Network Appliance Packet Classification Using Flow State Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for regulating traffic in computer networks are limited to operating at either low OSI layers (L2-L4), which are simple but unintelligent, or high layers (L7), which are costly and inefficient, and require rigid, inflexible rules that are difficult to modify without compromising network integrity.

Innovation Solution

A network appliance that classifies packets using OSI Layer 2-Layer 4 information and state information to enforce policies, allowing for intelligent selection of traffic to process at higher layers, reducing unnecessary processing and maintaining flow state information for efficient decision-making.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If packet filters operate at low OSI layers (L2-L4), then processing speed is improved, but intelligence and ability to understand traffic content deteriorates

Engineering Contradiction:
Improvepacket processing speedVSAvoidtraffic content understanding capability
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent segments packet filtering into two distinct stages: L2-L4 filtering for high-speed packet classification and routing decisions, and L7 filtering for intelligent content inspection. This segmentation allows each layer to operate at its optimal speed while maintaining the ability to understand traffic content when needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces flow state information as an intermediary that bridges L2-L4 packet filtering and L7 content inspection. Flow state tables store classification results from lower layers, enabling L7 filters to make intelligent decisions based on pre-classified traffic flows without re-inspecting every packet at lower layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If stateful firewalls maintain connection state information, then packet processing efficiency is improved, but device complexity increases

Engineering Contradiction:
Improvepacket processing efficiencyVSAvoidstate table management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The flow state information structure serves multiple functions simultaneously: it tracks connection state for efficiency, stores classification results for L7 filtering, and enables policy-based routing decisions. This multi-functionality reduces the need for separate data structures and reduces overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If L7 filtering is applied to all traffic, then content control accuracy is improved, but processing overhead and cost increase

Engineering Contradiction:
Improvecontent control accuracyVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies L7 filtering selectively only to traffic flows that require content inspection, rather than applying it to all traffic. Flow state information identifies which flows need L7 processing, allowing the system to perform partial L7 filtering only where necessary, reducing overall processing overhead while maintaining accuracy for controlled traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8639837B2System and method of traffic inspection and classification for purposes of implementing session ND content control
Publication Date: 2014.01.28 CA TECH INC
  • US8639837B2 patent drawing
  • US8639837B2 patent drawing
  • US8639837B2 patent drawing

AI summary

Packets received at a network appliance are classified according to a packet classification rules based on flow state information maintained by the network appliance and evaluated for each packet as it is received at the appliance on the basis of OSI Level 2-Level 4 (L2-L4) information retrieved from the packet. The received packets are acted upon according to outcomes of the classification; and the flow state information is updated according to actions taken on the received packets. The updated flow state information is then made available to modules performing additional processing of one or more of the packets at OSI Layer 7 (L7).