IP Library › Granted Patent US 11,985,169
Granted Patent B2
US 11,985,169 · App. 17/657,166 · Granted May 14, 2024

Classification of unknown network traffic

Inventor: Rajeev Chaubey (Karnataka, IN)
Assignee: Juniper Networks, Inc.
H04L63/20G06N20/00H04L63/02H04L63/0245H04L63/0281
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,985,169
App. No.
17/657,166
Granted
May 14, 2024
Kind
B2
Abstract

A network device may receive network traffic for an application. The network device may determine a first classification for the network traffic according to a first classification technique. The first classification may identify the network traffic as relating to a particular application or an unknown application. The network device may determine a second classification for the network traffic according to a second classification technique. The second classification may identify the network traffic as relating to an unknown application of a particular type and identity. The network device may process, based on whether the first classification identifies the network traffic as relating to the particular application or the unknown application, the network traffic according to a first security policy associated with the particular application or a second security policy associated with the unknown application of the particular type and identity.

Claims (74)

1. A network device, comprising:

one or more memories; and

one or more processors to:

receive network traffic;

determine a classification for the network traffic according to a classification technique,

wherein the classification technique is a machine learning technique that identifies the network traffic as relating to an unknown application of a particular type,

wherein the particular type corresponds to a type of traffic associated with unknown applications; and

process the network traffic according to a policy associated with the unknown application of the particular type.

2. The network device of claim 1 , wherein the network device includes a machine learning classifier component to perform the classification technique,

wherein the machine learning classifier component includes one or more of:

an application classifier,

a traffic type classifier, or

an application identity classifier.

3. The network device of claim 1 , wherein the network device includes a machine learning classifier component and a classification result evaluator component, and

wherein the one or more processors are further to:

provide one or more outputs, by the machine learning classifier component, to the classification result evaluator component; and

determine the policy that is to be enforced with regard to communications based on the one or more outputs.

4. The network device of claim 1 , wherein the one or more processors are further to:

determine an identifier according to a schema for labelling the unknown application of the particular type; and

associate the identifier to the policy associated with the unknown application of the particular type.

5. The network device of claim 1 , wherein the unknown application of the particular type is included in a group of unknown applications of the particular type, and

wherein the policy is associated with the group of unknown applications of the particular type.

6. The network device of claim 1 , wherein the policy is a security policy that allows or blocks traffic associated with the unknown application of the particular type.

7. The network device of claim 1 , wherein the network traffic is comprised of:

streaming video,

file upload,

email,

chat, or

peer to peer.

8. A method, comprising:

receiving, by a network device, network traffic;

determining, by the network device, a classification for the network traffic according to a classification technique,

wherein the classification technique is a machine learning technique that identifies the network traffic as relating to an unknown application of a particular type and a particular identity,

wherein the particular type corresponds to a type of traffic associated with unknown applications, and

wherein the particular identity differentiates between unknown applications of a same type; and

processing, by the network device, the network traffic according to a policy associated with the unknown application of the particular type and the particular identity.

9. The method of claim 8 , wherein the particular identity of the unknown application of the particular type and the particular identity is defined by one or more features of the network traffic.

10. The method of claim 8 , wherein the policy is a security policy that allows traffic associated with the unknown application of the particular type and the particular identity.

11. The method of claim 8 , further comprising:

determining, by a deep packet inspection classification technique, that the unknown application of the particular type and the particular identity is a known application, based on subsequent network traffic for the unknown application of the particular type and the particular identity; and

updating the policy and other data of the network device.

12. The method of claim 8 , wherein the network device includes a machine learning classifier component to perform the classification technique,

wherein the machine learning classifier component includes one or more of:

an application classifier,

a traffic type classifier, or

an application identity classifier.

13. The method of claim 8 , further comprising:

determining one or more features relating to one or more of:

a flow of the network traffic, or

encryption of the network traffic; and

processing the one or more features using the machine learning technique to determine the classification for the network traffic.

14. The method of claim 8 , wherein the unknown application of the particular type and the particular identity is included in a group of unknown applications of the particular type and the particular identity, and

wherein the policy is associated with the group of unknown applications of the particular type and the particular identity.

15. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by one or more processors, cause the one or more processors to:

receive network traffic;

determine a classification for the network traffic according to one or more features of the network traffic,

wherein the classification is determined using a machine learning technique that identifies the network traffic as relating to an unknown application of a particular type and a particular identity,

wherein the particular type corresponds to a type of traffic associated with unknown applications, and

wherein the particular identity differentiates between unknown applications of a same type; and

process the network traffic according to a security policy associated with the unknown application of the particular type and the particular identity.

16. The non-transitory computer-readable medium of claim 15 , wherein the unknown application of the particular type and the particular identity is defined by one or more features of the network traffic.

17. The non-transitory computer-readable medium of claim 15 , wherein the security policy blocks traffic associated with the unknown application of the particular type and the particular identity.

18. The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

determine, by a deep packet inspection classification technique, that the unknown application of the particular type and the particular identity is a known application, based on subsequent network traffic for the unknown application of the particular type and the particular identity; and

update the security policy associated with the unknown application of the particular type and the particular identity.

19. The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

determine the one or more features related to one or more of:

a flow of the network traffic, or

encryption of the network traffic; and

process the one or more features using a machine learning model to determine the classification for the network traffic.

20. The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

determine an identifier according to a schema for labelling the unknown application of the particular type and the particular identity; and

associate the identifier to the policy associated with the unknown application of the particular type and the particular identity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2022
From: CHAUBEY, RAJEEV
To: JUNIPER NETWORKS, INC.
Reel/Frame 060521/0154 →
Continuity (2)
Continuation 16415638 · May 17, 2019
Related Publication 20220224725A1 · Jul 14, 2022