Hot Flow Cache Management via Control Segment Offloading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network traffic management systems face inefficiencies in optimizing the handling of hot connection flows, as they often allocate valuable high-speed cache resources to both legitimate and malicious connection flows, leading to suboptimal performance and resource wastage.

Innovation Solution

Implementing a packet traffic management device with a data flow segment and control segment architecture, where the control segment generates flow control data and identifies hot connection flows for offloading to a high-speed cache, thereby maximizing the use of cache capacity by prioritizing legitimate high-bandwidth flows and minimizing storage of malicious ones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If all connection flows are stored in high-speed cache, then cache availability is maximized, but resource wastage increases due to malicious flows occupying cache space

Engineering Contradiction:
Improvecache capacity utilizationVSAvoidcache resource wastage
Core Design Contradiction:
Quantity of substanceVSLoss of energy

Solution Approach 1:

The patent applies local quality by differentiating treatment for different types of connection flows. Legitimate hot flows receive priority cache allocation while malicious flows are identified and excluded. The system creates distinct cache management policies for different flow categories, ensuring that cache resources are allocated based on flow legitimacy and bandwidth characteristics rather than treating all flows uniformly.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of storing all flows and filtering later, the patent inverts the approach by identifying and excluding malicious flows before they occupy cache space. The system proactively detects malicious patterns and prevents these flows from consuming high-speed cache resources, thereby protecting cache capacity for legitimate traffic from the outset.

Inventive Principle:
Principle #13The other way round (Inversion)

2Speed

If high-speed cache is used for all flows, then packet translation speed improves, but performance degrades due to malicious flow interference

Engineering Contradiction:
Improvepacket translation speedVSAvoidnetwork performance
Core Design Contradiction:
SpeedVSProductivity

Solution Approach 1:

The patent converts the harmful presence of malicious flows into a benefit by using their identification as a trigger for selective cache management. The detection of malicious flow patterns enables the system to dynamically adjust cache allocation, protecting legitimate high-bandwidth flows from performance degradation caused by malicious traffic while maintaining high packet translation speeds for authorized connections.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system dynamically changes cache allocation parameters based on flow characteristics. By monitoring flow behavior and identifying malicious patterns, the patent adjusts cache admission criteria and retention policies in real-time, ensuring that cache resources are optimized for legitimate traffic while malicious flows are excluded or subjected to different handling mechanisms.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If cache resources are allocated to malicious flows, then cache hit rate appears high, but legitimate flow performance suffers

Engineering Contradiction:
Improvecache hit rateVSAvoidlegitimate flow performance
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing flow classification and legitimacy verification mechanisms before cache allocation occurs. The system pre-identifies malicious flow patterns and sets up filtering rules that prevent malicious flows from entering the cache system. This preliminary screening ensures that only legitimate flows compete for cache resources, making cache hit rate a reliable indicator of actual performance rather than being inflated by malicious traffic.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9762492B2Data flow segment optimized for hot flows
Publication Date: 2017.09.12 F5 NETWORKS INC
  • US9762492B2 patent drawing
  • US9762492B2 patent drawing
  • US9762492B2 patent drawing

AI summary

Embodiments are directed towards improving the performance of network traffic management devices by optimizing the management of hot connection flows. A packet traffic management device (“PTMD”) may employ a data flow segment (“DFS”) and control segment (“CS”). The CS may perform high-level control functions and per-flow policy enforcement for connection flows maintained at the DFS, while the DFS may perform statistics gathering, per-packet policy enforcement (e.g., packet address translations), or the like, on connection flows maintained at the DFS. The DFS may include high-speed flow caches and other high-speed components that may be comprised of high-performance computer memory. Making efficient use of the high speed flow cache capacity may be improved by maximizing the number of hot connection flows and minimizing the number of malicious and/or in-operative connections flows (e.g., non-genuine flows) that may have flow control data stored in the high-speed flow cache.