BGP Flow Specification for Granular Traffic Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional routing protocols, such as BGP, lack flexibility in filtering network traffic, as they primarily mark network destinations to drop all traffic bound for them, offering little granularity in controlling specific packet flows.

Innovation Solution

Extending the Border Gateway Protocol (BGP) with a flow specification data type that allows for the definition of fine-grain traffic flow criteria, including source, destination, port, and protocol information, enabling routers to control network traffic based on variable packet attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If BGP routing entries are used to mark network destinations for traffic dropping, then network security is improved, but traffic control flexibility deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidtraffic control flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the traffic control functionality by introducing flow specification data types that divide the coarse-grained destination-based filtering into fine-grained flow-based filtering. This allows differentiation between various types of traffic (e.g., HTTP vs. HTTPS, different ports, protocols) while maintaining security, thereby resolving the contradiction between security and flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds new dimensions to traffic identification by incorporating flow specification attributes (source port, destination port, protocol type, etc.) alongside traditional destination addresses. This dimensional expansion enables fine-grained traffic control without sacrificing security, as the enhanced granularity allows precise targeting of malicious flows while preserving legitimate traffic.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If fine-grain traffic flow criteria are implemented, then traffic control precision is improved, but protocol complexity increases

Engineering Contradiction:
Improvetraffic control precisionVSAvoidprotocol complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent makes the routing protocol universally applicable to both traditional destination-based routing and the new flow specification-based routing. By designing the flow specification data types to be optional extensions within the existing BGP framework, the protocol maintains backward compatibility while enabling enhanced functionality, thus avoiding unnecessary complexity increase.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The flow specification data types are nested within the existing BGP routing update messages as optional attributes. This nesting approach allows the fine-grain traffic flow criteria to be carried within the existing protocol structure without requiring a complete protocol redesign, thereby improving precision while minimizing complexity overhead.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Object-affected harmful factors

If all traffic to marked destinations is dropped, then attack prevention is improved, but legitimate traffic loss increases

Engineering Contradiction:
Improveattack preventionVSAvoidlegitimate traffic loss
Core Design Contradiction:
Object-affected harmful factorsVSLoss of substance

Solution Approach 1:

The patent applies local quality by enabling different treatment of different traffic flows. Instead of uniform dropping of all traffic to marked destinations, the system can selectively drop only specific flows (e.g., malicious HTTP traffic) while allowing other flows (e.g., legitimate HTTPS traffic) to pass through. This localized differentiation prevents attacks while preserving legitimate traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent enables partial action by allowing network devices to apply traffic control measures only to the extent necessary to prevent attacks, rather than implementing blanket dropping. Flow specification criteria enable selective filtering that targets only the harmful portions of traffic, avoiding excessive action that would unnecessarily block legitimate communications.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7773596B1Distribution of traffic flow criteria
Publication Date: 2010.08.10 JUNIPER NETWORKS INC
  • US7773596B1 patent drawing
  • US7773596B1 patent drawing
  • US7773596B1 patent drawing

AI summary

Traffic flow criteria are distributed between routing devices. More specifically, a routing protocol, such as the Border Gateway Protocol (BGP), may be extended in a manner that allows fine-grain criteria to be conveyed for application to network traffic. For example, a flow specification data type may be defined in accordance with BGP to allow a variable number of packet flow attributes to be specified, such as source information, destination information, port information, protocol or other flow criteria. In this manner, traffic flow criteria are specified in a way that cannot be expressed using destination address prefixes only. The flow specification data type may be defined as network layer reachability information (NLRI) that is associated with a route advertised in accordance with BGP.