SDN Detection Policy Generation for Automated IFIT Path Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing traffic detection technologies, particularly in-band detection methods like IFIT, struggle with low detection efficiency due to the inability to automatically configure detection policies, leading to inefficiencies in identifying network anomalies and faults.

Innovation Solution

A method for generating detection policies using a software-defined network (SDN) controller that obtains path information to automatically configure policies for network devices, enabling efficient detection by determining the forwarding path of packets and generating policies based on this information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If in-band detection (IFIT) is used to achieve precise network performance detection, then measurement precision is improved, but detection efficiency deteriorates due to inability to automatically configure detection policies

Engineering Contradiction:
Improvenetwork performance detection precisionVSAvoiddetection efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

An SDN controller is introduced as an intermediary between the detection system and network devices. The controller automatically generates detection policies based on path information and configures them on relevant network devices, enabling automated detection without manual intervention while maintaining the precision of in-band detection methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-calculating detection policies and configuring them on network devices before actual detection is needed. The SDN controller proactively obtains path information and prepares detection configurations in advance, so when detection is required, the policies are already in place and can be executed immediately, improving detection efficiency.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manual configuration of detection policies is performed, then detection accuracy is maintained, but loss of time increases due to manual setup requirements

Engineering Contradiction:
Improvedetection accuracyVSAvoidpolicy configuration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The SDN controller implements self-service by automatically generating detection policies based on obtained path information and autonomously configuring them on the appropriate network devices. This eliminates the need for manual policy configuration while maintaining detection accuracy, as the controller intelligently determines the necessary detection parameters and applies them systematically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of configuring detection policies is replaced with an automated control system. The SDN controller uses software-based automation to substitute the manual configuration process, obtaining path information programmatically and deploying detection policies through automated device management interfaces, thereby eliminating time-consuming manual operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated detection policy generation is implemented, then productivity is improved, but device complexity increases due to SDN controller integration

Engineering Contradiction:
Improvedetection efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The SDN controller performs multiple functions: it obtains path information from the network, generates appropriate detection policies based on that information, and configures the policies on relevant network devices. By consolidating these diverse functions into a single multi-functional controller, the system achieves automated detection without proportionally increasing overall complexity, as one component handles multiple tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12483490B2Method for generating detection policy, device, and system
Publication Date: 2025.11.25 HUAWEI TECH CO LTD
  • US12483490B2 patent drawing
  • US12483490B2 patent drawing
  • US12483490B2 patent drawing

AI summary

This application relates to methods, devices, and systems for generating a detection policy. An example method can be applied to a controller. In the example method, the controller obtains path information, where the path information includes information about a first network device, and the first network device belongs to a network device through which a packet passes from a source end to a destination end. The controller generates a detection policy for a second network device based on the path information and delivers the detection policy to the second network device, where the second network device is the same as or different from the first network device.