Network Traffic Flow Inspection via Segmented Micro-Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional routing algorithms in data networks face performance concerns due to the high computational resources required for intrusion detection and other network services, leading to increased latency and decreased bandwidth.

Innovation Solution

A system that dynamically applies network resources to traffic flows based on heuristics and policy conditions, initially inspecting a small portion of the data flow with limited resources and escalating to more detailed inspections only if necessary, thereby optimizing resource allocation and reducing latency and costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network services perform complex operations to detect attack patterns, then security detection capability is improved, but latency increases and bandwidth decreases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments traffic flows into multiple micro-flows and processes them at different inspection levels. Routine micro-flows are handled quickly with minimal inspection, while suspicious micro-flows are subjected to more detailed analysis. This segmentation allows security detection to be applied selectively, improving overall latency while maintaining detection capability for suspicious traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial inspection to the majority of traffic flows by examining only packet headers or sampling a subset of packets, rather than performing full deep packet inspection on all traffic. This partial action approach maintains acceptable security detection for routine traffic while significantly reducing processing time and latency.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If network services perform complex operations to detect attack patterns, then security detection capability is improved, but network resources are consumed

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent divides traffic into micro-flows and applies different resource allocation strategies to different segments. Most micro-flows receive minimal resource allocation for rapid processing, while only suspicious micro-flows trigger full resource-intensive inspection. This segmentation dramatically reduces overall computational resource consumption while maintaining security detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent dynamically changes inspection parameters such as packet sampling rates, inspection depth, and resource allocation based on traffic characteristics and security policies. By adjusting these parameters adaptively, the system optimizes resource usage by applying intensive inspection only when necessary, rather than consuming maximum resources for all traffic.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If full inspection is applied to all traffic flows, then security detection capability is improved, but productivity decreases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments traffic flows into micro-flows and applies differentiated inspection policies to different segments. High-volume routine traffic is processed through optimized fast-path mechanisms with minimal inspection, while low-volume suspicious traffic receives thorough inspection. This segmentation maintains high network throughput for legitimate traffic while ensuring security detection for suspicious flows.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial inspection (examining only packet headers or sampling packets) to the majority of traffic flows rather than performing full deep packet inspection on all traffic. This partial action approach maintains network throughput and productivity by quickly processing routine traffic while still providing security detection capabilities.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10291534B2Incremental application of resources to network traffic flows based on heuristics and business policies
Publication Date: 2019.05.14 LEVEL 3 COMMUNICATIONS LLC
  • US10291534B2 patent drawing
  • US10291534B2 patent drawing
  • US10291534B2 patent drawing

AI summary

Disclosed herein are system, method, and computer program product embodiments for increasingly applying network resources to traffic flows based on heuristics and policy conditions. A network determines that a traffic flow satisfies a first condition and transmits a first portion of the traffic flow to a network service. A network service then inspects the first portion of the traffic flow at a first level of detail and determines that the traffic flow satisfies a second condition. The network can then transmit a second portion of the traffic flow to the network service based on the determining the traffic flow satisfies the second condition. The network service can inspect the second portion of the traffic flow at a second level of detail, wherein the inspecting at the second level of detail requires a different amount of computing resources than the inspecting at the first level of detail.