Two-Stage Flow Aggregation for Scalable Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security devices face scalability issues with increased network traffic and struggle to maintain up-to-date event statistics in distributed systems, leading to inefficient policy enforcement and stale flow information.

Innovation Solution

A network security device with a network flow statistics processing engine implementing a two-stage aggregation scheme, including per-flow and per-destination data export, using threshold-based and timer-based mechanisms to ensure timely and efficient reporting of flow information across varying flow rates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a centralized control scheme is used where one processor is designated as the management processor and incoming data packets are broadcast to all processors, then the security device can implement complex security policies with coordinated processing, but the device cannot scale to handle increased numbers of data packets efficiently

Engineering Contradiction:
Improvecapability to implement complex security policiesVSAvoidhandling capacity for increased data packets
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent divides the security device into multiple independent processing clusters, each capable of autonomously handling data packets. This segmentation eliminates the single point of control bottleneck while maintaining the ability to implement complex security policies through coordinated inter-cluster communication. Each cluster processes packets independently, enabling scalable handling of increased traffic volumes.

Inventive Principle:
Principle #1Segmentation

2Productivity

If the security device is implemented as a distributed system to improve scalability, then the device can handle increased data packets, but maintaining up-to-date event statistics becomes challenging

Engineering Contradiction:
Improvehandling capacity for increased data packetsVSAvoidaccuracy of event statistics
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where each processing cluster continuously reports flow information and event statistics to a centralized aggregation component. This feedback loop ensures that despite the distributed architecture, the system maintains accurate and up-to-date event statistics by collecting and correlating data from all clusters, enabling reliable security policy enforcement.

Inventive Principle:
Principle #23Feedback

3Productivity

If firewalls maintain event statistics using counters updated rapidly to examine network traffic in real-time, then the device can effectively enforce security policies, but maintaining these statistics becomes challenging in distributed systems

Engineering Contradiction:
Improvereal-time traffic examination capabilityVSAvoiddifficulty of maintaining event statistics
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the event statistics maintenance function into a centralized aggregation component that consolidates counter data from all distributed processing clusters. This approach maintains real-time traffic examination capability by rapidly collecting counter updates from multiple clusters while simplifying statistics maintenance through centralized processing, reducing the complexity associated with distributed counter synchronization.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If a monolithic device architecture is used with multiple processors, then the device can implement coordinated security processing, but the architecture does not scale to handle increased network traffic

Engineering Contradiction:
Improvecoordinated security processing capabilityVSAvoidscalability for increased network traffic
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent transitions from a single-dimensional monolithic processor architecture to a multi-dimensional distributed cluster architecture. Each cluster operates as an independent processing unit, and the system achieves coordinated security processing through inter-cluster communication protocols. This dimensional change from centralized to distributed architecture enables the system to scale horizontally to handle increased network traffic while maintaining security policy coordination.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9906495B2Network device implementing two-stage flow information aggregation
Publication Date: 2018.02.27 PALO ALTO NETWORKS INC
  • US9906495B2 patent drawing
  • US9906495B2 patent drawing
  • US9906495B2 patent drawing

AI summary

A network security device includes a network flow statistics processing engine to process network flow information related to network flows. The network flow statistics processing engine includes a first processing stage performing per-flow information aggregation and a second processing stage performing per-destination system component information aggregation, with each processing stage implementing a threshold-based data export scheme and a timer-based data export scheme. In this manner, up-to-date flow information is available to peer system components regardless of the varying flow rates of the network flow.