Network Traffic Control via Application Feature Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls and network devices often employ all-or-nothing application-based policies, leading to inefficient use of resources as they either allow or block all network traffic associated with an application, wasting computing and network resources by permitting or preventing traffic that should be allowed or blocked, respectively.

Innovation Solution

Implementing a more granular policy that permits or denies network traffic based on specific application features or feature types, allowing for selective communication management by identifying and applying policies to specific application features or feature types within the network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If all-or-nothing application-based policies are used, then policy implementation is simple, but resource efficiency deteriorates due to unnecessary traffic permission or blocking

Engineering Contradiction:
Improvepolicy implementation complexityVSAvoidcomputing and network resources
Core Design Contradiction:
Device complexityVSLoss of energy

Solution Approach 1:

The patent segments the application traffic control policy into two levels: application-level policies for simple allow/deny decisions, and feature-level policies for granular control within applications. This segmentation resolves the contradiction by maintaining simple overall policy structure while enabling efficient resource management through feature-specific rules that prevent unnecessary traffic processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing feature-specific policies only where needed within applications. Instead of applying uniform all-or-nothing policies to entire applications, the system selectively controls specific features (e.g., chat, file sharing, video conferencing) based on their individual security requirements and resource consumption patterns, thereby improving resource efficiency without excessive complexity.

Inventive Principle:
Principle #3Local quality

2Device complexity

If all-or-nothing application-based policies are used, then device complexity is reduced, but productivity deteriorates due to inefficient traffic handling

Engineering Contradiction:
Improvepolicy structureVSAvoidnetwork traffic handling efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments network traffic control into application-level and feature-level policies. This segmentation improves productivity by enabling selective enforcement of policies on specific application features rather than entire applications, reducing unnecessary traffic processing and improving overall network traffic handling efficiency while maintaining a manageable policy structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic policy enforcement by allowing the system to adaptively apply different policy granularities based on traffic characteristics. The network device can dynamically switch between application-level and feature-level policy evaluation, optimizing productivity by applying more granular control only when beneficial while maintaining simpler policy structures for routine traffic.

Inventive Principle:
Principle #15Dynamics

3Loss of energy

If granular feature-based policies are implemented, then resource efficiency is improved, but device complexity increases

Engineering Contradiction:
Improvecomputing and network resourcesVSAvoidpolicy management complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent adds a new dimension to policy management by introducing feature-level abstraction within applications. This dimensional change resolves the complexity issue by organizing granular policies in a hierarchical structure where features are grouped under parent applications, allowing efficient resource management through feature-specific rules while maintaining manageable complexity through structured policy organization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces an intermediary layer (the feature level) between application-level policies and individual traffic flows. This intermediary simplifies policy management by providing a structured abstraction that groups related traffic characteristics, enabling resource-efficient feature-specific control while reducing the complexity of managing individual traffic flow rules through organized policy hierarchies.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If feature-specific policies are applied, then resource management efficiency is enhanced, but policy lookup complexity increases

Engineering Contradiction:
Improveresource management efficiencyVSAvoidpolicy lookup operation
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-organizing policies in a hierarchical structure with applications as parent nodes and features as child nodes. This preliminary organization resolves the lookup complexity issue by enabling the system to first evaluate application-level policies and only proceed to feature-level policies when necessary, improving resource management efficiency while reducing actual lookup operations through structured policy evaluation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the policy lookup process into two distinct phases: application-level policy evaluation and feature-level policy evaluation. This segmentation improves resource management efficiency by enabling early filtering at the application level, reducing the number of detailed feature-level lookups needed, while maintaining manageable lookup complexity through structured, multi-phase evaluation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11303575B2Network traffic control based on application feature
Publication Date: 2022.04.12 JUNIPER NETWORKS INC
  • US11303575B2 patent drawing
  • US11303575B2 patent drawing
  • US11303575B2 patent drawing

AI summary

A network device may receive network traffic associated with a network and determine that the network traffic is associated with a dynamic application. The network device may determine, based on the network traffic being associated with a dynamic application, an application feature associated with the network traffic. The network device may perform a lookup operation associated with the application feature to identify policy information associated with the application feature. The network device may selectively permit communication of the network traffic via the network based on the policy information associated with the application feature, wherein the network traffic is to be permitted to be communicated via the network or prevented from being communicated via the network based on an indication from the policy information.