Dynamic Traffic Steering for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network traffic management systems lack dynamic control over data traffic steering, failing to effectively target and mitigate security threats in voluminous IP traffic, especially for resource-constrained services that require intensive data analysis.
Innovation Solution
A dynamic traffic steering system that uses a security agent to analyze network traffic and make intelligent steering decisions on a per-flow basis, directing traffic through secure channels like VPN tunnels or direct paths based on threat levels, application types, and behavioral analysis, allowing for targeted traffic blocking or redirection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all network traffic is collected for analysis by security services, then comprehensive threat detection is achieved, but resource consumption increases significantly
Solution Approach 1:
The patent segments network traffic into different categories (suspicious vs. normal) and routes them through different paths. A traffic steering component divides the voluminous traffic stream, sending only suspicious traffic to resource-constrained security services for intensive analysis, while normal traffic is offloaded to capacious communication channels. This segmentation resolves the contradiction by maintaining comprehensive threat detection capability while significantly reducing resource consumption at security services.
Solution Approach 2:
The patent extracts and isolates suspicious traffic from the bulk normal traffic using machine learning-based classification. By taking out only the relevant suspicious packets for security service analysis and leaving normal traffic to be handled by other channels, the system achieves effective threat detection without overwhelming security service resources with unnecessary traffic volume.
2Ease of operation
If static routing is used to split traffic between destinations, then traffic differentiation is achieved, but dynamic control capability is lost
Solution Approach 1:
The patent replaces static routing with dynamic traffic steering decisions made by machine learning models. The system continuously analyzes traffic characteristics, identifies suspicious patterns, and dynamically adjusts routing decisions in real-time based on current threat levels and traffic types. This dynamic approach maintains ease of traffic splitting while adding adaptability to respond to evolving threats and changing network conditions.
Solution Approach 2:
The patent implements feedback loops where security services analyze traffic samples, generate threat assessments, and feed this information back to the traffic steering component. This feedback mechanism enables the system to continuously adapt routing decisions based on actual threat levels detected, transforming static routing into a dynamic, responsive system that can adjust to changing security conditions while maintaining operational simplicity.
3Reliability
If resource-constrained security services receive all traffic, then complete analysis coverage is achieved, but service performance deteriorates
Solution Approach 1:
The patent segments traffic into suspicious and normal categories using machine learning classification, directing only suspicious traffic to resource-constrained security services. This segmentation maintains complete analysis coverage for threats while improving service performance by eliminating the performance-deteriorating burden of processing voluminous normal traffic through the same resource-constrained services.
Solution Approach 2:
The patent applies partial action by sending only a subset of traffic (suspicious traffic identified through classification) to security services rather than all traffic. This partial approach ensures complete threat analysis coverage while preventing performance deterioration by avoiding the excessive load that would result from processing entire traffic volumes through resource-constrained services.
Data Source
AI summary
The invention provides a security system and method for use in a communications network, said network comprising means to allow a plurality of devices to communicate over the network; a security agent configured on at least one device and adapted to communicate with the security system; said system comprising: means for performing dynamic intelligent traffic steering from the device based on analysis of data traffic on the network or on the device, wherein the steering decision can be made to select a channel on a per flow basis.


