Two-Stage Flow Aggregation for Scalable Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security devices face scalability issues with increased network traffic and struggle to maintain up-to-date event statistics in distributed systems, leading to inefficient policy enforcement and stale flow information.
Innovation Solution
A network security device with a network flow statistics processing engine implementing a two-stage aggregation scheme, including per-flow and per-destination data export, using threshold-based and timer-based mechanisms to ensure timely and efficient reporting of flow information across varying flow rates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a centralized control scheme is used where one processor is designated as the management processor and incoming data packets are broadcast to all processors, then the security device can implement complex security policies with coordinated processing, but the device cannot scale to handle increased numbers of data packets efficiently
Solution Approach 1:
The patent divides the security device into multiple independent processing clusters, each capable of autonomously handling data packets. This segmentation eliminates the single point of control bottleneck while maintaining the ability to implement complex security policies through coordinated inter-cluster communication. Each cluster processes packets independently, enabling scalable handling of increased traffic volumes.
2Productivity
If the security device is implemented as a distributed system to improve scalability, then the device can handle increased data packets, but maintaining up-to-date event statistics becomes challenging
Solution Approach 1:
The patent implements a feedback mechanism where each processing cluster continuously reports flow information and event statistics to a centralized aggregation component. This feedback loop ensures that despite the distributed architecture, the system maintains accurate and up-to-date event statistics by collecting and correlating data from all clusters, enabling reliable security policy enforcement.
3Productivity
If firewalls maintain event statistics using counters updated rapidly to examine network traffic in real-time, then the device can effectively enforce security policies, but maintaining these statistics becomes challenging in distributed systems
Solution Approach 1:
The patent merges the event statistics maintenance function into a centralized aggregation component that consolidates counter data from all distributed processing clusters. This approach maintains real-time traffic examination capability by rapidly collecting counter updates from multiple clusters while simplifying statistics maintenance through centralized processing, reducing the complexity associated with distributed counter synchronization.
4Adaptability or versatility
If a monolithic device architecture is used with multiple processors, then the device can implement coordinated security processing, but the architecture does not scale to handle increased network traffic
Solution Approach 1:
The patent transitions from a single-dimensional monolithic processor architecture to a multi-dimensional distributed cluster architecture. Each cluster operates as an independent processing unit, and the system achieves coordinated security processing through inter-cluster communication protocols. This dimensional change from centralized to distributed architecture enables the system to scale horizontally to handle increased network traffic while maintaining security policy coordination.
Data Source
AI summary
A network security device includes a network flow statistics processing engine to process network flow information related to network flows. The network flow statistics processing engine includes a first processing stage performing per-flow information aggregation and a second processing stage performing per-destination system component information aggregation, with each processing stage implementing a threshold-based data export scheme and a timer-based data export scheme. In this manner, up-to-date flow information is available to peer system components regardless of the varying flow rates of the network flow.


