Network Traffic Management Service Chain Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network traffic management systems are ineffective in classifying flows for server-speaks-first protocols and encrypted communications, as they rely on initial client messages and do not dynamically adjust service chains based on feedback from services within the chain.
Innovation Solution
A network traffic management system that identifies services by inspecting messages from servers, modifies service chains accordingly, and steers traffic based on these classifications, even for protocols like SMTP and TLS, allowing for dynamic adjustment based on contextual information and service feedback.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If flow classification is based on initial client message, then classification can be established quickly, but it fails for server-speaks-first protocols and encrypted communications
Solution Approach 1:
Instead of classifying flows based on client-initiated messages, the patent inspects server-sent messages to determine flow classification. This inversion allows the system to correctly identify flows for server-speaks-first protocols where the server initiates communication before the client can provide classification information.
Solution Approach 2:
The patent performs preliminary inspection of server messages to establish flow classification before the full service chain is activated. By examining early server messages (such as TLS handshakes or SMTP greetings), the system pre-determines the appropriate service chain to apply, ensuring correct routing from the outset.
2Productivity
If service chains are static, then system complexity is reduced, but the system cannot optimize processing based on service feedback
Solution Approach 1:
The patent implements dynamic service chains that can be modified based on feedback from services within the chain. Services can signal the need for additional processing or routing adjustments, causing the service chain to adapt in real-time. This allows optimization of network traffic processing while maintaining manageable complexity through event-driven modifications rather than complete reconfiguration.
Solution Approach 2:
The system incorporates feedback mechanisms where services within the service chain communicate their processing needs and status back to the traffic management device. This feedback loop enables the system to dynamically adjust service chain composition and routing decisions, optimizing processing efficiency based on actual service performance and traffic characteristics.
3Measurement precision
If inspection is performed on encrypted traffic, then protocol identification can be achieved, but it requires decrypting TLS communications
Solution Approach 1:
The patent performs partial inspection of encrypted traffic by examining only the portions of TLS handshakes that are visible without full decryption, such as Server Hello messages containing protocol indicators. This partial action approach achieves sufficient protocol identification accuracy without requiring the complex operation of complete TLS decryption, balancing inspection effectiveness with system complexity.
Data Source
AI summary
Methods, non-transitory computer readable media, network traffic management apparatuses, and network traffic management systems that identify a first service based on inspection of a message received from a server. The message is associated with a flow between a client and the server. The first service is incorporated in, or removed from a service chain associated with the flow. The message, or other received network traffic associated with the flow, is then steered according to the service chain. With this technology, network traffic can advantageously be processed and steered according to services within a service chain that more accurately reflect the communications occurring within particular flows with this technology. In particular, service chains for flows can advantageously be established or modified to account for server-speaks-first protocols, as well as protocols that may be used inside secure or encrypted connections.


