Finite State Machine-Based Traffic Orchestration for Multi-Engine Analysis Platforms
Software Engineering
Summary
The gist is being written…
Authors
Ankit Kumar, Thirumoorthi Thangamani
Abstract
Modern application-security platforms route live traffic from a single proxy into several independent analysis engines -- behavioral anomaly detection, authentication analysis, resource discovery, access-control inspection, among others. Each engine's appetite for traffic changes on its own schedule, yet the proxy can honor only one forwarding instruction per resource. We present a traffic-orchestration method that models the combined needs of all engines as a single composite finite state machine (FSM) whose state space is the Cartesian product of per-engine states. Every reachable composite state pre-maps to one forwarding configuration, so runtime reduces to a lookup rather than a negotiation. We add two refinements: time-based expiry treated as a first-class FSM transition enabling declarative traffic decay, and per-state multi-tier outputs that let one machine serve every service level. The design is fully declarative, engine-agnostic, and scales to N engines without re-architecture.