BGP Flow Specification for Granular Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional routing protocols, such as BGP, lack flexibility in filtering network traffic, as they primarily mark network destinations to drop all traffic bound for them, offering little granularity in controlling specific packet flows.
Innovation Solution
Extending the Border Gateway Protocol (BGP) with a flow specification data type that allows for the definition of fine-grain traffic flow criteria, including source, destination, port, and protocol information, enabling routers to control network traffic based on variable packet attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If BGP routing entries are used to mark network destinations for traffic dropping, then network security is improved, but traffic control flexibility deteriorates
Solution Approach 1:
The patent segments the traffic control functionality by introducing flow specification data types that divide the coarse-grained destination-based filtering into fine-grained flow-based filtering. This allows differentiation between various types of traffic (e.g., HTTP vs. HTTPS, different ports, protocols) while maintaining security, thereby resolving the contradiction between security and flexibility.
Solution Approach 2:
The patent adds new dimensions to traffic identification by incorporating flow specification attributes (source port, destination port, protocol type, etc.) alongside traditional destination addresses. This dimensional expansion enables fine-grained traffic control without sacrificing security, as the enhanced granularity allows precise targeting of malicious flows while preserving legitimate traffic.
2Measurement precision
If fine-grain traffic flow criteria are implemented, then traffic control precision is improved, but protocol complexity increases
Solution Approach 1:
The patent makes the routing protocol universally applicable to both traditional destination-based routing and the new flow specification-based routing. By designing the flow specification data types to be optional extensions within the existing BGP framework, the protocol maintains backward compatibility while enabling enhanced functionality, thus avoiding unnecessary complexity increase.
Solution Approach 2:
The flow specification data types are nested within the existing BGP routing update messages as optional attributes. This nesting approach allows the fine-grain traffic flow criteria to be carried within the existing protocol structure without requiring a complete protocol redesign, thereby improving precision while minimizing complexity overhead.
3Object-affected harmful factors
If all traffic to marked destinations is dropped, then attack prevention is improved, but legitimate traffic loss increases
Solution Approach 1:
The patent applies local quality by enabling different treatment of different traffic flows. Instead of uniform dropping of all traffic to marked destinations, the system can selectively drop only specific flows (e.g., malicious HTTP traffic) while allowing other flows (e.g., legitimate HTTPS traffic) to pass through. This localized differentiation prevents attacks while preserving legitimate traffic.
Solution Approach 2:
The patent enables partial action by allowing network devices to apply traffic control measures only to the extent necessary to prevent attacks, rather than implementing blanket dropping. Flow specification criteria enable selective filtering that targets only the harmful portions of traffic, avoiding excessive action that would unnecessarily block legitimate communications.
Data Source
AI summary
Traffic flow criteria are distributed between routing devices. More specifically, a routing protocol, such as the Border Gateway Protocol (BGP), may be extended in a manner that allows fine-grain criteria to be conveyed for application to network traffic. For example, a flow specification data type may be defined in accordance with BGP to allow a variable number of packet flow attributes to be specified, such as source information, destination information, port information, protocol or other flow criteria. In this manner, traffic flow criteria are specified in a way that cannot be expressed using destination address prefixes only. The flow specification data type may be defined as network layer reachability information (NLRI) that is associated with a route advertised in accordance with BGP.


