IP Flow Classification Using Router Interface Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The overlapping of IP addressing plans in different client sub-networks connected to the same service provider network leads to inaccurate classification of IP flows, making it impossible for monitoring systems to reliably identify the source or destination site of IP addresses, resulting in cumulative and misallocated flow data.

Innovation Solution

The method involves associating each site with a router interface and using source and destination interface information to correctly classify IP flows, employing additional ranking criteria beyond conventional IP addresses, with geographical and application repositories to distinguish between overlapping IP addressing plans, and utilizing the NetFlow protocol to collect accounting elements from Provider Edge routers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If IP addresses are used to identify entities and sites in the monitoring system, then the system can generate volumetric statistics and flow matrices, but when IP addressing plans overlap between different clients, the classification accuracy deteriorates and entities cannot be reliably distinguished

Engineering Contradiction:
Improveflow analysis capabilityVSAvoidentity identification accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces interface identification as an additional dimension beyond IP addresses. Each interface is assigned a unique identifier that serves as a new classification dimension, allowing the system to distinguish between overlapping IP addresses from different clients. This dimensional extension transforms the classification space from single-dimensional (IP address only) to multi-dimensional (IP address + interface ID), resolving the ambiguity caused by overlapping addressing plans.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces interface identifiers as intermediary elements between IP addresses and entity identification. These interface IDs act as mediators that bridge the gap between overlapping IP addresses and their true sources. The monitoring system uses these intermediary identifiers to correctly attribute flows to the appropriate entities and sites, even when multiple entities share the same IP address space.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If the monitoring system collects detailed accounting information from all routers, then comprehensive statistics can be generated, but the complexity of managing and correlating this data across multiple clients with overlapping IP plans increases

Engineering Contradiction:
Improveaccounting information completenessVSAvoiddata correlation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the network monitoring function by introducing interface-level identification. Instead of attempting to correlate all IP addresses across the entire network, the system segments the classification task by associating each interface with specific client sites. This segmentation allows the monitoring system to process and correlate accounting information in smaller, manageable units (interface-specific flows) rather than attempting to handle the entire network's IP space as a single complex entity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making interface identification specific to each router and site. Rather than using a global IP addressing scheme that must be unique across the entire network, the system allows each interface to have its own local identification context. This local quality approach enables accurate classification at each interface level while maintaining overall network-wide monitoring capability.

Inventive Principle:
Principle #3Local quality

3Ease of manufacture

If conventional NetFlow collection is used without interface information, then implementation is simple, but the ability to accurately classify flows by site and entity is lost

Engineering Contradiction:
Improvesystem implementation simplicityVSAvoidflow classification reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring interface identifiers on router interfaces before traffic monitoring begins. The interface identification infrastructure is established in advance, with each interface assigned a unique identifier that will be used for subsequent flow classification. This preliminary setup ensures that when accounting information is collected, the interface identification data is already available, eliminating the need for complex real-time correlation algorithms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent makes the interface identification mechanism universal across the entire network. The same interface identification approach can be applied to any router and any interface, making the solution scalable and adaptable to different network configurations. This universal approach maintains implementation simplicity while improving classification reliability, as the same basic mechanism works consistently across all network elements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8929229B2Method allowing a monitoring system of the network of an operator to classify IP flows
Publication Date: 2015.01.06 EKINOPS FRANCE
  • US8929229B2 patent drawing
  • US8929229B2 patent drawing

AI summary

A method is provided for allowing a monitoring system to classify, by entity, IP “accounting” elements passing through routers of a network of a service provider, these entities being arranged in different sites connected to the network. The method includes:each site is associated with an interface of a router to which that site is connected, andduring analysis by the monitoring system of an accounting element originating from a router, information relating to the source interface and destination interface contained in this accounting element is used in order to identify the source and destination sites and to classify this accounting element with respect to the correct source or destination entity.