Network Traffic Processing Agent for Bandwidth and Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contemporary networks face challenges from 'chatty' and bandwidth-intensive applications, which consume significant resources and can inadvertently or maliciously interfere with other applications, leading to performance degradation, availability issues, and security concerns.
Innovation Solution
A processing agent enforces policies by determining whether data can be communicated between sources and destinations, reducing redundant traffic by using identifiers instead of content, and detecting malware and fraud signatures to prevent malicious traffic, thereby isolating applications and reducing bandwidth costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data traffic is allowed to flow freely between applications, then network bandwidth utilization is improved, but network security and application isolation deteriorate
Solution Approach 1:
The patent introduces a processing agent as an intermediary component that sits between applications and the network infrastructure. This agent intercepts data packets, applies policy rules, and determines whether traffic should be allowed or blocked. The processing agent acts as a mediator that enables selective communication - allowing legitimate traffic to flow freely while blocking malicious or unauthorized traffic, thus maintaining both bandwidth utilization and application isolation.
2Loss of information
If all data traffic is transmitted in full, then data completeness is improved, but network bandwidth consumption and transmission time worsen
Solution Approach 1:
The patent extracts and transmits only the essential identifying features of data packets rather than the complete data content. The processing agent analyzes packets and extracts key identifiers, metadata, and control information that are sufficient for routing and processing purposes. This extraction approach maintains data completeness for legitimate communications while significantly reducing bandwidth consumption by eliminating redundant data transmission.
3Reliability
If security scanning and policy enforcement are performed on all traffic, then network security is improved, but processing time and computational resources worsen
Solution Approach 1:
The patent implements preliminary action by pre-configuring policy rules, communication groups, and allow/deny lists before traffic processing begins. The processing agent uses these pre-established rules to make rapid decisions about packet filtering and routing. This preliminary preparation eliminates the need for complex real-time analysis of each packet, significantly reducing processing time while maintaining security through pre-defined policy enforcement.
Data Source
AI summary
Aspects of the subject disclosure are directed towards protecting machines, such as virtual machines in a cloud datacenter, from receiving unwanted traffic, and also reducing bandwidth by eliminating redundant data transmissions. In one aspect, an agent intercepts packets from a source, and determines whether the destination is allowed to receive packets from the source, based upon a communication group membership. The agent also may drop packets based upon malware/fraud signatures. The agent also attempts to reduce bandwidth by replacing redundant content with identifiers (e.g., hashcodes), which a destination machine uses to rebuild the original content. A destination-side agent may perform the same or similar communication group membership and malware/fraud signature filtering operations, and reassemble redundancy-reduced content from received identifiers as needed.


