基于有限状态机的多引擎分析平台流量编排
Finite State Machine-Based Traffic Orchestration for Multi-Engine Analysis Platforms
AI总结:
提出基于复合有限状态机的流量编排方法,将多引擎联合需求建模为笛卡尔积状态空间,运行时简化为查找,并支持时间衰减与多层级输出,实现引擎无关、可扩展的声明式编排。
AI中文摘要:
现代应用安全平台将来自单一代理的实时流量路由到多个独立分析引擎——包括行为异常检测、认证分析、资源发现、访问控制检查等。每个引擎对流量的需求按自身计划变化,但代理对每个资源只能执行一个转发指令。我们提出一种流量编排方法,将所有引擎的联合需求建模为单个复合有限状态机(FSM),其状态空间是各引擎状态的笛卡尔积。每个可达的复合状态预映射到一个转发配置,因此运行时简化为查找而非协商。我们增加两项改进:将基于时间的过期作为一流的FSM转换处理,实现声明式流量衰减;以及每状态多层级输出,使一台机器可服务所有服务级别。该设计完全声明式、引擎无关,并可扩展到N个引擎而无需重新架构。
英文摘要:
Modern application-security platforms route live traffic from a single proxy into several independent analysis engines -- behavioral anomaly detection, authentication analysis, resource discovery, access-control inspection, among others. Each engine's appetite for traffic changes on its own schedule, yet the proxy can honor only one forwarding instruction per resource. We present a traffic-orchestration method that models the combined needs of all engines as a single composite finite state machine (FSM) whose state space is the Cartesian product of per-engine states. Every reachable composite state pre-maps to one forwarding configuration, so runtime reduces to a lookup rather than a negotiation. We add two refinements: time-based expiry treated as a first-class FSM transition enabling declarative traffic decay, and per-state multi-tier outputs that let one machine serve every service level. The design is fully declarative, engine-agnostic, and scales to N engines without re-architecture.