Network-Edge Traffic Filtering with Application Recognition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing traffic filtering technologies, such as the BGP FlowSpec, are inadequate for filtering complex and refined network and application-layer abnormal traffic at the network edge, failing to meet the requirements of modern communication networks.
Innovation Solution
A traffic filtering method and apparatus that utilizes a network edge node or service analysis component to obtain and execute filtering rules, incorporating flexible rule scaling, diverse filtering conditions and actions, and scheduling policies, with support for data sources and real-time adjustments through a rule engine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing traffic filtering technologies such as BGP FlowSpec are used, then network-layer abnormal traffic can be filtered out at the network edge, but application-layer abnormal traffic cannot be effectively filtered, failing to meet refined service requirements
Solution Approach 1:
The patent segments the filtering function into separate network-layer filtering (using BGP FlowSpec) and application-layer filtering (using application recognition technology). This allows each layer to be optimized independently, with network-layer filtering handling basic abnormal traffic and application-layer filtering providing refined service protection, thereby resolving the limitation of existing technologies that can only handle network-layer filtering.
Solution Approach 2:
The patent creates a universal filtering system that can handle multiple filtering scenarios simultaneously - network-layer abnormal traffic filtering, application-layer abnormal traffic filtering, and refined service filtering. The system integrates both FlowSpec for network-layer control and application recognition for higher-layer filtering, making it adaptable to diverse filtering requirements without requiring separate systems for each function.
2Measurement precision
If complex filtering rules are implemented to meet refined service requirements, then filtering accuracy improves, but device complexity and implementation difficulty increase
Solution Approach 1:
The patent introduces an application recognition technology as an intermediary component that simplifies the filtering rule implementation. Instead of requiring complex direct filtering rules for application-layer traffic, the system uses application recognition to identify application types and then applies corresponding filtering actions. This intermediary layer reduces the complexity of rule formulation while maintaining high filtering accuracy for refined services.
Solution Approach 2:
The patent replaces complex mechanical filtering rule processing with a more elegant application recognition mechanism. Rather than implementing complex pattern matching and decision trees for each filtering scenario, the system uses application recognition to automatically identify traffic characteristics and apply appropriate filtering actions, thereby reducing implementation complexity while improving filtering precision.
3Ease of manufacture
If the rule engine is deployed inside the network edge node, then filtering execution is simple, but the computing capability requirement of the network edge node increases
Solution Approach 1:
The patent makes the rule engine deployment dynamic and flexible, allowing it to be deployed either inside or outside the network edge node based on specific service requirements. When deployed inside, it provides simple execution but requires higher computing capability; when deployed outside, it reduces node capability requirements but adds deployment complexity. The system can dynamically choose the optimal deployment mode, resolving the contradiction between simplicity and capability requirements.
Data Source
AI summary
A traffic filtering method includes a network edge node that provides a cloud service that receives target traffic; obtains a filtering rule, where the filtering rule is for filtering, based on a filtering action, target traffic that meets a filtering condition; invokes a rule engine to parse and execute the filtering rule, where the rule engine is deployed in the network edge node or in a network edge processing system connected to the network edge node; and obtains filtered target traffic based on an execution result, where the filtered target traffic is traffic that meets a filtering requirement corresponding to the filtering rule. The target traffic filtered according to the filtering rule includes at least one of traffic sent by a network side to a user terminal and traffic sent by the user terminal to the network side.


