SD-WAN Traffic Classification for Unknown-Application Link Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SD-WAN systems struggle to assign traffic flows for unknown applications to optimal network links, leading to sub-optimal user experiences and inefficient resource utilization due to the lack of predefined Service-Level Agreement (SLA) parameters.

Innovation Solution

The SD-WAN appliance evaluates traffic characteristics to categorize unknown applications into classes based on known application quality of experience (QoE) metrics, predicts SLA parameters, and assigns traffic to links that meet these predicted requirements, using machine learning algorithms to auto-provision SLA rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the SD-WAN appliance assigns traffic flows for unknown applications to a default link, then the system operation is simple, but the user experience and resource utilization become sub-optimal

Engineering Contradiction:
Improvesimplicity of traffic assignmentVSAvoidresource utilization efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system enables unknown applications to self-categorize by analyzing their own traffic characteristics (packet size, inter-arrival time, traffic patterns). The application classification engine automatically evaluates these characteristics and assigns the application to appropriate classes without manual intervention, allowing the system to serve itself in classifying new applications.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-establishes multiple application classes with defined quality profiles and SLA parameters before unknown applications arrive. When an unknown application's traffic is analyzed, it is immediately matched against these pre-defined classes, enabling rapid classification and link assignment without waiting for manual configuration or extensive analysis.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the SD-WAN appliance categorizes unknown applications into classes and predicts SLA parameters, then the user experience improves, but the system complexity increases

Engineering Contradiction:
Improveuser experience qualityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the classification process into distinct components: traffic characteristic analysis (packet size, inter-arrival time, patterns), application class categorization, SLA parameter prediction, and link assignment. Each component handles a specific aspect of the classification task, making the overall complex system manageable through modular organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The application classification engine acts as an intermediary between unknown applications and the SD-WAN link assignment system. It receives raw traffic flows, analyzes characteristics, predicts SLA parameters, and outputs classified application identities with quality profiles. This intermediary layer shields the rest of the system from the complexity of analyzing unknown applications while ensuring reliable classification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If the SD-WAN appliance uses machine learning algorithms to auto-provision SLA rules, then the adaptability to unknown applications improves, but the processing time and computational resources increase

Engineering Contradiction:
Improveability to handle unknown applicationsVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system applies machine learning algorithms selectively rather than to all traffic. It focuses computational resources on analyzing characteristics of unknown applications that require classification, while known applications follow standard assignment procedures. This partial application of complex algorithms minimizes processing time while maintaining adaptability where needed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system pre-trains machine learning models with traffic characteristic data from known applications before deployment. This preliminary training enables the models to rapidly classify unknown applications by comparing their traffic patterns against pre-established benchmarks, reducing real-time processing requirements while maintaining high adaptability.

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If the SD-WAN appliance assigns all unknown application traffic to a single default link, then the device complexity is low, but the network performance and QoE metrics deteriorate

Engineering Contradiction:
Improvecomplexity of traffic managementVSAvoidnetwork performance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Instead of applying a uniform default link assignment to all unknown applications, the system analyzes the specific traffic characteristics of each unknown application and assigns it to a link optimized for that application's quality requirements. Each application receives localized, tailored treatment based on its specific needs rather than generic default handling.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts link assignment for unknown applications based on real-time traffic characteristic analysis. Rather than static default routing, the classification engine continuously evaluates packet size, inter-arrival time, and traffic patterns to determine the most appropriate link, enabling adaptive response to varying application requirements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3709573B1Satisfying service level agreement metrics for unknown applications
Publication Date: 2025.09.10 JUNIPER NETWORKS INC
  • EP3709573B1 patent drawingFigure 1
  • EP3709573B1 patent drawingFigure 2
  • EP3709573B1 patent drawingFigure 3

AI summary

In general, the disclosure describes techniques for assigning traffic originating from an unknown application to a link based on known application quality of experience metrics. For instance, a network device may receive an application data packet of a data flow for an application and determine an application signature of the application data packet. The network device may determine whether the application signature matches an entry in an application signature database, and if the application signature does not match, the network device may identify a class of the application based on one or more characteristics of the application data packet. The network device may then assign the application data packet of the data flow to a first link of a plurality of links based on the class of the application and quality of experience (QoE) metrics for each link.