IP Flow Classification Using Router Interface Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The overlapping of IP addressing plans in different client sub-networks connected to the same service provider network leads to inaccurate classification of IP flows, making it impossible for monitoring systems to reliably identify the source or destination site of IP addresses, resulting in cumulative and misallocated flow data.
Innovation Solution
The method involves associating each site with a router interface and using source and destination interface information to correctly classify IP flows, employing additional ranking criteria beyond conventional IP addresses, with geographical and application repositories to distinguish between overlapping IP addressing plans, and utilizing the NetFlow protocol to collect accounting elements from Provider Edge routers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If IP addresses are used to identify entities and sites in the monitoring system, then the system can generate volumetric statistics and flow matrices, but when IP addressing plans overlap between different clients, the classification accuracy deteriorates and entities cannot be reliably distinguished
Solution Approach 1:
The patent introduces interface identification as an additional dimension beyond IP addresses. Each interface is assigned a unique identifier that serves as a new classification dimension, allowing the system to distinguish between overlapping IP addresses from different clients. This dimensional extension transforms the classification space from single-dimensional (IP address only) to multi-dimensional (IP address + interface ID), resolving the ambiguity caused by overlapping addressing plans.
Solution Approach 2:
The patent introduces interface identifiers as intermediary elements between IP addresses and entity identification. These interface IDs act as mediators that bridge the gap between overlapping IP addresses and their true sources. The monitoring system uses these intermediary identifiers to correctly attribute flows to the appropriate entities and sites, even when multiple entities share the same IP address space.
2Loss of information
If the monitoring system collects detailed accounting information from all routers, then comprehensive statistics can be generated, but the complexity of managing and correlating this data across multiple clients with overlapping IP plans increases
Solution Approach 1:
The patent segments the network monitoring function by introducing interface-level identification. Instead of attempting to correlate all IP addresses across the entire network, the system segments the classification task by associating each interface with specific client sites. This segmentation allows the monitoring system to process and correlate accounting information in smaller, manageable units (interface-specific flows) rather than attempting to handle the entire network's IP space as a single complex entity.
Solution Approach 2:
The patent applies local quality by making interface identification specific to each router and site. Rather than using a global IP addressing scheme that must be unique across the entire network, the system allows each interface to have its own local identification context. This local quality approach enables accurate classification at each interface level while maintaining overall network-wide monitoring capability.
3Ease of manufacture
If conventional NetFlow collection is used without interface information, then implementation is simple, but the ability to accurately classify flows by site and entity is lost
Solution Approach 1:
The patent applies preliminary action by pre-configuring interface identifiers on router interfaces before traffic monitoring begins. The interface identification infrastructure is established in advance, with each interface assigned a unique identifier that will be used for subsequent flow classification. This preliminary setup ensures that when accounting information is collected, the interface identification data is already available, eliminating the need for complex real-time correlation algorithms.
Solution Approach 2:
The patent makes the interface identification mechanism universal across the entire network. The same interface identification approach can be applied to any router and any interface, making the solution scalable and adaptable to different network configurations. This universal approach maintains implementation simplicity while improving classification reliability, as the same basic mechanism works consistently across all network elements.
Data Source
AI summary
A method is provided for allowing a monitoring system to classify, by entity, IP “accounting” elements passing through routers of a network of a service provider, these entities being arranged in different sites connected to the network. The method includes:each site is associated with an interface of a router to which that site is connected, andduring analysis by the monitoring system of an accounting element originating from a router, information relating to the source interface and destination interface contained in this accounting element is used in order to identify the source and destination sites and to classify this accounting element with respect to the correct source or destination entity.

