Network Edge Device Application Traffic Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network edge devices, such as wireless access points, lack sufficient memory storage and processing power to analyze network traffic from numerous mobile devices and determine appropriate policy actions, necessitating offloading of storage and processing tasks to local and/or cloud-based network devices and systems.
Innovation Solution
A network edge device with a processor that classifies application traffic by associating it with an application ID and sends queries to a database for application attributes, enabling policy enforcement based on received attributes, while offloading processing and storage tasks to other network devices, allowing for dynamic and real-time application identification and policy implementation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network edge devices attempt to analyze network traffic and determine policy actions locally, then application classification accuracy can be improved, but the device's memory storage and processing power requirements increase beyond what edge devices can provide
Solution Approach 1:
The patent introduces a centralized server as an intermediary between network edge devices and application databases. The edge device sends network traffic data to the server, which then queries the database and returns application classification information. This mediator approach allows accurate classification without requiring the edge device to have sufficient local processing power or storage capacity.
Solution Approach 2:
The patent extracts the complex functions of application analysis, classification, and policy determination from the network edge device and relocates them to a centralized server with access to comprehensive databases. This extraction removes the burden of heavy processing and storage requirements from the edge device while maintaining classification accuracy through centralized intelligence.
2Device complexity
If network edge devices offload storage and processing tasks to centralized servers, then device resource requirements can be reduced, but real-time policy enforcement capability may be compromised
Solution Approach 1:
The system performs preliminary actions by pre-populating a centralized database with comprehensive application information, attributes, and policy rules before traffic analysis is needed. When the edge device sends traffic data, the server can quickly retrieve pre-analyzed information and return it immediately, enabling real-time policy enforcement without requiring the edge device to perform complex real-time analysis.
Solution Approach 2:
The patent replaces the mechanical approach of real-time local processing with an information-based system where pre-computed application profiles and policy rules are stored in a database. The centralized server substitutes the edge device's processing capability by retrieving and returning pre-analyzed information, achieving real-time performance through efficient data retrieval rather than real-time computation.
3Measurement precision
If centralized databases store comprehensive application attributes, then application classification accuracy improves, but the quantity of data storage requirements increase significantly
Solution Approach 1:
The centralized database serves multiple functions: storing application identification information, classification attributes, policy rules, and update information. By making the database universal and multi-functional, the system achieves comprehensive classification accuracy without requiring separate storage systems for each function, optimizing the overall storage requirements while maintaining detailed application profiles.
Data Source
AI summary
In certain embodiments, a network edge device comprises a memory storage, a networking component configured to communicate with a mobile device and a database comprising application attributes, and a processor. The processor, in certain embodiments, is located within the network edge device and is operable to receive application traffic from the mobile device (the application traffic being associated with an application), classify the application traffic by associating the application traffic with an application ID, and send a query comprising the application ID to the database comprising application attributes. In addition, the processor, in certain embodiments, is operable to receive a response, from the database comprising application attributes, comprising one or more application attributes associated with the application, wherein the response is based in part on the application ID, and to enforce a policy based in part on the application attribute.


