Multi-Access Edge Visibility Network for Selective Packet Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network providers face challenges in improving user experience by optimizing latency and bandwidth efficiency due to varying network conditions and user behaviors, which existing technologies have not adequately addressed.
Innovation Solution
A third-party component at the network edge maintains a rule table to derive network packet characteristics by inspecting data packets, performing deep packet inspection, and providing metadata to external sources for network actions, while also predicting anomalies based on baseline normalcy to enhance network visibility and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is performed to derive network packet characteristics, then network visibility and analytics capability are improved, but processing time and computational resources increase
Solution Approach 1:
The system pre-establishes rule tables with identification patterns and corresponding actions before packets arrive. When a packet is received, the system performs rapid pattern matching against pre-defined rules rather than performing full deep packet inspection on every packet, significantly reducing processing time while maintaining visibility for packets that require detailed analysis.
Solution Approach 2:
The system applies deep packet inspection selectively based on rule matches and packet characteristics. Not all packets undergo full inspection - only those that match specific rules or exhibit anomalous patterns require detailed analysis, allowing the system to maintain high visibility where needed while minimizing unnecessary processing overhead.
2Loss of time
If edge computing is deployed to reduce latency, then user experience is improved, but device complexity and deployment cost increase
Solution Approach 1:
The patent deploys third-party components specifically at the network edge where latency-critical operations occur. These edge components perform local packet inspection, rule matching, and analytics, providing low-latency processing for time-sensitive applications while the core network maintains centralized control and simpler architecture.
Solution Approach 2:
The system segments network functions by deploying independent third-party components at the edge that can be added or removed without affecting the core network infrastructure. This modular approach allows selective deployment of computing resources at the edge for specific use cases while keeping the overall system manageable and cost-effective.
3Productivity
If comprehensive network monitoring is implemented to improve bandwidth efficiency, then network optimization is improved, but data processing load and system complexity increase
Solution Approach 1:
The patent introduces third-party components as intermediaries between network packets and the core network system. These components perform comprehensive monitoring, rule matching, and analytics independently, then provide summarized information to the core network. This intermediary layer enables detailed monitoring without overwhelming the core system with processing load.
Solution Approach 2:
The system extracts and separates monitoring and analytics functions from the core network infrastructure, placing them in independent third-party components at the edge. This extraction allows comprehensive network monitoring to be performed without increasing core system complexity, as the monitoring functions operate autonomously and report results rather than requiring core system involvement in processing.
Data Source
AI summary
Disclosed herein are system, method, and computer program product embodiments for providing traffic visibility in a network. An embodiment operates by a third-party component receiving a copy of a first data packet during a first period of time. The third-party component extracts a first network parameter associated with the first period of time from the copy of the first data packet. The third-party component then predicts a baseline of normalcy for the first network parameter during a second period of time after the first period of time based on data associated with a copy of a second data packet and the first network parameter. Thereafter, the third-party component receives a copy of a third data packet during the second period of time, and extracts a second network parameter from the copy of the third data packet. The third-party component then determines that the second network parameter of the copy of the second data packet is an anomaly based on the baseline of normalcy for the first network parameter.


