Network Configuration Apparatus for Automated Traffic Barrier Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Middleboxes in computer networks often block legitimate traffic, hindering software development and deployment by requiring network engineers' assistance, which is time-consuming and costly, especially in large networks with complex infrastructures.
Innovation Solution
A network configuration apparatus that identifies potential barriers in the network path, evaluates traffic requests, and automatically generates change requests to network administrators to allow blocked traffic, reducing the need for manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If middleboxes are configured to block unwanted traffic for network security, then network security is improved, but legitimate traffic may be blocked and software deployment is hindered
Solution Approach 1:
The patent introduces an automated traffic analysis system that acts as an intermediary between software developers and network administrators. This system automatically analyzes traffic patterns, identifies legitimate traffic that should be allowed, and generates configuration changes for middleboxes, eliminating the need for manual intervention while maintaining security policies.
Solution Approach 2:
The system enables self-service by allowing software developers to automatically have their traffic requirements evaluated and approved without needing to contact network engineers. The automated analysis system evaluates traffic requests against security policies and automatically generates the necessary middlebox configuration changes, making the process self-serveing for developers.
2Ease of operation
If network engineers manually investigate network configurations to resolve traffic blockages, then traffic issues can be resolved, but the process is time-consuming and costly
Solution Approach 1:
The patent replaces the mechanical system of manual network engineering investigation with an automated computational system. The automated traffic analysis system uses algorithms to analyze network configurations, evaluate traffic requests, and generate configuration changes, substituting human manual processes with automated mechanical/computational processes that are faster and more consistent.
Solution Approach 2:
The system performs preliminary action by automatically pre-evaluating traffic requests against network security policies before deployment. The automated analysis system proactively identifies and resolves potential traffic blockages before they become issues, generating configuration changes in advance rather than reacting to problems after they occur.
3Reliability
If developers lack access rights to inspect network configuration data, then network security is maintained, but investigating traffic blockages becomes impossible
Solution Approach 1:
The automated traffic analysis system serves as an intermediary that developers can access without needing direct access to sensitive network configuration data. The system accepts traffic requests from developers, automatically analyzes them against security policies, and returns results without exposing developers to restricted configuration information, thus maintaining security while enabling investigation.
Data Source
AI summary
A network configuration apparatus includes a user interface module configured to receive a traffic request from a user. The traffic request includes a source and a destination for desired traffic. A barrier identification module obtains network data indicating a set of networking devices present in a route between the source and the destination. For each of the devices, the barrier identification module determines whether the device may block traffic from reaching the destination and, if so, adds the device to a set of potential barriers. A route analysis module, for each device of the potential barriers, flags the device if it will block the desired traffic. The user interface module, in response to there being at least one flagged device, transmits an alert that the traffic request is a failure; and, in response to there being zero flagged devices, transmits an alert that the traffic request is a success.


