In-Band Probe Endpoint Service for Cloud Situational Awareness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for determining the state of overlay tunnels in cloud networking systems only convey UP/DOWN information, lacking meaningful situational awareness and mitigation details, which limits the ability to effectively manage and respond to network failures and disruptions.

Innovation Solution

Implementing a cloud system with a probe endpoint service that uses in-band communication to transmit probes and receive responses containing situational data, allowing for proactive mitigation and remedial actions based on the received information, including HTTP GET and POST requests for connectivity checks and maintenance data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional probe mechanisms are used to determine overlay tunnel state, then connectivity status (UP/DOWN) can be determined, but meaningful situational awareness and mitigation details are not provided

Engineering Contradiction:
Improvesituational awareness informationVSAvoidprobe mechanism complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent combines connectivity testing and situational awareness data collection into a single probe mechanism. The probe client sends probes through overlay tunnels to cloud service endpoints, and the probe endpoint service returns both connectivity status and situational data (maintenance events, security events, service performance metrics) in the same response, eliminating the need for separate monitoring systems

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The probe endpoint service is designed to provide multiple functions: determining tunnel connectivity status, conveying situational awareness data, and providing mitigation details. This multi-functional approach allows a single system component to address multiple monitoring needs that would traditionally require separate mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If detailed situational data is collected through in-band communication, then proactive mitigation and remedial actions can be performed, but communication overhead and processing requirements increase

Engineering Contradiction:
Improvenetwork failure response reliabilityVSAvoidcommunication and processing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The probe mechanism collects situational awareness data proactively before failures occur. By gathering maintenance event information, security event data, and service performance metrics through regular probes, the system can anticipate and prepare for potential issues, enabling proactive mitigation rather than reactive response

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The probe endpoint service provides feedback to the probe client about tunnel health, situational conditions, and recommended mitigation actions. This feedback loop enables the client to automatically adjust its behavior based on current service conditions, improving reliability without requiring constant human intervention

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10819562B2Cloud services management systems utilizing in-band communication conveying situational awareness
Publication Date: 2020.10.27 ZSCALER INC
  • US10819562B2 patent drawing
  • US10819562B2 patent drawing
  • US10819562B2 patent drawing

AI summary

A cloud system includes a plurality of cloud nodes configured to implement a cloud service which is used by a plurality of clients; a cloud management system communicatively coupled to the plurality of cloud nodes and configured to manage the plurality of cloud nodes; and a probe endpoint service executed on a cloud node, wherein a client is configured to utilize the cloud service based on a connection between the client and the cloud node executing the probe endpoint service, wherein the client is configured to execute a probe client, wherein the probe client is configured to periodically transmit probes and receive probe responses which are either empty responses denoting connectivity or a response body with maintenance or situational data contained therein, and wherein the probe client is configured to perform mitigation actions based on reception of the data.