Traffic Broker Routing Packets Through In-Line Tools
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring and security systems require multiple deployments of in-line tools across a computer network to increase visibility, which is expensive and difficult to scale and manage, as the sequence of tools through which packets are processed depends on physical connections and reconfiguration is burdensome.
Innovation Solution
An in-line traffic broker is used to guide network traffic through specified sequences of one or more in-line tools via a configurable switching fabric, translating user-defined flow-to-tool sequences into packet dispatch schemes for individual ports at a network switch appliance, allowing flexible routing without reconfiguring physical connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple in-line tools are serially connected to process network traffic, then network security and monitoring effectiveness are improved, but device complexity and difficulty of reconfiguration increase
Solution Approach 1:
A traffic broker is introduced as an intermediary device that receives network traffic and dynamically routes it through sequences of in-line tools based on configurable policies. The traffic broker includes a rule store containing flow-to-tool sequence mappings and a packet switch that implements the routing decisions, eliminating the need for manual physical reconfiguration of tool connections.
Solution Approach 2:
The system enables dynamic reconfiguration of tool processing sequences through software-based packet dispatch schemes. The packet switch can be programmatically controlled to change routing paths without physical intervention, allowing the network security architecture to adapt dynamically to changing threats and requirements.
2Reliability
If multiple editions of the same tool are deployed across the network to increase visibility, then network monitoring effectiveness is improved, but cost and difficulty of scaling increase
Solution Approach 1:
The traffic broker serves multiple functions: it routes traffic through different tool sequences based on flow characteristics, manages rule stores for various packet dispatch schemes, and controls packet switching operations. This single multi-functional device replaces the need for multiple specialized tool deployments.
Solution Approach 2:
Multiple in-line tools are consolidated and connected to a single traffic broker instead of being distributed across the network. The broker combines their processing capabilities into a unified architecture, reducing the number of devices needed and simplifying management while maintaining comprehensive monitoring coverage.
3Speed
If in-line tools are deployed to process packets in real-time, then response time to security threats is improved, but system complexity and management burden increase
Solution Approach 1:
Flow-to-tool sequence rules are pre-configured in the rule store before actual traffic processing begins. The packet switch is pre-programmed with packet dispatch schemes that map traffic flows to appropriate tool sequences, enabling immediate real-time processing without complex runtime decision-making or manual intervention.
Data Source
AI summary
Embodiments are disclosed for a network switch appliance with a traffic broker that facilitates routing of network traffic between pairs of end nodes on a computer network through a configurable sequence of in-line tools.


