Application Path Identifier Policy for Network Traffic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls using communication-protocol-based policies face inefficiencies as they block all network traffic via a specific protocol, regardless of content or purpose, leading to resource wastage and the need for numerous policies to allow specific application protocols, which is cumbersome and resource-intensive.

Innovation Solution

Implementing an application-path-identifier-based policy that allows network traffic for specific application paths while denying others, reducing the need for individual policies and conserving resources by using an application-path-identifier-based policy instead of communication-protocol-based policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication-protocol-based policies are used to control network traffic, then network security is maintained, but device complexity and resource consumption increase due to the need for numerous individual policies for each application protocol

Engineering Contradiction:
Improvenetwork securityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a single policy type (application-path-identifier-based policy) that can control multiple different application protocols simultaneously. Instead of requiring separate policies for each protocol, the network device uses one unified policy mechanism that works across diverse protocols, reducing policy management complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple protocol-specific policies into a single application-path-identifier-based policy. By combining the control logic for different protocols into one unified policy framework, the system reduces the number of individual policies needed and simplifies the overall policy management structure.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If communication-protocol-based policies block all traffic via a specific protocol, then network security is enhanced, but productivity decreases due to resource wastage and cumbersome policy creation

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork resource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by enabling selective control of network traffic based on specific application paths rather than blocking entire protocols. This allows the system to permit or deny traffic locally at the application-path level, ensuring security for specific applications while allowing other applications to function normally, thus improving resource utilization.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments network traffic control from the protocol level down to the application-path level. By dividing the control granularity, the system can apply security policies to specific application paths within protocols rather than blocking all traffic for entire protocols, reducing resource wastage and improving productivity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If numerous communication-protocol-based policies are created to allow specific application protocols, then network security is maintained, but loss of time increases due to the need for extensive policy creation and enforcement

Engineering Contradiction:
Improvenetwork securityVSAvoidpolicy creation and enforcement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent reduces policy creation time by providing a universal policy mechanism that handles multiple application protocols simultaneously. Instead of creating numerous individual policies, administrators can define a single application-path-identifier-based policy that covers multiple protocols, significantly reducing the time required for policy creation and enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11765090B2Network traffic control based on application identifier
Publication Date: 2023.09.19 JUNIPER NETWORKS INC
  • US11765090B2 patent drawing
  • US11765090B2 patent drawing
  • US11765090B2 patent drawing

AI summary

A network device may receive network traffic associated with a session, wherein the session is associated with a network. The network device may determine, from the network traffic, an application path that is associated with the session and may determine an application path identifier associated with the application path. The network device may determine, based on policy information that is associated with the application path identifier, whether the network traffic associated with the session is permitted to be communicated via the network and may perform, based on whether the network traffic is determined to be permitted, an action associated with communication of the network traffic.