Markov model as a lower layer of a hierarchical hidden Markov model;

applies a discrete hidden Markov model as an upper layer of a hierarchical hidden Markov model to the state sequence estimated based on the continuous hidden Markov model; groups a plurality of states in a segment having resembling state transition patterns in the estimated state sequence;

assigns one state of the discrete hidden Markov model to the plurality of states grouped into one group to perform extraction of a state sequence, based on the discrete hidden Markov model with the plurality of patterns grouped into the one group as the one state;

extracts a feature value of the communication traffic, based on the state sequence extracted based on the discrete hidden Markov model, and

collates the feature value with one or more application feature values registered in advance to determine an application state corresponding to the time-series data.

2. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory,

generates communication noise by using an inverse function of a cumulative distribution function, based on a noise characteristic parameter corresponding to a type of a network through which the communication traffic flows and subtracts the communication noise from the time-series data of the communication traffic.

3. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory,

updates the hierarchical hidden Markov model.

4. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory, determines an application state based on a degree of similarity between the time-series data of the communication traffic corresponding to the state sequence extracted and the communication traffic corresponding to an application state in advance registered.

5. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory, determines an application state based on a degree of similarity between the state sequence extracted and a sequence of an application state in advance registered.

6. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory, uses a feature value of communication traffic of an application as training data, performs machine learning to generate a classification model that determines the application, and determines the application state by using the classification model on time-series data of evaluation target communication traffic.

7. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory, uses the continuous hidden Markov model as the lower layer of the hierarchical hidden Markov model and an EDHMM (Explicit-Duration) type discrete hidden Markov model as the upper layer of the hierarchical hidden Markov model.

8. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory,

predicts a future application state by using a plurality of application states that have already been determined.

9. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory,

predicts future communication traffic by using a plurality of application states that have already been determined.

10. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory,

performs at least one of network control and communication control based on an estimated application state.

11. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory,

determines application quality (QoE) based on the application state.

12. The traffic analysis apparatus according to claim 1 , wherein the processor, when executing the program instructions stored on the memory,

performs at least one of network control and communication control based on the application state or a prediction result of the future application state.

13. A computer-based traffic analysis method, comprising:

estimating a state sequence from time-series data of communication traffic based on a continuous hidden Markov model as a lower layer of a hierarchical hidden Markov model;

applying a discrete hidden Markov model as an upper layer of a hierarchical hidden Markov model to the state sequence estimated based on the continuous hidden Markov model;

grouping, a plurality of states in a segment having with resembling state transition patterns in the estimated state sequence;

assigning one state of the discrete hidden Markov model to the plurality of states grouped into one group to perform extraction of a state sequence, based on the discrete hidden Markov model with the plurality of patterns grouped into the one group as the one state;

extracting a feature value of the communication traffic, based on the state sequence extracted based on the discrete hidden Markov model, and

collating the feature value with one or more application feature values registered in advance to determine an application state corresponding to the time-series data.

14. A non-transitory computer-readable medium storing a program causing a computer to execute processing comprising:

estimating a state sequence from time-series data of communication traffic based on a continuous hidden Markov model as a lower layer of a hierarchical hidden Markov model

applying a discrete hidden Markov model as an upper layer of a hierarchical hidden Markov model to the state sequence estimated based on the continuous hidden Markov model;

grouping, a plurality of states in a segment having resembling state transition patterns in the estimated state sequence;

assigning one state of the discrete hidden Markov model to the plurality of states grouped into one group to perform extraction of a state sequence, based on the discrete hidden Markov model with the plurality of patterns grouped into the one group as the one state; and

extracting a feature value of the communication traffic, based on the state sequence extracted based on the discrete hidden Markov model, and

collating the feature value with one or more application feature values registered in advance to determine an application state corresponding to the time-series data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2020
From: IWAI, TAKANORI; SAWABE, ANAN
To: NEC CORPORATION
Reel/Frame 052466/0024 →
Priority Claims (1)
JP JP2017-207638 · Oct 26, 2017 · national
Continuity (1)
Related Publication 20200328947A1 · Oct 15, 2020
Cited By (1)
US 12,719,771