Network Traffic Control via Application Path Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls face inefficiencies in managing network traffic policies, as communication protocol-based policies often block entire communication protocols, leading to resource wastage and inability to access applications due to the need for numerous individual policies for each application protocol, causing unwanted dropping of network traffic.

Innovation Solution

Implementing an application protocol-based policy that allows or denies network traffic based on specific communication protocols within an application path, using truncation identifiers to represent multiple communication or application protocols, reducing the need for individual policies and conserving resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If communication protocol-based policies are used to block network traffic, then security control is simplified, but entire communication protocols are blocked leading to resource wastage and inability to access applications

Engineering Contradiction:
Improvepolicy management simplicityVSAvoidapplication accessibility
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent segments the policy control granularity from protocol level to application path level. Instead of blocking entire communication protocols, the system identifies and controls specific application paths (e.g., HTTPS, FTP, SMTP) within the protocol stack, allowing selective blocking of only the problematic application paths while permitting other paths to function normally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by differentiating control actions at different levels of the protocol stack. The system identifies specific application layer paths and applies blocking policies only to those local paths rather than uniformly across the entire communication protocol, enabling fine-grained control that preserves application accessibility where needed.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If numerous individual policies are created for each application protocol, then precise control is achieved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvetraffic control precisionVSAvoidnumber of policies
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a single application path identification mechanism that serves multiple functions: protocol detection, policy selection, and traffic control. The system uses a unified approach to identify application paths across different protocols (HTTPS, FTP, SMTP, etc.) and applies consistent policy evaluation logic, eliminating the need for separate individual policies for each protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the controlling parameter from protocol type to application path. Instead of managing policies based on protocol identifiers (which require numerous individual policies), the system uses application path parameters (e.g., specific URL paths, message formats) as the basis for policy selection, significantly reducing the number of required policies while maintaining precise control.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If communication protocol-based blocking is implemented, then security enforcement is simplified, but unwanted network traffic is dropped

Engineering Contradiction:
Improvesecurity enforcement simplicityVSAvoidnetwork traffic delivery
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces dynamics by making the blocking decision adaptive rather than static. The system dynamically identifies application paths in real-time based on the actual traffic characteristics and applies blocking policies only when the identified path matches problematic patterns. This dynamic approach prevents unwanted traffic drops by allowing legitimate traffic to pass through even when protocol-based blocking would have blocked it.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3751790B1Network traffic control based on application path
Publication Date: 2024.10.30 JUNIPER NETWORKS INC
  • EP3751790B1 patent drawingFigure 1
  • EP3751790B1 patent drawingFigure 2
  • EP3751790B1 patent drawingFigure 3

AI summary

A network device may receive network traffic associated with a session, wherein the session is associated with a network. The network device may determine, from the network traffic, an application path that is associated with the session, wherein the application path is associated with a communication protocol and an application protocol. The network device may determine, based on policy information that is associated with the application path, whether the network traffic associated with the session is capable of being communicated via the network using the communication protocol and the application protocol. The network device may perform, based on whether the network traffic is determined to be capable of being communicated, an action associated with enabling or preventing communication of the network traffic.