Traffic Broker Routing Packets Through In-Line Tools

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring and security systems require multiple deployments of in-line tools across a computer network to increase visibility, which is expensive and difficult to scale and manage, as the sequence of tools through which packets are processed depends on physical connections and reconfiguration is burdensome.

Innovation Solution

An in-line traffic broker is used to guide network traffic through specified sequences of one or more in-line tools via a configurable switching fabric, translating user-defined flow-to-tool sequences into packet dispatch schemes for individual ports at a network switch appliance, allowing flexible routing without reconfiguring physical connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple in-line tools are serially connected to process network traffic, then network security and monitoring effectiveness are improved, but device complexity and difficulty of reconfiguration increase

Engineering Contradiction:
Improvenetwork securityVSAvoidphysical connection configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A traffic broker is introduced as an intermediary device that receives network traffic and dynamically routes it through sequences of in-line tools based on configurable policies. The traffic broker includes a rule store containing flow-to-tool sequence mappings and a packet switch that implements the routing decisions, eliminating the need for manual physical reconfiguration of tool connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables dynamic reconfiguration of tool processing sequences through software-based packet dispatch schemes. The packet switch can be programmatically controlled to change routing paths without physical intervention, allowing the network security architecture to adapt dynamically to changing threats and requirements.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple editions of the same tool are deployed across the network to increase visibility, then network monitoring effectiveness is improved, but cost and difficulty of scaling increase

Engineering Contradiction:
Improvenetwork monitoring effectivenessVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The traffic broker serves multiple functions: it routes traffic through different tool sequences based on flow characteristics, manages rule stores for various packet dispatch schemes, and controls packet switching operations. This single multi-functional device replaces the need for multiple specialized tool deployments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple in-line tools are consolidated and connected to a single traffic broker instead of being distributed across the network. The broker combines their processing capabilities into a unified architecture, reducing the number of devices needed and simplifying management while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #5Merging (Combining)

3Speed

If in-line tools are deployed to process packets in real-time, then response time to security threats is improved, but system complexity and management burden increase

Engineering Contradiction:
Improveresponse time to threatsVSAvoidsystem management
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

Flow-to-tool sequence rules are pre-configured in the rule store before actual traffic processing begins. The packet switch is pre-programmed with packet dispatch schemes that map traffic flows to appropriate tool sequences, enabling immediate real-time processing without complex runtime decision-making or manual intervention.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10986039B2Traffic broker for routing data packets through sequences of in-line tools
Publication Date: 2021.04.20 GIGAMON INC
  • US10986039B2 patent drawing
  • US10986039B2 patent drawing
  • US10986039B2 patent drawing

AI summary

Embodiments are disclosed for a network switch appliance with a traffic broker that facilitates routing of network traffic between pairs of end nodes on a computer network through a configurable sequence of in-line tools.