A METHOD FOR OBTAINING NETWORK INFORMATION REGARDING A PHYSICAL NETWORK PORT THAT IS REMOVED FROM THE CONTROL OF THE OPERATING SYSTEM KERNEL AND CONTROLLED BY AN APPLICATION IN USER SPACE

EA054647B1Active Publication Date: 2026-09-23OBSHCHESTVO S OGRANICHENNOI OTVETSTVENNOSTIU TEKHARGOS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EA202593532
Authority / Receiving Office
EA · EA
Patent Type
Patents
Current Assignee / Owner
Priority Date
2025-08-22
Filing Date
2025-12-29
Publication Date
2026-09-23
Estimated Expiration
2045-12-29

Smart Images

  • Figure 00000008_0000
    Figure 00000008_0000
  • Figure 00000008_0001
    Figure 00000008_0001
  • Figure 00000009_0000
    Figure 00000009_0000
Patent Text Reader

Abstract

This group of inventions pertains to computing, and more specifically to technologies for managing and processing network traffic in high-performance systems, such as next-generation firewalls (NGFWs), intrusion prevention systems (IPS), and other deep packet inspection (DPI) devices. The essence of this group of inventions lies in a method for obtaining network information regarding a physical network port, removed from the control of the operating system kernel and managed by an application in user space and the system implementing it. The technical result, which this group of inventions aims to achieve, consists of increasing control flexibility and expanding the functionality of high-performance network packet processing systems.
Need to check novelty before this filing date? Find Prior Art

Claims

1. A method for obtaining network information regarding a physical network port that is removed from the control of the operating system kernel and controlled by an application in user space, comprising: creation of a virtual network interface using the operating system kernel; performing mirroring of at least incoming network packets from said physical network port to said virtual network interface; processing network packets received on a virtual network interface to obtain network information.

2. The method according to paragraph 1, during the execution of which a TAP interface is created as a virtual network interface.

3. The method according to paragraph 1 or 2, in which mirroring is performed for both incoming and outgoing network packets of the physical network port.

4. The method according to claim 1, in which mirroring is carried out by means of the said application running in user space, which processes network packets received from the physical network port and sends copies of them to the virtual network interface.

5. The method according to claim 1, wherein the physical network port is removed from the control of the operating system kernel using a set of libraries and drivers for fast packet processing, such as DPDK (Data Plane Development Kit).

6. The method according to claim 1, wherein the processing of network packets includes at least one of the operations from the group consisting of: analyzing information about a virtual local area network (VLAN) tag, adding a VLAN tag, changing a VLAN tag, and deleting a VLAN tag.

7. The method according to claim 1, which additionally involves creating and storing in shared memory a data structure that establishes a correspondence between the identifier of the physical network port, the identifier of the virtual network interface created for it, and at least one logical interface identifier used for routing.

8. A system for network information according to claim 1, comprising at least one physical network port, a processor and memory associated therewith, wherein the processor is configured to: control of a physical network port by an application in user space, which takes the port out of the control of the operating system kernel; creation of a virtual network interface using the operating system kernel; performing mirroring of at least incoming network packets from said physical network port to said virtual network interface; processing network packets received on a virtual network interface to obtain network information.

9. The system according to claim 8, characterized in that the processor is configured to create a TAP interface as a virtual network interface.

10. The system according to claim 8 or 9, characterized in that the processor is configured to perform mirroring for both incoming and outgoing network packets of the physical network port.

11. The system of claim 8, wherein the processor is configured to perform mirroring by executing instructions of said application in user space that reads network packets from a physical network port and sends copies of them to a virtual network interface.

12. The system of claim 8, wherein said user-space application uses a set of libraries and drivers for fast packet processing, such as DPDK (Data Plane Development Kit), to remove the physical network port from the control of the operating system kernel.

13. The system according to claim 8, characterized in that the processor is configured to process network packets, including at least one of the operations from the group consisting of: analyzing information about a virtual local area network (VLAN) tag, adding a VLAN tag, changing a VLAN tag, deleting a VLAN tag.

14. The system according to claim 8, characterized in that it further comprises a shared memory, and the processor is configured to create and store in this shared memory a data structure that establishes a correspondence between the identifier of the physical network port, the identifier of the virtual network interface created for it, and at least one logical identifier of the interface used for routing.