SD-WAN Policy Controller Service Detection Using IP Singularity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SD-WAN systems face challenges in accurately distinguishing between services sharing the same TCP/UDP port or IP address, leading to inefficiencies and resource consumption issues, particularly with overlapping IP address ranges and botnet-related problems.
Innovation Solution
A network policy controller maintains an Internet Service Database (ISDB) that stores multiple Internet services with corresponding protocols, port numbers, and IP address ranges, using singularity levels to accurately identify services by matching IP addresses within overlapping ranges, thereby controlling network traffic effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If IP address range is used to reduce the number of entries in ISDB, then device memory usage is reduced, but service detection accuracy deteriorates due to overlapping IP ranges
Solution Approach 1:
The patent segments IP address ranges by assigning different singularity levels to different range granularities. Large IP ranges (e.g., /8, /16) are assigned lower singularity levels while smaller IP ranges (e.g., /24, /28) are assigned higher singularity levels. This segmentation allows the system to maintain a manageable number of ISDB entries while preserving the ability to distinguish between services with overlapping IP ranges through hierarchical differentiation.
Solution Approach 2:
The patent applies local quality by assigning different singularity levels to different IP address ranges based on their specificity. Instead of treating all IP ranges uniformly, the system assigns higher singularity levels to more specific ranges (smaller prefixes) and lower singularity levels to broader ranges. This allows the ISDB to maintain accuracy for specific services while using broader ranges for less critical or more generic services, thereby reducing overall entry count.
2Measurement precision
If IPS is introduced to improve service detection accuracy, then service identification precision is improved, but network throughput deteriorates due to high resource consumption
Solution Approach 1:
The patent introduces singularity levels as an intermediary mechanism between traditional port-based identification and full IPS analysis. This intermediary layer allows the system to make intelligent service identification decisions without performing resource-intensive IPS deep inspection for all traffic. By using singularity levels to pre-classify IP ranges and their associated services, the system can efficiently route traffic without requiring full application-layer inspection for commonly identified services.
3Productivity
If single port or IP address matching is used, then network throughput is maintained, but service detection accuracy deteriorates due to inability to distinguish services sharing same port/IP
Solution Approach 1:
The patent adds a new dimension to service identification by introducing singularity levels as a hierarchical classification layer. Instead of relying solely on flat port-number or IP-address matching, the system incorporates the dimension of IP range specificity through singularity levels. This dimensional enhancement allows the system to distinguish between services that share the same port or IP address by examining the singularity level and hierarchical relationship between IP ranges, thereby improving accuracy without sacrificing throughput.
Data Source
AI summary
Systems and methods for detecting Internet services by a network policy controller are provided. According to one embodiment, a network controller maintains an Internet service database (ISDB) in which multiple Internet services and corresponding protocols, port numbers, Internet Protocol (IP) address ranges and singularity levels of the IP ranges are stored. The network policy controller intercepts network traffic and detects the Internet service of the network traffic. If an IP address of the network traffic falls in an IP range with highest singularity level and the protocol type, port number of the network traffic are matched in the ISDB, the corresponding Internet service is identified as the Internet service of the network traffic. The network policy controller further controls transmission of the network traffic based on the Internet service.


