Network Proxy Auto Discovery via Traffic Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems face challenges in detecting and monitoring network proxies, particularly in data center 'east-west' traffic flows, as they often lack explicit knowledge of proxy devices, making it difficult to diagnose issues and maintain service performance.
Innovation Solution
A controller in a computer network correlates Transmission Control Protocol/Internet Protocol (TCP/IP) information and transaction identifiers from source and destination devices to determine the presence and type of proxy devices, using agents to capture and generate signatures for packets, allowing for auto discovery of proxies without explicit communication with them.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proxy devices are deployed to balance traffic between application nodes, then service performance and traffic distribution are improved, but network visibility and detection capability are worsened
Solution Approach 1:
The patent introduces an application intelligence platform as an intermediary system that collects, correlates, and analyzes data from multiple sources (agents, network devices, logs) to detect and monitor proxy devices. This mediator enables visibility into proxy operations without requiring direct access to the proxy devices themselves, resolving the contradiction between deploying proxies for performance and maintaining detection capability.
Solution Approach 2:
The system implements feedback mechanisms by continuously collecting data from network traffic, application logs, and agent-reported information, then using this feedback to identify proxy device presence and behavior. The platform correlates this feedback data to determine whether traffic is flowing directly or through proxies, enabling ongoing detection and monitoring of proxy operations.
2Loss of information
If data is collected from disparate systems and tools, then monitoring coverage is improved, but data correlation and analysis complexity are worsened
Solution Approach 1:
The patent merges multiple data collection mechanisms into a unified application intelligence platform that consolidates information from network devices, application agents, and log sources. This single platform correlates and analyzes all collected data together, reducing the complexity that would arise from managing multiple separate tools and systems while maintaining comprehensive monitoring coverage.
Solution Approach 2:
The application intelligence platform performs multiple functions including data collection, correlation, analysis, and proxy detection within a single system. This multi-functional approach eliminates the need for separate specialized tools for each function, reducing overall system complexity while maintaining broad monitoring capabilities across different data sources.
Data Source
AI summary
According to one or more embodiments of the disclosure, techniques herein provide for auto discovery of network proxies. In particular, in one embodiment, a controller in a computer network receives, from both source devices and destination devices, corresponding Transmission Control Protocol/Internet Protocol (TCP/IP) information and associated transaction identifiers (IDs) for packets sent by the source devices and for packets received at the destination devices. The controller may then correlate particular source TCP/IP information to particular destination TCP/IP information based on associated transaction IDs being the same, and can compare the correlated source TCP/IP information and destination TCP/IP information in order to determine whether a proxy device exists (e.g., and which particular type of proxy device exists) between the source device and the destination device.


