Network Proxy Auto Discovery via Traffic Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in detecting and monitoring network proxies, particularly in data center 'east-west' traffic flows, as they often lack explicit knowledge of proxy devices, making it difficult to diagnose issues and maintain service performance.

Innovation Solution

A controller in a computer network correlates Transmission Control Protocol/Internet Protocol (TCP/IP) information and transaction identifiers from source and destination devices to determine the presence and type of proxy devices, using agents to capture and generate signatures for packets, allowing for auto discovery of proxies without explicit communication with them.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proxy devices are deployed to balance traffic between application nodes, then service performance and traffic distribution are improved, but network visibility and detection capability are worsened

Engineering Contradiction:
Improveservice performanceVSAvoidproxy detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an application intelligence platform as an intermediary system that collects, correlates, and analyzes data from multiple sources (agents, network devices, logs) to detect and monitor proxy devices. This mediator enables visibility into proxy operations without requiring direct access to the proxy devices themselves, resolving the contradiction between deploying proxies for performance and maintaining detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by continuously collecting data from network traffic, application logs, and agent-reported information, then using this feedback to identify proxy device presence and behavior. The platform correlates this feedback data to determine whether traffic is flowing directly or through proxies, enabling ongoing detection and monitoring of proxy operations.

Inventive Principle:
Principle #23Feedback

2Loss of information

If data is collected from disparate systems and tools, then monitoring coverage is improved, but data correlation and analysis complexity are worsened

Engineering Contradiction:
Improvemonitoring coverageVSAvoiddata correlation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges multiple data collection mechanisms into a unified application intelligence platform that consolidates information from network devices, application agents, and log sources. This single platform correlates and analyzes all collected data together, reducing the complexity that would arise from managing multiple separate tools and systems while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The application intelligence platform performs multiple functions including data collection, correlation, analysis, and proxy detection within a single system. This multi-functional approach eliminates the need for separate specialized tools for each function, reducing overall system complexity while maintaining broad monitoring capabilities across different data sources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11522765B2Auto discovery of network proxies
Publication Date: 2022.12.06 CISCO TECHNOLOGY INC
  • US11522765B2 patent drawing
  • US11522765B2 patent drawing
  • US11522765B2 patent drawing

AI summary

According to one or more embodiments of the disclosure, techniques herein provide for auto discovery of network proxies. In particular, in one embodiment, a controller in a computer network receives, from both source devices and destination devices, corresponding Transmission Control Protocol/Internet Protocol (TCP/IP) information and associated transaction identifiers (IDs) for packets sent by the source devices and for packets received at the destination devices. The controller may then correlate particular source TCP/IP information to particular destination TCP/IP information based on associated transaction IDs being the same, and can compare the correlated source TCP/IP information and destination TCP/IP information in order to determine whether a proxy device exists (e.g., and which particular type of proxy device exists) between the source device and the destination device.