Artificial intelligence-supported network telemetry using data processing units

By using AI-enabled telemetry technology between DPU and cloud computing resources, potential DDoS attacks can be identified and addressed, solving the problems of resource intensity and inefficiency in existing technologies and improving the efficiency and availability of cybersecurity detection for small and medium-sized organizations.

CN116264520BActive Publication Date: 2026-05-26MELLANOX TECHNOLOGIES LTD(IL)

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
MELLANOX TECHNOLOGIES LTD(IL)
Filing Date
2022-11-04
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing systems are resource-intensive and inefficient in detecting distributed denial-of-service (DDoS) attacks, especially for small and medium-sized organizations (SMEs), where network security solutions are less efficient and more vulnerable to attacks.

Method used

By employing AI-supported telemetry technology, packet inspection is performed between local network infrastructure and cloud computing resources through DPU and machine learning models to identify potential network attacks. Relevant packets are then routed to cloud computing resources at full line speed via offload paths, reducing false positives and improving detection efficiency.

Benefits of technology

It enables early detection and reduced confusion of DDoS attacks, improves service availability and network scalability, reduces latency and false positive rates, and is suitable for small organizations with limited resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116264520B_ABST
    Figure CN116264520B_ABST
Patent Text Reader

Abstract

This disclosure relates to artificial intelligence-enabled network telemetry using a data processing unit. The device receives packets from a local network. These packets may be directed to cloud computing resources. The device determines that the packet is associated with a new packet flow. In response to determining that the packet is associated with a new packet flow, the device provides one or more packets from the new packet flow to a machine learning model for packet inspection. The device receives the output from the machine learning model and routes the new packet flow based on the output received from the machine learning model. The output indicates whether the new packet flow is associated with a network attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to telemetry in data processing units (DPUs), network interface cards (NICs), and adapters, and in some examples, utilizes artificial intelligence (AI) techniques to perform monitoring operations associated with performance and traffic statistics. Background Technology

[0002] Some systems may support Intrusion Detection System (IDS) technologies associated with Denial-of-Service (DDoS) attacks. In some cases, this technology may include inspecting incoming data traffic related to DDoS attacks. This inspection of data traffic can be resource-intensive. Summary of the Invention

[0003] The technology relates to improved methods, systems, devices, and apparatuses supporting AI-enabled telemetry. Generally, the technology provides AI-enabled telemetry that mitigates the impact of distributed DDoS attacks on networks.

[0004] A method is provided, comprising: receiving packets from a local network. In some aspects, the packets are directed to cloud computing resources; determining that the packets are associated with a new packet flow; in response to determining that the packets are associated with the new packet flow, providing one or more packets from the new packet flow to a machine learning model for packet inspection; receiving the output of the machine learning model; and routing the new packet flow based on the output received from the machine learning model. In some aspects, the output indicates whether the new packet flow is associated with a network attack.

[0005] A machine-readable medium storing data is provided, which, if executed by one or more processors, enables one or more processors to: examine packets directed to cloud computing resources; determine whether the packets are part of a packet stream associated with a cyberattack; and notify the DPU that the packet stream is not associated with a cyberattack, thereby enabling the DPU to process additional packets in the packet stream via an offload path running at full line speed.

[0006] A system is provided comprising: a Data Processing Unit (DPU) located between a cloud computing resource and an on-premises network infrastructure. In some aspects, the DPU is configured to receive packets from the on-premises network infrastructure that are directed to the cloud computing resource. The system includes a machine learning model configured to examine the packets and determine whether the packets are part of a packet flow associated with a cyberattack. In some aspects, the machine learning model is further configured to notify the DPU that the packet flow is not associated with a cyberattack, thereby enabling the DPU to process additional packets in the packet flow via an offloading path that bypasses the machine learning model.

[0007] Examples may include one of the following features, or any combination thereof.

[0008] In some examples of the methods, systems, and machine-readable media described in this paper, the machine learning model is executed by a Layer 7 (L7) processor.

[0009] In some examples of the methods, systems, and machine-readable media described herein, the L7 processor may include at least one of a GPU, a DPU, and a central processing unit (CPU).

[0010] In some examples of the methods, systems, and machine-readable media described herein, the packet may include the first packet in a new packet stream.

[0011] In some examples of the methods, systems, and machine-readable media described herein, one or more packets are encrypted, wherein the machine learning model performs packet checking without decrypting the one or more packets.

[0012] Examples of the methods, systems, and machine-readable media described herein may include providing packets to filtering logic that implements an attack detection rule set. In some aspects, the attack detection rule set is configured to determine which packets are associated with a new packet stream.

[0013] In some examples of the methods, systems, and machine-readable media described in this paper, the filtering logic is implemented at a lower protocol stack layer than the machine learning model.

[0014] In some examples of the methods, systems, and machine-readable media described herein, filtering logic is executed at at least one of the data link layer, network layer, and transport layer. In some respects, the machine learning model is executed at the application layer.

[0015] In some examples of the methods, systems, and machine-readable media described herein, routing a new packet flow may include directing all packets associated with the new packet flow to cloud computing resources via an offloading path.

[0016] In some examples of the methods, systems, and machine-readable media described herein, the offloading path carries packets associated with new packet streams at full line rate.

[0017] Some examples of the methods, systems, and machine-readable media described herein may include evaluating packet headers to determine the encryption and / or decryption requirements associated with the packet.

[0018] In some examples of the methods, systems, and machine-readable media described herein, packets are received at a DPU set up on the NIC.

[0019] In some examples of the methods, systems, and machine-readable media described herein, determining that a packet is associated with a new packet stream may include determining that the packet was received from a tenant who has not previously sent packets to cloud computing resources.

[0020] In some examples of the methods, systems, and machine-readable media described herein, cloud computing resources are shared among multiple tenants. In some aspects, a cyberattack can include at least one of the following: DDoS attack, cipher machine attack, compromised access control, security misconfiguration, injection, phishing attack, malware attack, ransomware attack, cross-site scripting (XSS) attack, sensitive data exposure, information disclosure, cryptojacking, fraudulent email transmission, botnet, malicious insider attack, and social profile engineering attack.

[0021] In some examples of the systems described in this paper, the machine learning models are executed by GPUs that operate at the application layer.

[0022] In some examples of the systems described in this article, the offloading path carries additional packets associated with new packet flows at full line speed.

[0023] In some examples of the systems described in this paper, the packets are provided to a machine learning model in response to the determination that the packets were received from a tenant who has not previously sent packets to cloud computing resources.

[0024] In some examples of the systems described in this paper, the DPU operates at one or more of the data link layer, network layer, and transport layer. In some respects, the machine learning model executes at the application layer. Attached Figure Description

[0025] Figure 1 An example of a system using DPU-enabled AI-enabled network telemetry is shown according to various aspects of this disclosure.

[0026] Figures 2A to 2C An example of a system using DPU-enabled AI-enabled network telemetry is shown according to various aspects of this disclosure.

[0027] Figure 3 An example of a system using DPU-enabled AI-enabled network telemetry is shown according to various aspects of this disclosure.

[0028] Figure 4 An example of a process flow for using DPU-enabled AI-enabled network telemetry according to various aspects of this disclosure is shown. Detailed Implementation

[0029] The following description provides exemplary aspects of this disclosure and is not intended to limit the scope, applicability, or configuration of the claims. Rather, the following description will provide those skilled in the art with an implementation description of the described examples. It is understood that various changes can be made to the function and arrangement of the elements without departing from the spirit and scope of the appended claims. Various aspects of this disclosure will be described with reference to schematic diagrams of an ideal configuration.

[0030] Some organizations (e.g., businesses) may provide digital services (e.g., cloud-based applications, cloud services, etc.) via digital infrastructure. In some cases, relatively small and medium-sized organizations (such as small and medium-sized enterprises (SMEs)) may not own digital infrastructure. In other cases, if an organization does own such digital infrastructure, it may be unable to provide effective security protection for it.

[0031] For example, poor planning, budgeting, and / or deployment in cybersecurity can expose organizations and / or digital infrastructure to a variety of cyber risks (e.g., DDoS attacks, cipher machine attacks, compromised access controls, security misconfigurations, injection attacks, phishing attacks, malware attacks, ransomware attacks, XSS attacks, sensitive data breaches, information leaks, cryptojacking, fraudulent email transmissions, botnets, malicious insider attacks, social profile engineering attacks, etc.). Therefore, providing greater digital freedom, security, privacy, and awareness of such cyber risks can mitigate potential business losses. In some cases, smaller organizations (such as SMEs) with less efficient cybersecurity solutions are more likely to be targeted by cyberattacks compared to larger enterprises.

[0032] Various aspects of this disclosure include technologies that support the provision of cybersecurity solutions for a wide range of systems (e.g., corporate systems), networks, and sensitive information. The technologies described herein can support the protection of organizations from malicious online activities, regardless of industry type, organizational size, and / or business scale. In some examples, the technologies described herein can be applied to small organizations (e.g., SMEs) with limited resources to allocate security solutions. Various aspects of this disclosure can support the provision of the cybersecurity solutions described herein, along with appropriate referral services, to such small organizations. In some respects, the technologies described herein can be relatively easier for small organizations and / or vendors with limited expertise in cybersecurity management to adopt and use (compared to other security technologies).

[0033] Various aspects of this disclosure include examples of specifying and implementing services for supporting network security management over networking infrastructure (e.g., small office networking infrastructure). Example services (e.g., network security management virtual network functions (VNFs), network services (NS), etc.) that can be deployed on programmable networking infrastructure (e.g., relatively easy to deploy compared to some other network security technologies) are described. Non-limiting examples of services (e.g., VNFs, NS, etc.) may include network / network firewalls, IDS, intrusion prevention systems (IPS), security information and incident management (SIEM) systems, honeypots, etc. Some example aspects include implementing software-defined networking (SDN) and network function virtualization (NFV) technologies to design and develop software-based flow management solutions and network services, leveraging the evolving implementations of these capabilities.

[0034] In some cases, various aspects of this disclosure support the market entry of such solutions where repositories of services (e.g., network security management services, VNFs, NSs, etc.) are available for deployment on office infrastructure (e.g., small office networking infrastructure). In some aspects, these services may include edge network security management services.

[0035] Examples of aspects of this disclosure support telemetry technologies that, in addition to supporting device performance analysis and traffic statistics, also support security aspects (e.g., secure traffic), improved user experience, and reduced latency. In some cases, the technologies described herein can be applied to telecommunications (e.g., fourth-generation (4G) telecommunications networks, fifth-generation (5G) telecommunications networks, etc.) and IoT-rich environments. In some aspects, the technologies described herein can be incorporated to provide non-enterprise SMEs with access to telemetry systems, which ensures the protection of SME-related data and operations.

[0036] For example, various aspects of this disclosure support telemetry in a DPU, where the DPU resides between cloud infrastructure and on-premises network infrastructure. The DPU may be standalone or contained within a larger architecture. In some embodiments, the DPU may include a NIC (e.g., a smart NIC), be included within the NIC, or include a NIC subsystem. An SME can make service requests to cloud computing resources (also referred to herein as service providers) included in the cloud infrastructure via the on-premises network infrastructure and the DPU. A machine learning model (also referred to herein as an AI model) included in the DPU (and / or NIC) can analyze (e.g., be provided) the service request to determine whether the service request constitutes a cyberattack. In some aspects, the machine learning model may be implemented at the processor of the DPU (e.g., GPU, CPU, etc.).

[0037] Therefore, for example, a machine learning model can be provided with real-time traffic (e.g., a real-time packet stream), and the machine learning model can determine whether any packets contained in the packet stream are associated with a cyberattack (e.g., a DDoS attack, a cryptographer attack, etc.). In the example, if the machine learning model determines that packets associated with a new packet stream are associated with a cyberattack, the DPU can route (bootstrap) all packets associated with the new packet stream to a cloud computing resource via an offload path (also referred to herein as the offloaded path). Routed packets via the offload path can be carried to the cloud computing resource at full line rate (also referred to herein as peak bit rate, connection speed, useful bit rate, information rate, or digital bandwidth capacity).

[0038] The techniques described in this paper can support improvements in detecting network attacks (e.g., DDoS attacks), such as reducing the number of instances where incoming packets (or incoming packet flows) are obfuscated with network attacks. Other example advantages include balanced early detection of network attacks (e.g., near 100% early detection or 100% early detection), improved service availability (e.g., near 100% service availability or 100% service availability), and improved network scalability by leveraging DPUs (e.g., near 100% scalability or 100% scalability).

[0039] Various aspects of cloud infrastructure and on-premises network infrastructure can be implemented through programmable networking infrastructure, including telemetry. In some examples, programmable networking infrastructure can be implemented using SDN and NFV technologies. In some aspects, programmable networking infrastructure can support software-based flow management (e.g., management of packets associated with different packet flows).

[0040] Example aspects of programmable networking infrastructure can be implemented in a market environment where repositories for network security management VNFs and NSs are available. In one example, the user network associated with the programmable networking infrastructure could support services that connect services associated with on-site users to cloud computing resources (e.g., service providers).

[0041] The techniques described in this paper support intrusion detection that prevents service requests from being mistaken for network attacks (e.g., DDoS attacks) and / or reduces the overall volume of network attacks. Therefore, for example, the techniques described in this paper can reduce the amount of latency associated with actual service requests from third parties. In some cases, these techniques can reduce the likelihood of bottlenecks associated with processing and communicating service requests. These techniques can support the establishment of intrusion detection systems that take into account the continuous creation of new flows with different profiles, and the need to maintain reasonable network availability.

[0042] Various aspects of this disclosure are further illustrated and described with reference to apparatus diagrams, system diagrams, and flowcharts related to AI-supported network telemetry using a DPU.

[0043] Figure 1 An example of a system 100 using DPU-supported AI-supported network telemetry according to various aspects of this disclosure is shown.

[0044] In one example, system 100 may include user network 105 (also referred to herein as on-premises user network, local network, office infrastructure, etc.) and (one or more) cloud infrastructures 160 (e.g., cloud infrastructure 160-a, cloud infrastructure 160-b, etc., also referred to herein as digital infrastructure). In one example, cloud infrastructure 160-a may be referred to as service / application cloud infrastructure. In some respects, via user network 105 and cloud infrastructure 160, an organization (e.g., an enterprise) may provide digital services (e.g., cloud-based applications, cloud services, etc.) to users connected to user network 105. In some respects, digital services may include network security management services, VNFs, NS, etc., as described herein. In some respects, digital services may be deployed on user network 105.

[0045] User network 105 may include DPU 115 and local networking infrastructure 110. In one example, DPU 115 may be connected to local networking infrastructure 110 via communication channel 111 supported by local networking infrastructure 110. In some respects, DPU 115 may be standalone or included in another device. For example, DPU 115 may be (or included in) a NIC. In some respects, the NIC may be a smart NIC capable of supporting accelerated networking functions. A smart NIC may also be referred to herein as a smart server adapter (ISA).

[0046] In the example, DPU 115 can support performance enhancements through network data path processing. In some respects, DPU 115 can be a system-on-a-chip (SoC) device that combines a high-performance and software-programmable multi-core CPU, a high-performance network interface (e.g., network interface 135), and flexible and programmable acceleration engines (e.g., semiconductor acceleration engine 125, acceleration engine 130, etc.). For example, DPU 115 provides a high-performance network interface that can parse, process, and efficiently transmit data at line speed or network speed.

[0047] The DPU 115 may include a telemetry component 120, an acceleration engine (e.g., a semiconductor acceleration engine (125), an acceleration engine (130)), a network interface 135, a GPU 140, a CPU 141, a programmable processing core 145, a PCIe switch 150, and a memory 155.

[0048] Telemetry component 120 can support automated communication processes between DPU 115 and multiple data sources (e.g., cloud computing resources 165, devices 170, etc.). Telemetry component 120 can support monitoring of devices (e.g., cloud infrastructure 160, cloud computing resources 165, devices 170, etc.) and data related to monitoring security, application health, quality, and performance. In some cases, telemetry component 120 can support monitoring of network infrastructure, storage infrastructure, and overall bandwidth capacity and consumption. In some aspects, telemetry component 120 can support cloud monitoring (e.g., metrics regarding cloud availability, internet latency, outages, etc.) and routing decisions (e.g., routing data on and between any of the local networking infrastructure 110, DPU 115, cloud infrastructure 160, cloud computing resources 165, devices 170, etc.).

[0049] Acceleration engines (e.g., semiconductor acceleration engine 125, acceleration engine 130) may include hardware components or electronic circuits designed to perform functions with relatively higher efficiency compared to software programs executed on CPU 141.

[0050] Network interface 135 can support packet communication (e.g., sending and receiving) between DPU 115 and device 170 (e.g., via communication channel 111 and local networking infrastructure 110). In some aspects, network interface 135 can support packet communication between DPU 115 and cloud computing resource 165 (e.g., via communication channel 161 and cloud infrastructure 160). In some aspects, network interface 135 can be a network interface card (NIC).

[0051] GPU 140 can support processing computationally intensive workloads (e.g., artificial intelligence, deep learning, data science, etc.). For example, GPU 140 can support the aspects described herein, such as determining whether a packet (or corresponding packet flow) is associated with a network attack and determining an attack detection rule set for detecting network attacks. Alternatively, CPU 141 (and / or programmable core 145) can implement the aspects described herein regarding determining whether a packet (or corresponding packet flow) is associated with a network attack and determining an attack detection rule set for detecting network attacks.

[0052] Although the programmable core 145 is described as a specific type of programmable processing core, such as a programmable advanced simplified instruction set computer (RISC) machine (ARM) core, it should be understood that any suitable type of processing core or collection of processing cores can be included in the programmable core 145. The programmable core 145 may include multiple programmable processing cores of the same or different types. Furthermore, as the name suggests, the programmable processing cores can be configured to perform different processing tasks without departing from the scope of this disclosure.

[0053] PCIe switch 150 can support switching between buses (e.g., PCIe buses) included in DPU 115. PCIe switch 150 can support packet-based communication protocols and packet routing (e.g., based on memory address, I / O address, device ID, etc.). Alternatively, DPU 115 can include other switch types (e.g., PCI switches) for switching between buses included in DPU 115.

[0054] Memory 155 may include local memory of DPU 115. In some aspects, memory 155 may store instructions and / or data locally of DPU 115. Memory 155 may include one or more computer memory devices. Memory 155 may include, for example, random access memory (RAM) devices, read-only memory (ROM) devices, flash memory devices, disk storage media, optical storage media, solid-state storage devices, core memory, buffer memory devices, combinations thereof, etc. In some examples, memory 155 may correspond to computer-readable storage media. In some aspects, memory 155 may be internal or external to DPU 115.

[0055] Components of the DPU 115, such as telemetry component 120, acceleration engines (e.g., semiconductor acceleration engines 125 and 130), network interface 135, GPU 140, CPU 141, programmable core 145, PCIe switch 150, and memory 155, can be interconnected via the DPU 115's system bus (not shown). The system bus can be, for example, a PCIe bus, a PCI bus, etc. In some respects, the system bus can include or be any high-speed system bus.

[0056] Cloud infrastructure 160 (e.g., cloud infrastructure 160-a, cloud infrastructure 160-b, etc.) can be implemented through any combination of servers and / or databases (not shown). For example, cloud infrastructure 160 can provide cloud computing services (also referred to herein as digital services), such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), Storage as a Service (STaaS), Security as a Service (SECaaS), Data as a Service (DaaS), Desktop as a Service (DaaS), Test Environment as a Service (TEaaS), and Application Programming Interface (API) as a Service (APIaaS).

[0057] In one example, a user can connect to user network 105 via device 170 (also referred to herein as a client device) to access cloud computing resources 165 that provide cloud computing services. For example, device 170 can access cloud computing services from cloud computing resources 165 via user network 105 and cloud infrastructure 160.

[0058] The various aspects of DPU 115, (one or more) cloud infrastructure 160, cloud computing resources 165, and devices 170 can be implemented by any electronic device capable of connecting to a wireless or wired network. In some cases, system 100 may include any number of devices (e.g., DPU 115, cloud computing resources 165, devices 170, etc.) and / or servers (e.g., implementing one or more cloud computing resources 165), and each of the devices and / or servers may be associated with a corresponding entity.

[0059] For example, system 100 can support packet communication between cloud computing resource 1605 and device 170, for example, via user network 105 (e.g., using local networking infrastructure 110, communication channel 111, and DPU 115), communication channel 161, and communication channel 171. In some example aspects, with respect to providing packets directed to cloud computing resource 165, data packets can flow through communication channel 171, local networking infrastructure 110, communication channel 111, telemetry component 120, acceleration engine 130, network interface 135, communication channel 161, and cloud infrastructure 160.

[0060] User network 105 (e.g., local networking infrastructure 110, communication channel 111), communication channel 161, and communication channel 171 can be implemented through any communication network capable of facilitating machine-to-machine communication between entities (e.g., any number of DPUs 115, cloud computing resources 165, devices 170, etc.). For example, the communication network can include any type of known communication medium or collection of communication media, and can use any type of protocol to transmit messages, signals, and / or data between endpoints. In some aspects, the communication network can include wired communication technologies, wireless communication technologies, or any combination thereof. In some examples, the communication network can support both insecure and secure communication channels.

[0061] In some examples, communication channels 111 and 161 may be secure communication channels, while communication channel 171 may be an insecure communication channel. Alternatively, communication channels 111, 161, and 171 may include any combination of secure and insecure communication channels.

[0062] The Internet is an example of a network supported by System 100 (e.g., a communication network implementing aspects of any one of Local Networking Infrastructure 110, Communication Channel 111, Communication Channel 161, and Communication Channel 171), and the network can constitute an Internet Protocol (IP) network consisting of multiple computers, computing networks, and other devices (e.g., DPU 115, cloud computing resources 165, device 170, etc.) located in multiple locations. Other examples of networks supported by System 100 may include, but are not limited to, standard Common Old Telephone Systems (POTS), Integrated Services Digital Network (ISDN), Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Wireless LAN (WLAN), Session Initiation Protocol (SIP) network, Voice over Internet Protocol (VoIP) network, cellular network, and any other type of packet-switched or circuit-switched network known in the art. In some cases, System 100 may include any combination of networks or network types. In some aspects, a network may include any combination of communication media, such as coaxial cable, copper cable / wire, fiber optic cable, or antennas for communicating data (e.g., sending / receiving data).

[0063] System 100 can support intrusion detection. For example, System 100 can support high-bandwidth traffic analysis regarding changes in network patterns. According to an example aspect of this disclosure, DPU 115 can support high-speed packet processing (e.g., line rate), including Layer 2 (L2) to Layer 4 (L4) header parsing and manipulation. In some aspects, DPU 115 can implement filtering logic for DDoS attacks based on this information. For example, DPU 115 can implement filtering logic for identifying network attacks (e.g., DDoS attacks, cipher machine attacks, etc.).

[0064] Figures 2A to 2C An example of a system 200 using a DPU to support AI-enabled network telemetry is shown, according to various aspects of this disclosure. The various aspects of the system 200 described herein may support layer header parsing and manipulation, filtering logic for packet inspection, and machine learning models for packet inspection.

[0065] System 200 may include references Figure 1 Various aspects of the described system 100. For example, Figure 2A and Figure 2B The local network infrastructure 210, DPU 215, and cloud infrastructure 260 are illustrated. The local network infrastructure 210, DPU 215, and cloud infrastructure 260 may include components referenced herein. Figure 1 The various aspects of the similar elements described. Figure 2C The aspects described in this paper that can be implemented by the DPU 215 are shown.

[0066] System 200 can support data exchange between local network infrastructure 210 and DPU 215 via communication path 211. Communication path 211 may include references Figure 1 The various aspects of the described communication channel 111.

[0067] System 200 can support data exchange between DPU 215 and cloud infrastructure 260 via communication path 216 and offloading path 217. For example, system 200 can support DPU 215 and cloud computing resources (e.g., see reference). Figure 1 The described data exchange between cloud computing resources 165) is via communication path 216, offload path 217, and cloud infrastructure 260. Communication path 216 and offload path 217 may include references to... Figure 1 The various aspects of the described communication channel 161.

[0068] The DPU 215 (or a NIC that includes the DPU 215) can support layered architectures of communication protocol stacks. For example, the DPU 215 can support a protocol stack that includes layer 230.

[0069] Layer 230-a (e.g., L2) is a data link layer that supports lower-level addressing structures used between end systems (e.g., connecting nodes). For example, Layer 230-a (e.g., L2) can support node-to-node data transmission between connected nodes, where data is packaged into frames. Layer 230-a (e.g., L2) can be the lowest layer of a protocol stack.

[0070] Layer 230-b (e.g., Layer 3 (L3)) is the network layer responsible for receiving frames from Layer 230-a (e.g., L2) (data link layer) and transmitting the frames to their intended destination based on the addresses contained within the frames.

[0071] Layer 230-c (e.g., L4) is a transport layer that supports the management of data packet delivery and error checking (e.g., packet 220, packet 222, etc.). Layer 230-c (e.g., L4) can support the adjustment of data size, ordering, and transmission.

[0072] Layer 230-d (e.g., Layer 5 (L5), later in...) Figure 2B (As shown in the image) is a session layer that supports terminal devices (e.g., see reference). Figure 1 The establishment, management, and termination of sessions or connections between the device 170 and the cloud computing resource 165. In some aspects, layer 230-d (e.g., L5) may support session layer services such as authentication and reconnection.

[0073] Layer 230-e (e.g., Layer 6 (L6), later in...) Figure 2B Layer 230-f (e.g., L7) is a presentation layer that supports conversion between data formats, for example, based on the syntax and / or semantics accepted by the application implemented in layer 230-f (e.g., L7). In some respects, layer 230-e (e.g., L6) can perform data encryption and decryption.

[0074] Layer 230-f (e.g., L7) is the application layer that supports the implementation of end-user applications (e.g., browser applications, email applications, office applications, etc.). In some cases, layer 230-f (e.g., L7) can be the top layer of the protocol stack.

[0075] Machine learning engine 235 and machine learning model 237 may be implemented at layer 230-f (e.g., L7). Machine learning engine 235 and machine learning model 237 may be executed by a processor (e.g., an L7 processor) at layer 230-f (e.g., L7). In some aspects, the processor (e.g., an L7 processor) may be included in DPU 215 or separate from DPU 215 (e.g., independent). In some aspects, the L7 processor may include a GPU integrated into DPU 215 (e.g., reference...). Figure 1The GPU described is either GPU 140 or a GPU separate from the DPU 215 (e.g., a standalone GPU). In some other examples, the L7 processor may include a CPU (e.g., refer to...). Figure 1 CPU 141 (described).

[0076] For example, the processor of DPU 215 (e.g., GPU 140, CPU 141, etc.) can utilize the memory stored in DPU 115 (e.g., reference memory). Figure 1 The data in the memory 155 described herein is used as a neural network. The neural network may also be referred to herein as a machine learning network. The neural network may include a machine learning architecture. In some respects, the neural network may be or include an artificial neural network (ANN). In some other respects, the neural network may be or include any machine learning network, such as a deep learning network, a convolutional neural network, etc. Some elements stored in the memory may be described or referred to as instructions or instruction sets, and some functions of the DPU 215 may be implemented using machine learning techniques.

[0077] Memory (e.g., memory 155) can be configured to store instruction sets, neural networks, and other data structures (e.g., as described herein) for executing various types of routines or functions, in addition to temporarily storing data for a processor (e.g., GPU 140, CPU 141, etc.). For example, memory can be configured to store program instructions (instruction sets) that can be executed by a processor (e.g., GPU 140, CPU 141, etc.) and provide the functionality of the machine learning engine 235 described herein. Memory can also be configured to store data or information that is available or can be invoked by instructions stored in memory. An example of data that can be stored in memory for use by its components is machine learning model 237 (also referred to herein as a data model or neural network model) and / or training data 238 (also referred to herein as training data and feedback).

[0078] Machine learning engine 235 may include one or more engines. DPU 215 (e.g., using machine learning engine 235) may utilize one or more machine learning models 237 to identify and process data from other devices (e.g., reference models). Figure 1 The information obtained by the described device 170 (server, database, etc.). In some aspects, the DPU 215 (e.g., machine learning engine 235) can update one or more machine learning models 237 based on the learning information contained in the training data 238. In some aspects, the machine learning engine 235 and the machine learning models 237 can support forward learning based on the training data 238. The machine learning engine 235 can access and use one or more machine learning models 237.

[0079] Machine learning model 237 can be built and updated by machine learning engine 235 based on training data 238. Machine learning model 237 can be provided in any number of formats or forms. Non-limiting examples of machine learning model 237 include decision trees, support vector machines (SVMs), nearest neighbor and / or Bayesian classifiers. In some aspects, machine learning model 237 may include predictive models, such as autoregressive models. Other examples of machine learning model 237, such as generating (e.g., building, training) and applying machine learning model 237, are described with reference to the diagrammatic description herein.

[0080] In some respects, training data 238 may include any combination of patterns (e.g., data patterns, signatures, network attack signatures) and / or metadata related to whether detected packets (e.g., packet 220 as described herein) or packet streams (e.g., packet streams 221 or 223 as described herein) are associated with a network attack. Additional example aspects of training data 238 will be described later here.

[0081] refer to Figure 2A System 200 can support L2 and L4 parsing and manipulation of packets 220 (e.g., any one of packets 220-a to 220-n). In some respects, system 200 can support the determination of whether packets 220 (e.g., packets 220-a, 220-b, etc.) are considered part of a network attack (e.g., a DDoS attack, a cipher machine attack, etc.). If packets 220 are considered part of a network attack, system 200 can establish a digital filter. In some examples, the digital filter can be established first in a lower layer of the protocol stack (e.g., layer 230-a (e.g., L2)) and then in a higher layer of the protocol stack (e.g., layer 230-c (e.g., L4)).

[0082] In one example, DPU 215 may receive packet 220-a from local network infrastructure 210. For example, packet 220-a may be the first packet in a packet stream 221 that includes packets 220-a through 220-n. In one example, DPU 215 may determine that packet 220-a is directed to a cloud computing resource associated with cloud infrastructure 260 (e.g., referencing...). Figure 1 The cloud computing resources described in 165). In some respects, the determination may be based on the address indicated by packet 220-a.

[0083] DPU 215 can determine whether packet 220-a is associated with a new packet stream. For example, DPU 215 can determine whether packet 220-a is related to (e.g., reference) Figure 1The described device 170 is associated with a new connection between its communication equipment and the cloud computing resources associated with cloud infrastructure 260. In one example, if DPU 215 determines that packet 220-a comes from a tenant that has not previously sent packets to the cloud computing resources, DPU 215 can determine that packet 220-a is associated with a new packet flow (e.g., determine that packet flow 221 is a new packet flow).

[0084] In the example of determining whether packet 220-a is associated with a new packet stream (e.g., determining that packet stream 221 is a new packet stream), DPU 215 can provide packet 220-a to filtering logic 225. In some respects, filtering logic 225 can be within the acceleration engine of DPU 215 (e.g., reference...). Figure 1 The acceleration engine 225 is implemented at the described location. In some cases, the filtering logic 225 can be implemented by a configurable hardware machine within the DPU 215, and the configurable hardware machine can be able to "bootstrap" the packets or packet streams described herein. In one example, the configurable hardware machine is a full-line-rate machine that supports performing such filtering without losing packets.

[0085] Filtering logic 225 can implement a set of rules configured to determine whether packet 220-a is associated with a new packet flow. In some aspects, filtering logic 225 may include an attack detection rule set for detecting network attacks (e.g., DDoS attacks). In one example, the rule set for determining whether packet 220-a is associated with packet flow 221 and / or the attack detection rule set for detecting network attacks may include a pre-configured rule set.

[0086] Filtering logic 225 can be implemented at layers 230-a (e.g., L2), 230-b (e.g., L3), and 230-c (e.g., L4). In another example, filtering logic 225 can be implemented at any combination of layers 230-a (e.g., L2), 230-b (e.g., L3), and 230-c (e.g., L4). Thus, for example, when packet 220 (e.g., packet 220-a, packet 220-b, etc.) arrives at DPU 215, packet 220 can pass through layer 230-a (e.g., L2) to layer 230-c (e.g., L4).

[0087] In some respects, any combination of layers 230-a (e.g., L2) through 230-c (e.g., L4) may include a set of rules configured to determine whether packet 220 (e.g., packet 220-a) is associated with a new packet flow and a set of attack detection rules for detecting whether packet 220 is associated with a network attack (e.g., a DDoS attack, a cryptographer attack, etc.). For example, the set of rules configured to determine whether packet 220 (e.g., packet 220-a) is associated with a new packet flow may be implemented at any of layers 230-a (e.g., L2) through 230-c (e.g., L4). In another example, the attack detection rule set may be implemented at any of layers 230-a (e.g., L2) through 230-c (e.g., L4).

[0088] DPU 215 can identify whether packet stream 221 (e.g., if identified as a new packet stream) conforms to any attack detection rule set associated with layers 230-a to 230-c. For example, DPU 215 can compare the pattern of packet stream 221 (e.g., data pattern, signature, cyberattack signature, etc.) with patterns of packet streams included in the attack detection rule set. The attack detection rule set may include patterns corresponding to non-malicious packet streams (e.g., data pattern, signature) and patterns corresponding to malicious packet streams (e.g., cyberattack, DDoS attack, etc.). In some respects, signatures may include DDoS signatures, DDoS attack signatures, cryptographer attack signatures, etc.

[0089] In one example, based on this comparison, DPU 215 can determine that the pattern of packet flow 221 matches the pattern associated with a non-malicious packet flow. Therefore, for example, DPU 215 can route all packets 220 associated with packet flow 221 to a cloud computing resource via offload path 217 (e.g., sending all data packets 220 to the cloud computing resource at full line rate). Offload path 217 can support offloading in hardware (e.g., at DPU 215). In some respects, offloading a packet 220 (or multiple packets 220) may be referred to herein as an offload pattern.

[0090] In some alternatives, DPU 215 may route some packets 220 associated with packet stream 221 to a cloud computing resource via communication path 216, and DPU 215 may route the remaining packets 220 to a cloud computing resource via offload path 217. For example, DPU 215 may send packet 220-a to the cloud computing resource via communication path 216 (e.g., sending packet 220-a to the cloud computing resource at less than full line speed), and DPU 215 may route packets 220-b to 220-n to the cloud computing resource via offload path 217 (e.g., sending packets 220-b to 220-n to the cloud computing resource at full line speed).

[0091] In another example, based on this comparison, DPU 215 can determine that the pattern of packet flow 221 matches a pattern associated with malicious packet flows (e.g., network attacks, DDoS attacks, etc.). Therefore, for example, DPU 215 can prevent packets 220 associated with packet flow 221 (e.g., prevent the transmission of data packets 220) from being completely routed to cloud computing resources.

[0092] In some cases, based on comparison, DPU 215 can determine that the pattern of packet flow 221 does not match the pattern of any packet flow included in the attack detection rule set. For example, DPU 215 can determine that the pattern of packet flow 221 does not match the pattern associated with non-malicious packet flows included in the attack detection rule set, and DPU 115 can determine that the pattern of packet flow 221 does not match the pattern associated with malicious packet flows (e.g., network attacks, DDoS attacks, etc.) included in the attack detection rule set. That is, for example, DPU 215 can identify that packet flow 221 does not conform to any attack detection rule set associated with layers 230-a to 230-c.

[0093] Therefore, for example, DPU 215 can forward one or more packets 220 (e.g., any or all of packets 220-a to 220-n) to layer 230-f (e.g., L7) for packet inspection. For example, DPU 215 can provide one or more packets 220 from packet flow 221 to machine learning model 237 (implemented at layer 230-f (e.g., L7)) for packet inspection. Using machine learning model 237, DPU 215 (e.g., machine learning engine 235) can inspect packets 220 (e.g., packets 220-a, packets 220-b, etc.) to determine whether packet flow 221 (e.g., identified as a new packet flow) is associated with a network attack (e.g., a DDoS attack, a cryptographer attack, etc.).

[0094] DPU 215 (e.g., machine learning engine 235, using machine learning model 237) can use a rule database associated with network attack detection to provide enhanced L7-based network attack (e.g., DDoS attacks, cryptographer attacks, etc.) detection. For example, using the rule database, DPU 215 (e.g., machine learning engine 235, using machine learning model 240) can identify whether packet flow 221 is associated with a network attack. In some cases, DPU 215 (e.g., machine learning engine 235) can extract patterns corresponding to packet flow 221.

[0095] In some respects, the rule database may include application-layer-related rules for feature extraction corresponding to layer 230-f (e.g., L7). For example, application-layer-related rules may include rules for L7 feature extraction.

[0096] In some respects, the extracted pattern may include features (e.g., signature) that indicate whether packet flow 221 is malicious (e.g., associated with a cyberattack). The extracted pattern may include, for example, an indication that packet flow 221 is a new packet flow for which associated attributes are to be extracted. In one example, the extracted pattern may include features such as source (e.g., device 170, etc.), destination (e.g., cloud computing resource 165, etc.), application identifier, etc. An example of the extracted pattern is provided in the case where DPU 215 (e.g., machine learning engine 235) determines that packet flow 221 is malicious or non-malicious.

[0097] In the first example, DPU 215 (e.g., machine learning engine 235) can identify that packet stream 221 is associated with a network attack (e.g., DDoS attack, cryptographer attack, etc.), and DPU 215 (e.g., machine learning engine 235) can extract a pattern corresponding to packet stream 221. In some aspects, this pattern may include features indicating that packet stream 221 is associated with a network attack. For example, the pattern may include a signature (e.g., DDoS signature, DDoS attack signature, cryptographer attack signature, etc.) that indicates that packet stream 221 is associated with a network attack. Therefore, for example, DPU 215 (e.g., machine learning engine 235) can identify whether packet stream 221 includes a network attack signature (e.g., DDoS signature, DDoS attack signature, cryptographer attack signature, etc.) to determine whether packet stream 221 is a network attack. Figure 2B An example of a machine learning engine 235 that identifies network attack signatures at layer 230-f (e.g., L7) is shown.

[0098] In the second example, DPU 215 (e.g., machine learning engine 235) can identify that packet stream 221 is not associated with a network attack (e.g., a DDoS attack, a cryptographer attack, etc.), and DPU 215 (e.g., machine learning engine 235) can extract a pattern corresponding to packet stream 221. In some aspects, this pattern may include features indicating that packet stream 221 is not associated with a network attack. For example, the pattern may include a signature indicating that packet stream 221 is not associated with a network attack.

[0099] DPU 215 (e.g., machine learning engine 235) can forward extracted patterns (e.g., signatures) to layers 230-a (e.g., L2) to 230-c (e.g., L4). In one example, DPU 215 can add extracted patterns (e.g., signatures) to existing filters and the attack detection rule set implemented in filtering logic 225, thereby updating (e.g., increasing) the total number of attack detection rules implemented in filtering logic 225. Figure 2B Feedback 236 (e.g., feedback 236-a, feedback 236-b, feedback 236-c) shows an example of forwarding the extracted pattern (e.g., signature) to layer 230-a (e.g., L2) to layer 230-c (e.g., L4).

[0100] In some respects, DPU 215 (e.g., machine learning engine 235) can generate and provide additional filtering logic to filtering logic 225. For example, DPU 215 (e.g., machine learning engine 235) can provide additional filtering logic to any of layers 230-a (e.g., L2) through layers 230-c (e.g., L4). In some cases, the filtering logic may include extracted patterns, extracted network attack signatures, and / or a generated set of attack detection rules, such as those determined by machine learning engine 235, for blocking incoming packets (e.g., packets associated with a network attack). Figure 2C An example of a DPU 215 using a machine learning engine 235 (e.g., in layer 230-f (e.g., L7)) to generate and provide filtering logic to filtering logic 225 (e.g., any one of layers 230-a (e.g., L2) to 230-c (e.g., L4)).

[0101] Therefore, if DPU 215 receives a packet associated with a subsequent new packet stream (e.g., different from packet stream 221), DPU 215 can use an updated set of attack detection rules to determine whether the pattern of the subsequent new packet stream matches the pattern associated with a malicious packet stream (e.g., the pattern corresponding to packet stream 221 in the first example) or a non-malicious packet stream (e.g., the pattern corresponding to packet stream 221 in the second example).

[0102] In one example, DPU 215 may receive subsequent packets 222-a from local network infrastructure 210. For example, packet 222-a may be the first packet in a packet stream 223 that includes packets 222-a through 222-n. In one example, DPU 215 may determine that packet 222-a is directed to cloud computing resources of cloud infrastructure 260.

[0103] DPU 215 can determine whether packet 222-a is associated with a new packet stream. In one example, DPU 215 can determine that packet stream 223 is a new packet stream. In response to determining that packet stream 223 is a new packet stream, DPU 215 can provide packet 222-a to filtering logic 225.

[0104] The first example described here illustrates an example aspect where packet flow 221 has been identified as being associated with a cyberattack (e.g., a DDoS attack, a cryptographer attack, etc.). If DPU 215 determines that the pattern of packet flow 223 matches the pattern associated with packet flow 221, then DPU 215 can also consider packet flow 223 to be malicious (e.g., a cyberattack). For example, using layers 230-a (e.g., L2) to 230-c (e.g., L4), DPU 215 can determine that the pattern of packet flow 223 matches the pattern of packet flow 221 contained in an updated set of attack detection rules. That is, for example, DPU 215 can determine that the characteristics of packet flow 223 (e.g., pattern, cyberattack signature) match the characteristics of packet flow 221 (e.g., pattern, cyberattack signature). Therefore, for example, DPU 215 can prevent the complete routing of packet 222 associated with packet flow 223 to cloud computing resources (e.g., prevent the transmission of packet 222).

[0105] An alternative aspect of the second example described above is presented here, where packet flow 221 has been identified as not associated with a network attack. If DPU 215 determines that the pattern of packet flow 223 matches the pattern associated with packet flow 221, DPU 215 can consider packet flow 223 to be non-malicious. For example, using layers 230-a (e.g., L2) to 230-c (e.g., L4), DPU 215 can determine that the pattern (e.g., signature, characteristics) of packet flow 223 matches the pattern (e.g., signature characteristics) of packet flow 221 included in an updated set of attack detection rules. Therefore, for example, DPU 215 can route packets 222 associated with packet flow 223 (e.g., packets 222-a to packets 222-2-n, or packets 222-b to packets 222-n) to cloud computing resources via offload path 217.

[0106] Therefore, for example, system 200 can use data path 231, data path 232, and communication path 216 (e.g., Figure 2A As shown in the diagram, system 200 can support processing unknown packet streams (e.g., packet streams with corresponding patterns not included in the attack detection rule set). System 200 can use data path 231 in combination with communication path 216 and offload path 217 (as shown in the diagram) to support processing packets of unknown patterns (e.g., packet streams with corresponding patterns not included in the attack detection rule set). Figure 2A (As shown) to support the processing of packets from known packet flows (e.g., packet flows with corresponding patterns contained in the attack detection rule set).

[0107] Reference Figure 2B and Figure 2C This article describes the various aspects of System 200's support for packet inspection regarding encryption, decryption, and connection tracking.

[0108] Each packet 220 (e.g., packet 220-a, packet 220-b, etc.) may include a header. The header may indicate the source and destination addresses of packet 220 and fields associated with routing packet 220.

[0109] In one example, packet 220 (e.g., packet 220-a) may include a header indicating the protocol associated with the transmission of packet 220. For example, the header may be an L3 header indicating the L3 protocol associated with the transmission of packet 220. In another example, the header may be an L4 header indicating the L4 protocol associated with the transmission of packet 220.

[0110] In some respects, packet 220 may be an encrypted packet. In some other respects, packet 220 may be an unencrypted packet. In some respects, the header of packet 220 (e.g., L3 header, L4 header, etc.) may include indications of encryption and / or decryption requirements associated with packet 220. DPU 215 may evaluate the header (e.g., L3 header, L4 header) to determine the encryption and / or decryption requirements associated with packet 220. Examples of header evaluation may include evaluating a 5-tuple, including the source IP address (e.g., in the IP header), the destination IP address (e.g., in the IP header), the source port (“sport”) (e.g., in the TCP header), the destination port (“dport”) (e.g., in the TCP header), and subsequent protocols (e.g., communication protocol, data transmission protocol, etc.). Example aspects of packet 220 as an encrypted packet are described below with reference to this example.

[0111] In the example, if the header is an L3 header, then DPU 215 can process the decryption of block 220 at layer 230-b (e.g., L3), such as... Figure 2B and Figure 2CThe decryption is shown in 240. In another example, if the header is an L4 header, DPU 215 can process the decryption of packet 220 at layer 230-c (e.g., L4), as shown. Figure 2C As shown in decryption 241. Alternatively, DPU215 may implement block encryption at layer 230-b (e.g., L3) and / or at layer 230-c (e.g., L4).

[0112] In some respects, if the header is an L4 header, the DPU 215 can implement connection tracking offloading at layer 230-c (e.g., L4), as in Figure 2B Connection tracking is illustrated in connection tracing 245. Connection tracking refers to the ability to maintain state information about a connection in a memory table, such as source and destination IP address and port number pairs (called socket pairs), protocol type, connection state, and timeout. In this example, connection tracking offloading may include tracking connections and storing information about the connection state. For example, at connection tracking 245, DPU 215 (or a NIC including DPU 215) can implement connection tracking offloading, allowing DPU 215 to... Figure 2A The offloading path 217 shown routes established traffic (e.g., packet 220 and packet flow 221) to cloud computing resources of cloud infrastructure 260.

[0113] System 200 can support process balancing. For example, DPU 215 can balance L4 processing (e.g., connection tracking, decryption, etc.) implemented at layer 230-c (e.g., L4). In one example, DPU 215 can direct (e.g., send) a certain percentage or all of the network traffic from layer 230-c (e.g., L4) to machine learning engine 235 for processing. In some aspects, machine learning engine 235 can be a dedicated pattern machine engine implemented at layer 230-f (e.g., L7) capable of processing predefined network attack signatures (e.g., DDoS signatures, etc.) and inspecting incoming data (e.g., directed network traffic). For example, machine learning engine 235 can detect network attacks contained in incoming data by determining whether a pattern (e.g., signature) corresponding to any incoming data matches a predefined network attack signature (e.g., DDoS signature, etc.).

[0114] exist Figure 2CAt position 250, DPU 215 (e.g., machine learning engine 235) can generate filtering logic as described herein (e.g., to block incoming packets associated with a network attack). At position 255, DPU 215 (e.g., machine learning engine 235) can provide or move the generated filtering logic to filtering logic 225. In one example, DPU 215 can provide or move the filtering logic to any of layers 230-a (e.g., L2) through 230-c (e.g., L4). The filtering logic may include example aspects of filtering logic 225 and the attack detection rule set described herein.

[0115] In some alternative and / or additional aspects, for the example where packet 220 is an encrypted packet, DPU 215 (e.g., machine learning engine 235, using machine learning model 240) can perform packet inspection without decrypting packet 220. For example, DPU 215 can extract metadata from packet 220 without decrypting it. In this example, DPU 215 (e.g., machine learning engine 235) can provide the extracted metadata to machine learning model 240. DPU 215 (e.g., using machine learning model 240) can analyze the extracted metadata to determine whether packet 220 (and associated packet stream 221) is associated with a cyberattack (e.g., a DDoS attack, a cryptographer attack, etc.).

[0116] Examples of metadata that DPU 215 can extract from encrypted packets (e.g., packet 220) include: packet size, session (e.g., reference...). Figure 1 The description includes packet counts and general headers in a session (such as between the terminal device 170 and the cloud computing resource 165). In some respects, portions of the metadata (e.g., packet size, number of packets, and general headers) are not encrypted. In one example, in TLS-encrypted traffic, the Media Access Control (MAC) header, Virtual Local Area Network (VLAN) header, IP header, and TCP header are plain text and can be extracted by DPU 215. In some respects, DPU 215 can add the extracted metadata to training data 238. In one example, the extracted metadata can be used to further train a machine learning model 240.

[0117] Therefore, as referenced Figures 2A to 2C As described, system 200 can support continuous feedback and implementation between layers 230. For example, system 200 can support continuous feedback and implementation between layers 230-a (e.g., L2), 230-b (e.g., L3), 230-c (e.g., L4), and 230-f (e.g., L7).

[0118] Once the data is examined and a decision is made, DPU 215 will be able to pass the results to the business logic application for further analysis. In one example, the role of DPU 215 may include collecting information about the application running in layer 230-f (e.g., L7) for a given session. For example, DPU 215 may perform an examination operation that includes determining what the application is in layer 230-f (e.g., L7). Based on the completion or final determination of DPU 215's information collection and / or examination, DPU 215 may pass the relevant results (e.g., application identifiers associated with the application) to security software to run and / or provide its telemetry services. In one example, DPU 215 may use a reference... Figure 1 The telemetry component 120 described herein is used to provide telemetry services.

[0119] Compared to some systems, various aspects of the system 200 described herein can support reduced processing overhead. For example, in some intrusion detection systems, each individual packet is associated with a network attack (e.g., DDoS attack, cipher machine attack, etc.). However, inspecting each individual packet can be resource-intensive. Furthermore, this technique may be ineffective against network attacks (e.g., DDoS attacks, etc.) that aim to circumvent packet-by-packet methods.

[0120] According to an example aspect of this disclosure described herein, system 200 (e.g., DPU 215) can inspect packets of a new packet flow (e.g., packet 220-a of packet flow 221) while processing all other packets of the same packet flow (e.g., packets 220-b to 220-n) at full line rate via offload path 217. Therefore, for example, compared to some other intrusion detection systems, system 200 (e.g., DPU 215) can inspect a relatively small percentage of traffic (e.g., about 10% of the traffic), which can reduce processing overhead and provide improved data throughput.

[0121] Figure 3 An example of a system using DPU-enabled AI-enabled network telemetry according to various aspects of this disclosure is shown. System 300 may include device 305. Device 305 may implement reference Figure 1 The various aspects of DPU 115, cloud computing resource 165, device 170, or DPU 215 described in section 2. In some cases, device 305 may be referred to as a computing resource. Device 305 may perform any or all of the operations described in this disclosure.

[0122] Device 305 may include a transmitter 310, a receiver 315, a communication interface 320, a controller 320, a memory 325, a processor 340, and a communication interface 360. In some examples, the components of device 305 (e.g., transmitter 310, receiver 315, controller 320, memory 325, processor 340, communication interface 360, etc.) may communicate via system buses (e.g., control bus, address bus, data bus, PCI bus, PCIe bus, etc.) included in device 305.

[0123] Transmitter 310 and receiver 315 can support sending and receiving signals to and from device 305. In some aspects, transmitter 310 and receiver 315 can support the transmission and reception of signals within device 305. Transmitter 310 and receiver 315 can be collectively referred to as transceivers. Antennas can be electrically coupled to transceivers. Device 305 may also include (not shown) multiple transmitters 310, multiple receivers 315, multiple transceivers, and / or multiple antennas.

[0124] The controller 320 may reside on the same chip (e.g., an ASIC chip) as the transmitter 310 and / or receiver 315. In some cases, the controller 320 may reside on a different chip than the transmitter 310 and / or receiver 315. In some examples, the controller 320 may reside on a chip of another device 305. The controller 320 may instruct the transmitter 310 to use one or more algorithms to encode and / or decode data. In some examples, the controller 320 may be a programmed microprocessor or microcontroller. In some aspects, the controller 320 may include one or more CPUs, memory, and programmable I / O peripherals.

[0125] The memory 325 can be any electronic component capable of storing electronic information. The memory 325 can be, for example, RAM, ROM, disk storage media, optical storage media, flash memory devices in RAM, onboard memory contained in a processor, EPROM memory, EEPROM memory, registers, and combinations thereof.

[0126] Memory 325 may include instructions 330 (computer-readable code) and data 335 stored thereon. Instructions 330 may be executed by processor 340 to implement the methods disclosed herein. In some aspects, execution of instructions 330 may involve one or more portions of data 350. In some examples, when processor 340 executes instructions 330, portions of instructions 330 and / or data 335 may be loaded onto processor 340.

[0127] Processor 340 may correspond to one or more computer processing devices. For example, processor 340 may include silicon chips, such as field-programmable gate arrays (FPGAs), ASICs, any other type of integrated circuit (IC) chip, a collection of IC chips, and so on. In some aspects, processors may include microprocessors, CPUs (e.g., see reference 1), and so on. Figure 1 The described CPU 141), GPU (e.g., refer to...) Figure 1 The GPU 140 described may be a processor 340 or a plurality of microprocessors configured to execute instruction sets stored in a corresponding memory (e.g., memory 325 of device 305). For example, when executing an instruction set stored in memory 325, processor 340 may enable or execute one or more functions of device 305. In some examples, an ARM (e.g., refer to...) may be implemented in device 305. Figure 1 The processor 340 is a combination of a programmable core 145 and a digital signal processor (DSP) 355.

[0128] The communication interface 360 ​​can support interaction between the user and the device 305 (e.g., via a physical or virtual interface).

[0129] Figure 4 An example of a process flow 400 using DPU-supported AI-supported network telemetry according to various aspects of this disclosure is shown. In some examples, process flow 400 can implement reference... Figures 1 to 3 The various aspects of the DPU 115, DPU 215, or device 305 described.

[0130] In the following description of process flow 400, operations may be performed in a different order than those shown, or operations may be performed in a different order or at different times. Some operations may also be excluded from process flow 400, or other operations may be added to process flow 400.

[0131] It is important to understand that when DPU 115 is described as performing several operations of process flow 400, any device (e.g., GPU 140 of DPU 115, CPU 141 of DPU 115, another DPU, NIC including different DPUs, etc.) can perform the operations shown in the figure. In some respects, DPU 115 is mounted on the NIC.

[0132] At 405, DPU 115 can receive packets from the local network. In some respects, these packets are directed to cloud computing resources. In other respects, these cloud computing resources are shared among multiple tenants.

[0133] In 410, DPU 115 can evaluate the packet header to determine the encryption and / or decryption requirements associated with the packet.

[0134] At 415, DPU 115 can determine that a packet is associated with a new packet stream. In some aspects, this packet may include the first packet in the new packet stream. In other aspects, determining that a packet is associated with a new packet stream may include determining that the packet was received from a tenant that has not previously sent packets to the cloud computing resource.

[0135] In one example, at position 420, DPU 115 can provide packets to the filtering logic that implements the attack detection rule set. In some respects, the attack detection rule set is configured to determine which packets are associated with a new packet stream.

[0136] In 425, in response to determining that a packet is associated with a new packet stream, DPU 115 may provide one or more packets from the new packet stream to a machine learning model for packet inspection. In some aspects, the machine learning model may be executed by an L7 processor. In some aspects, the L7 processor may include at least one of a GPU, DPU 115, and CPU.

[0137] In some respects, filtering logic (e.g., as described in reference 420) can be implemented at a layer of the protocol stack lower than the machine learning model. For example, filtering logic can be executed in at least one of the data link layer, network layer, and transport layer. In one example, the machine learning model can be executed at the application layer.

[0138] In some respects, one or more packets are encrypted. In some respects (not shown), a machine learning model can perform the packet inspection described with reference to 425 without decrypting one or more packets.

[0139] At 430, DPU 115 can receive output from a machine learning model. In some respects, the output indicates whether a new packet stream is associated with a cyberattack. In some respects, a cyberattack may include at least one of the following: DDoS attack, cipher machine attack, compromised access control, security misconfiguration, injection, phishing attack, malware attack, ransomware attack, XSS attack, sensitive data exposure, information disclosure, cryptojacking, fraudulent email transmission, botnet, malicious insider attack, and social profile engineering attack.

[0140] At position 435, DPU 115 can route new packet flows based on the output received from the machine learning model. In some aspects, routing new packet flows may include offloading all packets associated with the new packet flow to cloud computing resources via an offload path. In the example, the offload path carries the packets associated with the new packet flow at full line speed.

[0141] Any steps, functions, and operations discussed in this article can be performed continuously and automatically.

[0142] Exemplary apparatuses, systems, and methods of this disclosure have been described with reference to examples of DPU 105, DPU 215, and apparatus 305. However, to avoid unnecessarily obscuring this disclosure, some known structures and devices have been omitted from the foregoing description. This omission should not be construed as a limitation on the scope of the claimed disclosure. Specific details have been set forth to provide an understanding of this disclosure. However, it should be understood that this disclosure may be practiced in a variety of ways beyond the specific details set forth herein.

[0143] As can be understood from the description herein and for computational efficiency reasons, the components of the devices and systems described herein can be placed in any suitable location in a distributed network of components without affecting the operation of the devices and / or systems.

[0144] Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. It should be further understood that terms (such as those defined in commonly used dictionaries) should be interpreted as having the same meaning as they have in the context of the relevant art and this disclosure.

[0145] Although flowcharts have been discussed and illustrated for specific event sequences, it should be understood that changes, additions, and omissions to the sequence may occur without substantially affecting the operation of the disclosed examples, configurations, and aspects.

[0146] The foregoing discussion of this disclosure has been presented for purposes of illustration and description. The foregoing is not intended to limit the disclosure to the form disclosed herein. For example, in the preceding detailed description, various features of the disclosure have been combined in one or more examples, configurations, or aspects to streamline the disclosure. Features of the examples, configurations, or aspects of this disclosure may be combined in alternative examples, configurations, or aspects other than those discussed above. This approach to disclosure should not be construed as reflecting an intention that the claimed disclosure requires more features than expressly enumerated in each claim. Rather, as reflected in the following claims, the inventive aspect does not lie in all the features of a single example, configuration, or aspect of the foregoing disclosure. Therefore, the following claims are incorporated into this detailed description, each claim existing alone as a separate preferred example of the disclosure.

[0147] Other variations are within the spirit of this disclosure. Therefore, while the disclosed technology is readily adaptable to various modifications and alternative constructions, some examples of which are shown in the accompanying drawings and have been described in detail above. However, it should be understood that the disclosure is not intended to be limited to one or more specific forms disclosed, but rather, it is intended to cover all modifications, alternative constructions, and equivalents falling within the spirit and scope of this disclosure as defined in the appended claims.

[0148] Unless otherwise stated herein or obviously contradicted by the context, the use of the terms “a,” “an,” and “the,” and similar designations in the context of describing the disclosed examples (particularly in the context of the following claims) should be interpreted as encompassing both the singular and plural, rather than as definitions of the terms. Unless otherwise stated, the terms “comprising,” “having,” “including,” and “containing” should be interpreted as open-ended terms (meaning “including, but not limited to”). “Connection,” when unmodified and referring to a physical connection, should be interpreted as being partially or wholly contained, attached to, or joined together, even with some intervening elements. Unless otherwise indicated herein, references to numerical ranges herein are intended only as a way of abbreviating each individual value falling within that range, and each individual value is incorporated into the specification as if it were separately stated herein. In at least one example, unless otherwise indicated or contradicted by the context, the use of the terms “set” (e.g., “item set”) or “subset” should be interpreted as a non-empty set comprising one or more members. Furthermore, unless otherwise indicated or contradicted by the context, the term “subset” of the corresponding set does not necessarily mean an appropriate subset of the corresponding set, but rather that the subset and the corresponding set can be equal.

[0149] Unless explicitly stated otherwise or clearly contradicted by the context, connective phrases such as “at least one of A, B, and C” or “at least one of A, B, and C” are interpreted in the context as generally used to indicate that an item, term, etc., can be any non-empty subset of the set A, B, or C, or A, B, and C. For example, in an illustrative example of a set with three members, the connective phrases “at least one of A, B, and C” and “at least one of A, B, and C” refer to any of the following sets: {A}, {B}, {C}, {A, B}, {A, C}, {B, C}, {A, B, C}. Therefore, such connective language is generally not intended to imply that some examples require at least one of A, at least one of B, and at least one of C to be present individually. Additionally, unless explicitly stated otherwise or contradicted by the context, the term “multiple” indicates a plural state (e.g., “multiple items” indicates multiple items). In at least one example, the number of multiple items is at least two, but may be more when explicitly indicated or by the context. Furthermore, unless otherwise stated or otherwise made clear from the context, the phrase “based on” means “at least partially based on” rather than “based on only”.

[0150] Unless otherwise stated herein or clearly contradicted by the context, the operations of the processes described herein may be performed in any suitable order. In at least one example, processes such as those described herein (or variations and / or combinations thereof) are executed under the control of one or more computer systems configured with executable instructions and are implemented as code (e.g., executable instructions, one or more computer programs, or one or more application programs) that execute collectively on one or more processors via hardware or a combination thereof. In at least one example, the code is stored on a computer-readable storage medium, for example, in the form of a computer program containing multiple instructions that are executed by one or more processors. In at least one example, the computer-readable storage medium is a non-transient computer-readable storage medium that does not include transient signals (e.g., the propagation of transient electrical or electromagnetic transmissions) but includes non-transient data storage circuitry (e.g., buffers, caches, and queues) within the transceiver of transient signals. In at least one example, code (e.g., executable code or source code) is stored on a set of one or more non-transitory computer-readable storage media (or other memory storing executable instructions) on which executable instructions are stored, causing the computer system to perform the operations described herein when the executable instructions are executed by one or more processors of the computer system (i.e., as a result of execution). In at least one example, the set of non-transitory computer-readable storage media comprises multiple non-transitory computer-readable storage media, and one or more individual non-transitory storage media lack all the code, while the multiple non-transitory computer-readable storage media collectively store all the code. In at least one example, the executable instructions are executed such that different instructions are executed by different processors—for example, the non-transitory computer-readable storage media stores the instructions and the main central processing unit (“CPU”) executes some instructions while the graphics processing unit (“GPU”) executes other instructions. In at least one example, different components of the computer system have separate processors and different processors execute different subsets of instructions.

[0151] Therefore, in at least one example, the computer system is configured to implement one or more services that perform the operations of the processes described herein, either individually or collectively, and such a computer system is configured with suitable hardware and / or software capable of performing the operations. Furthermore, the computer system implementing at least one example of this disclosure is a single device, and in another example, it is a distributed computer system comprising multiple devices operating differently, such that the distributed computer system performs the operations described herein, and that the single device does not perform all the operations.

[0152] The use of any and all examples or exemplary language (e.g., "such as") provided herein is intended only to better illustrate examples of this disclosure and does not impose any limitation on the scope of the disclosure unless otherwise required. No language in the specification should be construed as indicating that any unclaimed element is essential to the practice of the disclosed content.

[0153] All references cited in this article, including publications, patent applications and patents, are incorporated herein by reference to the same extent that each reference is individually and specifically indicated as incorporated herein by reference and its entire contents are set forth herein.

[0154] The terms “coupled” and “connected”, and their derivatives, may be used in the specification and claims. It should be understood that these terms may not be intended to be synonyms with each other. Rather, in certain examples, “connected” or “coupled” may be used to indicate that two or more elements are in direct or indirect physical or electrical contact with each other. “Coupled” may also mean that two or more elements are not in direct contact with each other, but still cooperate or interact with each other.

[0155] Unless otherwise expressly stated, it will be understood that throughout this specification, terms such as “processing,” “calculation,” “operation,” “determine,” etc., refer to the actions and / or processes of a computer or computing system or similar electronic computing device that manipulate and / or convert data represented as physical quantities (e.g., electronic quantities) in the registers and / or memory of the computing system into other data similarly represented as physical quantities in the memory, registers, or other such information storage, transmission, or display devices of the computing system.

[0156] Similarly, the term "processor" can refer to any device or part of a device that processes electronic data from registers and / or memory and converts that electronic data into other electronic data that can be stored in registers and / or memory. As a non-limiting example, "processor" can be a CPU or a GPU. A "computing platform" can include one or more processors. As used herein, a "software" process can include, for example, software and / or hardware entities that perform work over time, such as tasks, threads, and intelligent agents. Likewise, each process can refer to multiple processes that execute instructions sequentially or in parallel, continuously or intermittently. In at least one example, the terms "system" and "method" are used interchangeably herein, provided that a system can embody one or more methods, and a method can be considered a system.

[0157] In this document, reference may be made to obtaining, acquiring, receiving, or inputting analog or digital data into a subsystem, computer system, or computer-implemented machine. In at least one embodiment, the process of obtaining, acquiring, receiving, or inputting analog and digital data can be accomplished in various ways, such as by receiving data as a parameter to a function call or a call to an application programming interface. In at least one embodiment, the process of obtaining, acquiring, receiving, or inputting analog or digital data can be accomplished by transmitting data via a serial or parallel interface. In at least one example, the process of obtaining, acquiring, receiving, or inputting analog or digital data can be accomplished by transmitting data from a providing entity to an acquiring entity via a computer network. In at least one example, reference may also be made to providing, outputting, transmitting, sending, or presenting analog or digital data. In various examples, the process of providing, outputting, transmitting, sending, or presenting analog or digital data can be implemented by transmitting data as an input or output parameter to a function call, an application programming interface, or an inter-process communication mechanism.

[0158] While this document describes example implementations of the described technologies, other architectures can be used to implement the described functionality and are intended to fall within the scope of this disclosure. Furthermore, although specific assignments of responsibilities have been defined above for descriptive purposes, various functions and responsibilities may be assigned and divided in different ways depending on the circumstances.

[0159] Furthermore, although the subject matter has been described in language specific to structural features and / or methodological actions, it should be understood that the subject matter claimed in the appended claims is not necessarily limited to the specific features or actions described. Rather, specific features and actions are disclosed as exemplary forms for implementing the claims.

Claims

1. A method comprising: Receive packets from the local network, wherein the packets are directed to cloud computing resources; Determine that the packet is associated with a new packet stream; In response to determining that the packet is associated with the new packet stream, one or more packets from the new packet stream are provided to the machine learning model for packet inspection; The packets are provided to filtering logic that implements an attack detection rule set, wherein the filtering logic is executed in at least one of the data link layer, network layer and transport layer. Receive the output from the machine learning model, wherein the output indicates whether the new packet flow is associated with a network attack, and wherein the machine learning model is executed at the application layer; and The new packet flow is routed based on the output received from the machine learning model.

2. The method of claim 1, wherein the machine learning model is executed by a layer 7 L7 processor.

3. The method of claim 2, wherein the L7 processor includes at least one of a graphics processing unit (GPU), a data processing unit (DPU), and a central processing unit (CPU).

4. The method of claim 1, wherein the packet includes a first packet in the new packet stream.

5. The method of claim 1, wherein the one or more packets are encrypted, and wherein the machine learning model performs packet checking without decrypting the one or more packets.

6. The method of claim 1, wherein the attack detection rule set is configured to determine that the packet is associated with the new packet flow.

7. The method of claim 1, wherein routing the new packet flow includes directing all packets associated with the new packet flow to the cloud computing resource via an offloading path.

8. The method of claim 7, wherein the offloading path carries packets associated with the new packet stream at full line speed.

9. The method of claim 1, further comprising: Evaluate the packet header to determine the encryption and / or decryption requirements associated with the packet.

10. The method of claim 1, wherein the packet is received at a data processing unit (DPU) located on a network interface card (NIC).

11. The method of claim 1, wherein determining that the packet is associated with the new packet stream comprises: It is determined that the packet was received from a tenant who had not previously sent packets to the cloud computing resource.

12. The method of claim 1, wherein the cloud computing resources are shared among multiple tenants, and wherein the network attack includes at least one of the following: Distributed Denial-of-Service (DDoS) attack, cryptanalysis attack, compromised access control, security misconfiguration, injection, phishing attack, malware attack, ransomware attack, cross-site scripting (XSS) attack, sensitive data exposure, information disclosure, cryptojacking, fraudulent email transmission, botnet, malicious insider attack, and social archive engineering attack.

13. A system comprising: A data processing unit (DPU) located between cloud computing resources and local network infrastructure, wherein the DPU is configured to receive packets from the local network infrastructure directed to the cloud computing resources; and A machine learning model is configured to examine the packets and determine whether the packets are part of a packet flow associated with a network attack, wherein the machine learning model is further configured to notify the DPU that the packet flow is not associated with the network attack, thereby enabling the DPU to process additional packets in the packet flow via an offload path that bypasses the machine learning model, wherein the packets are provided to the machine learning model in response to determining that the packets are received from a tenant that has not previously sent packets to cloud computing resources, wherein the packets are provided to multiple layers of the DPU's protocol stack, wherein two or more of the multiple layers of the protocol stack implement filtering logic for determining whether the packet flow is associated with or not with the network attack.

14. The system of claim 13, wherein the machine learning model is executed by a graphics processing unit (GPU) operating at the application layer.

15. The system of claim 13, wherein the offloading path carries additional packets at full line speed.

16. The system of claim 13, wherein the cloud computing resources are shared among multiple tenants, and wherein the network attack includes at least one of the following: Distributed Denial-of-Service (DDoS) attack, cipher machine attack, compromised access control, security misconfiguration, injection, phishing attack, malware attack, ransomware attack, cross-site scripting (XSS) attack, sensitive data exposure, information disclosure, cryptojacking, fraudulent email transmission, botnet, malicious insider attack, and social archive engineering attack.

17. A non-transitory machine-readable medium storing data, wherein if the data is executed by one or more processors, the one or more processors: Inspect the groups that are directed to cloud computing resources; Determine whether the packet is part of a packet stream associated with a network attack; and The data processing unit (DPU) is notified that the packet flow is not associated with the network attack, thereby enabling the DPU to process additional packets in the packet flow via an offload path operating at full line speed. Determining whether a packet is part of a packet flow associated with the network attack includes: The packets are provided to multiple layers of the protocol stack of the DPU, wherein two or more of the multiple layers of the protocol stack implement filtering logic for determining whether the packet flow is associated with or not with the network attack.