Error Packet Metadata Telemetry for Network Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telemetry systems lack the ability to provide context associated with error packets, leading to ineffective network policy enforcement and potential false positives, as they only indicate that an error occurred without providing details about the packet causing the error.

Innovation Solution

A network device is configured to detect errors, determine metadata associated with error packets, and generate telemetry data that includes this metadata, allowing a network analyzer to enforce policies based on the context of the error packets, thereby enabling more granular policy enforcement and identifying sources of errors or malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional telemetry systems only record error occurrence without packet context, then the system complexity is reduced and processing is simpler, but the network policy enforcement effectiveness deteriorates and false positives increase

Engineering Contradiction:
Improvenetwork policy enforcement effectivenessVSAvoidtelemetry data processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments telemetry data into two parts: error occurrence indicators and packet context metadata. The network device generates telemetry data that includes both the error event and associated packet metadata (such as packet headers, source/destination information). This segmentation allows the network analyzer to receive structured data where error information and context information are separated but linked, enabling effective policy enforcement without overwhelming complexity in the telemetry system.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If telemetry data includes detailed packet metadata, then measurement precision of error context is improved, but the quantity of data transmitted and processed increases

Engineering Contradiction:
Improveerror packet context accuracyVSAvoidtelemetry data volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential packet metadata fields that are relevant for network policy enforcement, rather than transmitting complete packet data. The network device extracts specific context information such as packet headers, source and destination addresses, and error type, excluding unnecessary packet payload and redundant fields. This extraction approach provides sufficient measurement precision for error analysis while significantly reducing the quantity of telemetry data that needs to be transmitted and processed.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If the network analyzer enforces policies without packet context, then the processing speed is faster, but the productivity of network security enforcement deteriorates due to false positives

Engineering Contradiction:
Improvenetwork security enforcement efficiencyVSAvoidtime for policy decision accuracy
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the network device prepare and attach packet context metadata to telemetry data before transmission to the network analyzer. This preliminary preparation of context information allows the network analyzer to immediately enforce policies with high accuracy upon receiving telemetry data, without needing to perform additional packet capture or analysis operations. The context is already prepared in advance, enabling fast and accurate policy decisions that improve network security enforcement productivity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11902096B2Collection of error packet information for network policy enforcement
Publication Date: 2024.02.13 JUNIPER NETWORKS INC
  • US11902096B2 patent drawing
  • US11902096B2 patent drawing
  • US11902096B2 patent drawing

AI summary

A network device may detect an error associated with a packet based on error information being generated from processing the packet at a layer of a network stack. The network device may determine, based on detecting the error, metadata associated with the packet. The network device may generate telemetry data to include the metadata. The network device may provide the telemetry data to a network analyzer for policy enforcement.