SD-WAN Flow Metadata Exchange for Security Consistency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In SD-WAN environments, the inefficient use of computing resources and inconsistent security monitoring occur due to the duplication of meta data determination processes for flow identification, such as App ID, User ID, and Content ID, at both SD-WAN devices and cloud-based security services.
Innovation Solution
Implementing a system that exchanges flow meta data between network and security functions, where meta data determined at one location is communicated to the other, thereby reducing redundant computations and ensuring consistent meta data across both SD-WAN devices and cloud-based security services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If meta data determination processes are duplicated at both SD-WAN devices and cloud-based security services, then each function can independently identify flows, but computing resources are wasted and performance deteriorates
Solution Approach 1:
The patent introduces an intermediary mechanism where the SD-WAN device determines flow meta data (App ID, User ID, Content ID) and communicates this information to the cloud-based security service. This mediator approach eliminates the need for the security service to independently determine the same meta data, reducing redundant computations while maintaining consistent identification across both systems.
Solution Approach 2:
The SD-WAN device performs the meta data determination process in advance before traffic reaches the cloud-based security service. By completing this preliminary action at the edge device, the system avoids repeating the same computational process at the cloud service, thereby reducing overall resource consumption while ensuring consistent flow identification.
2Reliability
If meta data determination is performed at both SD-WAN devices and cloud-based security services, then each system has complete flow identification capability, but system scalability is limited due to redundant processing
Solution Approach 1:
The patent establishes the SD-WAN device as an intermediary that determines flow meta data and communicates it to the cloud-based security service. This intermediary architecture allows the security service to leverage the meta data from the SD-WAN device without performing redundant determination, thereby enhancing system scalability while maintaining consistent security monitoring.
Solution Approach 2:
The patent merges the meta data determination function into a single location (the SD-WAN device) and has the cloud-based security service utilize this shared information. This consolidation eliminates redundant processing across the system, improving scalability while ensuring that both systems maintain consistent flow identification capabilities through shared meta data.
3Ease of operation
If flow meta data is determined independently at each system, then each system can autonomously identify flows, but computing efficiency decreases due to redundant calculations
Solution Approach 1:
The patent introduces the SD-WAN device as an intermediary that autonomously determines flow meta data and shares this information with the cloud-based security service. This approach maintains the autonomy of each system in identifying flows while eliminating redundant calculations, as the security service utilizes the meta data provided by the SD-WAN device rather than independently determining it.
Solution Approach 2:
The SD-WAN device performs the meta data determination as a preliminary action and communicates the results to the cloud-based security service. This preliminary action maintains the autonomous identification capability of the SD-WAN device while ensuring that the security service does not need to repeat the same computational process, thereby improving overall computing efficiency.
Data Source
AI summary
In some embodiments, a system/process/computer program product for flow metadata exchanges between network and security functions for a security service includes receiving a flow at a software-defined wide area network (SD-WAN) device; analyzing the flow to determine whether the flow is associated with a split tunnel, comprising: extracting meta data information associated with one flow of the flow to determine the meta data information, wherein the meta data information includes one or more of the following: a user identifier, an application identifier, and/or a device identifier; comparing the extracted meta data information with meta data information associated with a predetermined set of users, applications, and devices; and in the event that the extracted meta data information matches the meta data information associated with one or more of the predetermined set of users, applications, and devices, then determining that the one flow is associated with the split tunnel; and monitoring the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service.


