Network-based attack protection

By dynamically adjusting the operating frequency of non-core system agents and cores, the solution addresses network congestion and DDoS attacks, ensuring efficient packet handling and CPU availability in network functions.

JP7768694B2Active Publication Date: 2025-11-12INTEL CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021114042
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-08-11
Filing Date
2021-07-09
Publication Date
2025-11-12
Estimated Expiration
2041-07-09

AI Technical Summary

Technical Problem

Network functions and virtual network functions are overwhelmed by network traffic, leading to congestion and unresponsiveness due to signaling storms and malicious attacks like DDoS, causing processor overload and inefficient packet handling.

Method used

Adjusting the operating frequency of non-core system agents and cores to manage packet processing, using power management controllers and intrusion detection systems to mitigate congestion and protect against attacks by reducing or increasing frequency as needed.

Benefits of technology

Maintains CPU availability and network performance by managing packet processing loads, preventing overload, and effectively defending against DDoS attacks in 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007768694000001
    Figure 0007768694000001
  • Figure 0007768694000002
    Figure 0007768694000002
  • Figure 0007768694000003
    Figure 0007768694000003
Patent Text Reader

Abstract

To provide an apparatus, a method, and a program, for preventing a network function (NF) and a virtual network function (VNF) from becoming overloaded and congested by network flooding.SOLUTION: There is provided a method for reducing a frequency of operation of a peripheral device interface between a network interface card and a processor on the basis of detection of a traffic violation. Detecting a traffic violation is on the basis of detection of IP packet fragments at one or more of a network appliance, the network interface card, a non-core part, a system agent, an operating system, an application, or a computing platform. The peripheral device interface includes one or more of a system agent, a non-core part, a bus, a device interface, and a cache.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] Network functions (NFs) and virtual network functions (VNFs) that handle high-speed data plane and signaling processing can be flooded with network traffic, causing the VNFs to become overloaded and virtualized applications to become congested or unresponsive. Causes of network flooding may include signaling storms generated in the network. Processing signaling storms requires high computational resources, which can cause processors to become overloaded or unavailable for performing other work. Several causes of network flooding may include malicious network attack vectors, including denial-of-service (DoS) attacks using fragmentation and buffer-based attacks, as well as distributed versions of these types of attacks (e.g., distributed denial-of-service (DDoS)). [Brief explanation of the drawings]

[0002] [Figure 1] 1 illustrates an exemplary system.

[0003] [Figure 2] 1 illustrates an exemplary system.

[0004] [Figure 3A] Illustrates an exemplary system

[0005] [Figure 3B] 1 shows an example pipeline for packet filtering of packet fragments.

[0006] [Figure 4] 1 illustrates an exemplary process.

[0007] [Figure 5A] 1 illustrates an exemplary process.

[0008] [Figure 5B] This example shows how to change the operating frequency of a non-core part or system agent.

[0009] [Figure 6] Shows the system.

[0010] [Figure 7] 1 illustrates an exemplary environment.

[0011] [Figure 8] 1 shows an exemplary network interface. DETAILED DESCRIPTION OF THE INVENTION

[0012] In some solutions, receive queues handled by the central processing unit (CPU) are allowed to fill up in response to an overflow of receive packets, allowing the CPU to process the packets. Packets may be dropped or blocked, and input ports on input / output (I / O) devices may be disabled to prevent more traffic from being received. In some solutions, access control list (ACL) policies may be applied on the network interface card (NIC) or in host software. However, if a severe overload occurs, additional processor resources may not be available to process the receive packets or apply the ACLs. Furthermore, the timing window between when an overload is detected and when a drop policy is applied can result in indiscriminate dropping of high-priority or important packets (e.g., failover protocol traffic, routing table updates, heartbeats, etc.).

[0013] In a network security attack, malicious input targets an application or service. The attacker may interrupt or gain control of the application or machine. After a successful compromise, the attacker may disable the target application (resulting in a denial-of-service state), disable physical or virtual ports in the case of routers and switches, exhaust resources such as memory buffers or exceed queue depths, or potentially access all rights and privileges available to the compromised application.

[0014] Network devices and software, such as intrusion prevention systems (IPS), inspect network traffic flows to detect and prevent vulnerability exploits. IPSs can run on the communication path between source and destination. They actively analyze received packets and can take automated actions against all traffic flows entering the network. If a malicious attack is detected, independent messaging can be used to send an alarm to data center administrators. In response to CPU overload, IPSs can drop packets deemed malicious, block traffic from source addresses, or reset connections with the source or sender. If mitigation efforts are unsuccessful or produce unacceptable results, system administrators may have no choice but to shut down the system. However, mitigation actions can degrade network performance, slow down systems, and not respond quickly enough to real-time activity.

[0015] Various embodiments attempt to address the flooding of received packets by modifying the frequency of a non-core portion or system agent as a congestion controller at the entry point of packets for processing by the processor. For example, in the event of a flood of received packets, the power or frequency allocated to the non-core portion or system agent may be reduced, optionally making additional power or frequency available to a CPU core to process packets such as a backlog of packets. In some embodiments, the non-core portion or system agent may provide a device interface between one or more CPU cores and a network interface card. Reducing the operating frequency of the non-core portion or system agent may slow the rate at which received packets are copied or transferred from a network interface card (NIC) to a cache or other memory for processing by a CPU core or other device (e.g., an accelerator or graphics processing unit (GPU)). For example, the NIC or other interface may be connected to a CPU core via the non-core portion or system agent using any version of the Peripheral Component Interconnect Express (PCIe) interface. Slowing the frequency of the non-core portion or system agent can slow the rate at which received packets are copied from the NIC, but can slow the packet transmission rate. If packet flooding is mitigated, or if the processor can adequately handle the packet flooding, the frequency of operation of the non-core portion or system agent can be increased to a higher but lower level than the default frequency, or to the default frequency. Various embodiments provide additional protection against attacks using DDoS attacks in the 5G network core and edge, and can maintain CPU availability even during network-based attacks.

[0016] In some embodiments, the operating frequency of the non-core portion or system agent can be configured using a register (e.g., a model-specific register (MSR)). For example, a power management controller (e.g., firmware) can adjust the operating frequency of the non-core portion or system agent. Reducing the operating frequency of the non-core portion or system agent can increase the amount of power available to the cores, or if there is power available to supply one or more cores, the power management controller can increase the power allocated to the cores. For example, the IPS can request the power management controller to reduce the operating frequency of the non-core portion or system agent.

[0017] 1 illustrates an exemplary path for network traffic from a network interface card (NIC) to a core. In system 100, network packets received at NIC 102 can be routed using message transactions between uncore portion 104 and NIC 102 before processing by core 120. Message transactions between NIC 102 and core 120 can use components of uncore portion 104. Uncore portion 104 can include circuitry that resides outside of CPU core 120 but on the same die, such as an L3 cache, an integrated memory controller, an UltraPath Interconnect (UPI), and an interconnect mesh.

[0018] For example, if a PCIe interface is used, the PCIe interface 106 can provide communication of received packets from the NIC 102 to at least a last level cache (LLC) and a caching and home agent (CHA) 108. Note that the LLC and CHA can be integrated or separate components. The CHA can function as a local coherence and cache controller and as a coherence and interface to the memory controller 110. In some embodiments, the CHA couples to the LLC, and the CHA can attempt to maintain cache coherence among various memory and cache devices in other clusters or CPU sockets. For example, a core can send a memory access request to its CHA, which can provide the data from its cache slice or obtain a copy of the data from another core's cache.

[0019] Various embodiments can detect packet flooding and, to prevent or mitigate overload of utilization of cores 120, LLCs, and CHAs 108, reduce the frequency of uncore portions to manage congestion at the ingress point of packets from NIC 102 for processing by cores 120. For example, in response to detecting possible packet flooding, an IPS (not shown) can request power controller 140 to reduce the operating frequency of uncore portions 104. In some examples, power controller 140 can increase the operating frequency of any cores 120 to process the backlog of packets if there is an available power budget.

[0020] In some embodiments, any of the cores 120 may execute applications, workloads, or software that performs packet processing based on one or more of the Data Plane Development Kit (DPDK), Storage Performance Development Kit (SPDK), Open Data Plane, Network Function Virtualization (NFV), software-defined networking (SDN), Evolved Packet Core (EPC), or 5G Network Slicing. Some implementation examples of NFV are described in the European Telecommunications Standards Institute (ETSI) specifications or the Open Source NFV Management and Orchestration (MANO) from the ETSI Open Source Mano (OSM) group. A virtual network function (VNF) can include a sequence of virtualized tasks, or service chains, that run on common configurable hardware, such as firewalls, domain name systems (DSNs), caching, or network address translation (NAT), and can run in a virtualized execution environment (VEE) (e.g., containers or virtual machines). VNFs can be linked together as service chains. In some instances, EPC is the core architecture specified by 3GPP, at least for Long Term Evolution (LTE) access. 5G network slicing can provide multiplexing of independent virtualized logical networks over the same physical network infrastructure.Some applications are capable of video processing or media transcoding (changing the encoding of audio, image, or video files).

[0021] Figure 2 illustrates an exemplary system. System 200 illustrates an exemplary layout of LLC / CHAs (e.g., non-core portions) and cores, as well as interfaces (e.g., UPI and PCIe) with memory controllers (MCs). A mesh can be used to provide connectivity between various devices in system 200. Any layout of interfaces, non-core portions, and cores can be used, and any number of interfaces, non-core portions, cores, and MCs can be used.

[0022] 3A illustrates an exemplary system. In this example, network elements 302-0 through 302-N (where N is an integer greater than or equal to 1) may be communicatively coupled to a server 310 using network interfaces 308 via connections 304. Any of network elements 302-0 through 302-N and network interfaces 308 may include a network interface (e.g., a network interface card or network interface controller), a bus interface, a fabric interface, a switch, a router, a forwarding element, etc. Connection 304 may be at least compatible with any networking or communications standard, including Ethernet, InfiniBand, Compute Express Link (CXL), HyperTransport, any high-speed fabric, PCIe, NVLink, Advanced Microcontroller Bus Architecture (AMBA) Interconnect, OpenCAPI, Gen-Z, CCIX, Intel® QuickPath Interconnect (QPI), Intel® Ultra Path Interconnect (UPI), Intel® On-Chip System Fabric (IOSF), Omnipath, etc. Server 310 may refer to any computing platform, such as a server, a rack, an edge computing node, or a data center.

[0023] In some embodiments, intrusion detection system 350 inspects network traffic flows to detect vulnerability exploits or other attempts to flood network interface 308 or core 316 with packets it processes. Intrusion detection system 350 can protect critical networking infrastructure from fragmented packet-based denial-of-service (DoS) attacks and distributed denial-of-service (DDoS) attacks, improving uptime and network service level agreements (SLAs). For example, intrusion detection system 350 can detect and attempt to prevent at least the following types of attacks: tiny fragment attacks, buffer overflow attacks, or overlapping fragment attacks.

[0024] A tiny fragment attack may involve an attacker or sender setting a fragment size small enough to squeeze Layer 4 (e.g., TCP and UDP) header fields into the second fragment. A buffer overflow attack may be a denial-of-service (DoS) attack, in which an attacker or sender continuously sends many incomplete IP fragments, consuming time and memory as the server 310 attempts to reassemble the fake packets. An overlapping fragment attack may involve an attacker or sender overwriting the fragment offset on non-first IP fragment packets, potentially generating erroneous IP packets when the forwarding plane reassembles the IP packets, causing memory to overflow or causing the system to reload.

[0025] For example, RFC 1858 (1995) discusses security considerations for IP fragment filtering and highlights two attacks against hosts that involve IP fragments in TCP packets: tiny fragment attacks and overlapping fragment attacks. Blocking these attacks is desirable because they can potentially lead to unauthorized access to a host or lock up all of its internal resources. RFC 1858 also describes two defenses against these attacks: direct and indirect. The direct method discards initial fragments that are smaller than a minimum length. The indirect method involves discarding the second fragment of a fragment set if it begins 8 bytes into the original IP datagram.

[0026] The intrusion detection system 350 can apply IP filter rules before fragment processing (e.g., in the OS). If it detects a tiny fragment, it can discard the packet. If it detects an overlapping fragment attack, it can discard all fragments in the fragment chain if overlapping fragments are detected.

[0027] To detect buffer overflow attacks, the intrusion detection system 350 may track the number of IP datagrams reassembled and a maximum threshold for the number of fragments per datagram, and may do the following: (1) when the maximum number of fragments per datagram is reached, subsequent fragments are discarded and the global statistic COUNTER is incremented by one; (2) in addition to setting a maximum threshold, each IP datagram is associated with a managed timer; (3) if an IP datagram does not receive all of its fragments within a specified time, the timer expires and the IP datagram and all its fragments are discarded; and (4) when the maximum number of datagrams that can be reassembled at any given time is reached, all subsequent fragments are discarded and the global statistic COUNTER is incremented by one.

[0028] In some embodiments, intrusion detection system 350 may execute on any of network device 306, network interface 308, and / or server 310 (e.g., operating system, application, or core interface 314). For example, network device 306 may receive packets from connection 304 to be forwarded to network interface 308. In some examples, network device 306 may execute intrusion detection system 350 to detect DoS or DDoS attacks aimed at network interface 308 or server 310 and attempt to mitigate packet overflows resulting from attacks on network interface 308 and server 310.

[0029] In some embodiments, the intrusion detection system 350 can enforce access control lists (ALCs) to discard packets associated with a particular flow that is deemed malicious. A flow can be a sequence of packets transmitted between two endpoints and generally represents a single session using a known protocol. Thus, a flow can be identified by a predefined set of N tuples. For routing purposes, a flow can be identified by tuples that identify endpoints, such as source and destination addresses. For content-based services (e.g., load balancers, firewalls, intrusion detection systems, etc.), a flow can be identified with finer granularity by using five or more tuples (e.g., source address, destination address, IP protocol, transport layer source port, destination port). Packets in a flow are expected to have the same set of tuples in their packet headers.

[0030] According to various embodiments, in response to detecting an intrusion attempt, the intrusion detection system 350 (e.g., an IPS) can issue a frequency change notification, flag, indicator, or message to the power manager 312 to request an adjustment to the frequency of the core interface 314 between the network interface 308 and the core 316. For example, the core interface 314 can include a non-core portion or system agent that provides an interface between the network interface 308 and the core 316. In some embodiments, the non-core portion or system agent can include a bus interface (e.g., PCIe), a cache, a cache, and a home agent. In the event of detection of a vulnerability identified by the intrusion detection system 350, the intrusion detection system 350 can request the power manager 312 to reduce the operating frequency of the core interface 314 as a gate to control messaging rates between the network interface 308 and the core 316. For example, reducing the operating frequency of the non-core portions can protect the server 310 and core 316 from being overloaded with incoming messages and can slow message transfers between the core 316 and the network interface 308.

[0031] In a scenario in which the intrusion detection system 350 detects a debilitating attack (e.g., DoS or DDoS) against a particular flow or multiple flows, the intrusion detection system 350 can notify the power manager 312 to increase the frequency of the core interface 314 via a frequency change message, indicator, or flag. If the intrusion detection system 350 detects a vulnerability that is no longer active, it can attempt to increase the operating frequency of the core interface 314 incrementally or to a previous frequency level. For example, if the intrusion detection system 350 detects that the CPU has completed processing packets in the backlog, the operating frequency of the core interface 314 can be increased. In response to a request to increase the frequency of the core interface 314, the power manager 312 can attempt to decrease the core frequency if the power budget is not available to increase the frequency of the core interface 314. It should be noted that the power manager 312 can adjust (e.g., increase or decrease) the power available to non-core devices such as accelerators, media processors, video offload engines, decryption / encryption offload engines, network interface cards, graphics processing units (GPUs), etc.

[0032] In some embodiments, the core interface 314 and the cores 316 can operate in separate, variable voltage and frequency domains. This allows the system to leverage all the benefits of the variable non-core domains while allowing for improved power efficiency. For a given power budget, lowering the frequency of the core interface 314 can allow additional headroom for a higher operating frequency of the cores 316. A higher core frequency can assist in the execution of preventative measures prescribed by the intrusion detection system 350 or the operating system (OS).

[0033] In some examples, a core may be an execution core or computational engine capable of executing instructions. A core may have access to its own cache and read-only memory, or multiple cores may share a cache or ROM. Cores may be homogeneous and / or heterogeneous devices. Any type of inter-processor communication technique may be used, such as, but not limited to, messaging, inter-processor interrupts (IPI), inter-processor communications, etc. Cores may be connected in any type of manner, such as, but not limited to, a bus, ring, or mesh.

[0034] In some embodiments, the non-core portions or system agents may include one or more of a memory controller, a shared cache (e.g., LLC), a cache coherency manager, an arithmetic logic unit, a floating point unit, a core or processor interconnect, or a bus or link controller (e.g., a PCIe interface). The system agents may provide one or more of a direct memory access (DMA) engine connection, a non-cache coherent master connection, inter-core data cache coherence, arbitration cache requests, or Advanced Microcontroller Bus Architecture (AMBA) capabilities.

[0035] In some embodiments, power manager 312 can independently adjust the operating frequencies of core 316, core interface 314, and other devices by setting values ​​in registers, such as model specific registers (MSRs). For example, MSRs can include control registers used for program execution tracing, toggling computational functions, and / or performance monitoring.MSRs control various cache memories in the microprocessor's cache hierarchy, such as Memory Order Buffer (MOB) control and status; page fault error codes; clearing the page directory cache and translation lookaside buffer entries (TLB); disabling all or part of the cache, removing power from all or part of the cache, and invalidating cache tags; microcode patch mechanism control; debug control; processor bus control; hardware data and instruction prefetch control; sleep and wake-up control; and ACPI (Advanced Configuration and Power Interface) control. Interface); state transitions defined by industry standards (e.g., P-states and C-states), and power management control such as disabling clocks or power to various functional blocks; instruction merge control and status; Error Correcting Code (ECC) memory error status; bus parity error status; thermal management control and status; service processor control and status; inter-core communication; inter-die communication; microprocessor fuse functions; voltage regulator module voltage identifier control; phase-locked loop (PLL) control; cache snoop control; write combine buffer control and status; overclocking function control; interrupt controller control and status; temperature sensor control and status; encryption / decryption, MSR password protection, L2 cache and These may include one or more of: enabling and disabling various features such as parallel requests to the processor bus, individual branch prediction functions, instruction merging, microinstruction timeouts, performance counters, store forwarding, and speculation table walks; load queue size; cache memory size; control of how accesses to undefined MSRs are handled; multicore configuration; cache memory configuration (e.g., deselecting columns of bit cells in the cache and replacing columns with redundant columns of bit cells); the duty cycle and / or clock ratio of the microprocessor's phase-locked loop (PLL); and a configured voltage identifier (VID) that controls the voltage supply to the microprocessor.

[0036] FIG. 3B shows an example pipeline for packet filtering of packet fragments. A NIC, switch, or other device or software (e.g., an IPS) can detect packet fragments. Classifier 362, IP filter 364, fragment IP filter 366, and IP reassembly unit 368 work together to identify whether a packet is part of a tiny fragment attack, a buffer overflow attack, or an overlapping fragment attack. If the packet is deemed to be part of a tiny fragment attack, a buffer overflow attack, or an overlapping fragment attack, IP reassembly unit 368 can reassemble the packet and provide the reassembled packet to a NIC or switch or forward the reassembled packet to a server.

[0037] FIG. 4 illustrates an exemplary process. At 402, a network interface (e.g., a NIC, network interface controller, fabric interface, etc.) can receive packets from a connection. A system agent or non-core portion can communicatively connect and forward packet content from the network interface to one or more cores. At 404, the frequency of the non-core portion can be adjusted based on instructions from a congestion management system. Reducing the operating frequency of the non-core portion can reduce the rate at which received packets are provided to the core. Increasing the operating frequency of the non-core portion can increase the rate at which received packets are provided to the core. At 406, packet classification can be performed to determine whether a DoS or DDoS attack has occurred based on the number of fragmented packets detected over a time interval. For example, a DoS or DDoS attack can be detected based on the number of tiny fragment attacks, buffer overflow attacks, or overlapping fragment attacks occurring within a time window for a flow or multiple flows.

[0038] If a DoS or DDoS attack is detected, a congestion avoidance scheme may be initiated at 408 to request congestion management. Congestion management may include reducing the frequency of the non-core portion, increasing the operating frequency of the core or processor, allocating additional buffer space for received packets in memory, etc. If congestion management determines that a frequency adjustment should be made due to the attack at 410, the non-core frequency may be reduced by signaling frequency control to the non-core frequency control. If congestion management determines that a frequency adjustment should be made due to the end of the attack or no attack being detected at 410, the non-core frequency may be increased or maintained by signaling frequency control to the non-core frequency control.

[0039] Traffic policing can occur at 412 to regulate traffic bursts. When the traffic rate reaches a configured maximum rate, excess traffic is dropped (or remarked). Traffic shaping can occur at 414, whereby excess packets are held in a queue and scheduled for later transmission over time increments to provide a smoothed packet output rate. Traffic shaping regulates the flow of packets egressing an interface or sub-interface, matching the packet flow to the interface speed, the ability to configure Frame Relay Traffic Shaping (FRTS), or regulating the flow of packets egressing an interface (per traffic class) to match the packet flow to the interface speed, using modular quality of service (QoS) command line interface (CLI) commands. Packets can be provided to a buffer or cache for processing by one or more cores or other devices.

[0040] FIG. 5A shows an example process. At 502, a workload can be distributed to one or more cores or devices for execution. For example, the devices can include an accelerator, a media processor, a video offload engine, a decryption / encryption offload engine, a network interface card, or a graphics processing unit (GPU). At 504, a default frequency for a peripheral device interface can be set. For example, the peripheral device interface can include one or more of a PCIe interface, a CXL interface, a DDR interface, a bus interface, a system agent, a non-core portion, and / or a cache. In some embodiments, the peripheral device interface can provide communication between a communication interface and a core, a processor, or an accelerator. The communication interface can include a network interface card, a host interface, a bus interface, or other communication device that may be subject to malicious or non-malicious traffic flooding. In some embodiments, a default clock frequency can be set for the peripheral device interface, which can control the rate at which data is transferred from the communication interface to the core, the processor, or the accelerator. In some embodiments, increasing the default operating frequency of a peripheral device interface may result in less power budget being available to the core or device, and the operating frequency of the core or device may be reduced so that the overall power budget of the peripheral device interface and the core and device is not exceeded.

[0041] At 506, traffic received at the communication interface can be observed to detect traffic flooding. Traffic flooding can result from a DoS or DDoS attack at a network interface or server. For example, an IPS or congestion monitor can observe packet characteristics such as (1) IP packet fragments that are incomplete packets, (2) IP packet fragments that are too small, (3) IP packet fragments that result in excessive packets, (4) a full IP packet fragment buffer, or (5) any denial of service (DoS) reported at the ingress. For example, the IPS can identify traffic flooding if any of (1) through (5) occurs a sufficient number of times over a time interval for a particular flow or multiple flows. For example, traffic flooding can be detected by a particular number of occurrences of (1) through (4) over a time interval for a particular flow or multiple flows.

[0042] At 508, a determination is made whether a traffic violation has occurred. If traffic flooding is detected, a traffic violation may have occurred. If a traffic violation is not observed, the process may return to 506. If a traffic violation is observed, the process may continue to 510.

[0043] At 510, a determination is made as to whether the traffic violation has been corrected. A correction of the IP violation may occur if the OS processes IP packets and discards IP packets that are deemed to be in any of (1) through (4) above, while maintaining a sufficient processing rate of received packets (e.g., under an applicable Service Level Agreement (SLA)) and utilizing an allowable amount of packet buffer space for received packets (e.g., the amount of buffer space does not violate the SLA). The operating system or networking software, such as a TCP / IP stack or Berkley packet filter, or a networking software application (one that processes packets directly from the NIC port, such as a Data Plane Development Kit (DPDK) or Storage Performance Development Kit (SPDK)-based application) can determine whether the traffic violation has been corrected. If the traffic violation has been corrected, the process continues to 504, where the frequency of the peripheral device interface is returned to the peripheral device interface's default operating frequency or is increased in stages, but not to the peripheral device interface's default operating frequency.

[0044] In some embodiments, any of 504, 506, 508, or 510 is performed by a processor or circuitry of a network appliance, a NIC, an ACL, a non-core portion, or a system agent, or by software running on a processor (e.g., a Linux® networking stack, a DPDK application, or an SPDK application).

[0045] If the traffic violation is not corrected, the process continues at 512. At 512, the operating frequency of the peripheral device interface can be reduced. The frequency reduction can be incremental. The amount of frequency reduction can depend on the number of traffic violations without correction. For the first observed traffic violation without correction, the reduction can be incremental (stepwise). For a second traffic violation observed without correction (e.g., if the second iteration of 510 indicates No), the frequency of the interface can be reduced by a second step, which is larger than the previous step. For a third traffic violation observed without correction (e.g., if the third iteration of 510 indicates No), the frequency of the interface can be reduced by an amount larger than the second step. However, a lower limit on the operating frequency of the interface can be set, for example, if the interface is a non-core part or a system agent. In addition to reducing the operating frequency of the peripheral device interface, the operating frequency of the core or device can be increased if there is sufficient power budget available to increase the operating frequency of the core or device. The process continues at 510.

[0046] FIG. 5B illustrates an example method for changing the operating frequency of a non-core portion or system agent. In scenario 550, a device such as a NIC, FPGA, ASIC, ACL, or fragmentation device can detect packet fragments corresponding to an attack and (1) request a non-core frequency controller to adjust its frequency or (2) request an OS to adjust the frequency of the non-core portion. In scenario 552, a device can detect packet fragments corresponding to an attack and request an operating system (OS) network stack (e.g., Linux eBPF or ACL and fragmentation logic) to adjust the frequency of the non-core portion.

[0047] In scenario 554, the device detects packet fragments corresponding to an attack and can request a DPDK application (e.g., ACL and fragmentation logic) to adjust the frequency of the non-core portion. In scenario 556, the device detects packet fragments corresponding to an attack and can request a virtual switch (e.g., ACL and fragmentation logic) to adjust the frequency of the non-core portion. The virtual switch can include a vSwitch, a VMware® Virtual Switch (e.g., ESXi), Microsoft® Hyper-V, or Open vSwitch.

[0048] FIG. 6 illustrates a system that may employ embodiments described herein to adjust the operating frequency of a peripheral device interface, system agent, non-core portion, core, or device in response to a detected or undetected attack. System 600 includes a processor 610 that provides processing, operational management, and execution of instructions for system 600. Processor 610 may include any type of microprocessor, central processing unit (CPU), graphics processing unit (GPU), processing core, or other processing hardware that provides processing for system 600, or a combination of processors. Processor 610 controls the overall operation of system 600 and may be or include one or more programmable general-purpose or special-purpose microprocessors, digital signal processors (DSPs), programmable controllers, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), etc., or a combination of these devices.

[0049] In one example, system 600 includes an interface 612 coupled to processor 610, which may represent a higher-speed or high-throughput interface for system components requiring higher-bandwidth connections, such as memory subsystem 620, graphics interface component 640, or accelerator 642. Interface 612 may be a standalone component or may represent interface circuitry integrated on the processor die. When present, graphics interface 640 interfaces with a graphics component that provides a visual display to a user of system 600. In one example, graphics interface 640 may drive a high-definition (HD) display that provides output to a user. High definition may refer to a display having a pixel density of approximately 100 PPI (pixels per inch) or greater, and may include formats such as Full HD (e.g., 1080p), Retina display, 4K (ultra-high definition or UHD), etc. In one example, the display may include a touchscreen display. In one example, graphics interface 640 generates a display based on data stored in memory 630, or based on operations performed by processor 610, or both. In one example, graphics interface 640 generates a display based on data stored in memory 630, or based on operations performed by processor 610, or both.

[0050] Accelerators 642 can be programmable or fixed function offload engines that can be accessed or used by processor 610. For example, accelerators among accelerators 642 can provide compression (DC) capabilities, cryptographic services such as public key encryption (PKE), encryption, hashing / authentication capabilities, decryption, or other capabilities or services. In some embodiments, accelerators among accelerators 642 additionally or alternatively provide field selection controller functionality as described herein. In some cases, accelerators 642 can be integrated into a CPU socket (e.g., a connector to a motherboard or circuit board that contains and provides an electrical interface with the CPU). For example, the accelerator 642 may include programmable processing elements such as single or multi-core processors, graphics processing units, logic execution units, single or multi-level caches, functional units usable for independently executing programs or threads, application-specific integrated circuits (ASICs), neural network processors (NNPs), programmable control logic, and field-programmable gate arrays (FPGAs). The accelerator 642 may provide multiple neural networks, CPUs, processor cores, general-purpose graphics processing units, or graphics processing units enabled for use with artificial intelligence (AI) or machine learning (ML) models. For example, the AI ​​models may use or include any or a combination of reinforcement learning schemes, Q-learning schemes, deep Q-learning, asynchronous advantage actor-critic (A3C), associative neural networks, recurrent associative neural networks, or other AI or ML models. Multiple neural networks, processor cores, or graphics processing units may be enabled for use with AI or ML models.

[0051] Memory subsystem 620 represents the main memory of system 600 and provides storage for code executed by processor 610 or data values ​​used in executing routines. Memory subsystem 620 may include one or more memory devices 630, such as read-only memory (ROM), flash memory, one or more types of random access memory (RAM), such as DRAM, or other memory devices, or a combination of such devices. Memory 630 stores and supports, among other things, an operating system 632 to provide a software platform for executing instructions within system 600. Furthermore, applications 634 may execute on the OS 632 software platform in memory 630. Applications 634 represent programs having their own operating logic to perform one or more functions. Processes 636 represent agents or routines that provide auxiliary functions to OS 632, one or more applications 634, or a combination thereof. OS 632, applications 634, and processes 636 provide the software logic that provides functionality for system 600. In one example, memory subsystem 620 includes memory controller 622, which is a memory controller for generating and issuing commands to memory 630. It will be appreciated that memory controller 622 may be a physical part of processor 610 or a physical part of interface 612. For example, memory controller 622 may be an integrated memory controller integrated into circuitry with processor 610.

[0052] Although not specifically shown, it will be understood that system 600 can include one or more buses or bus systems between devices, such as a memory bus, a graphics bus, an interface bus, or the like. A bus or other signal line can communicatively or electrically couple components together, or communicatively and electrically couple components. A bus can include physical communication lines, point-to-point connections, bridges, adapters, controllers, or other circuits or combinations. A bus can include, for example, one or more of a system bus, a Peripheral Component Interconnect (PCI) bus, a HyperTransport or Industry Standard Architecture (ISA) bus, a Small Computer System Interface (SCSI) bus, a Universal Serial Bus (USB), or an Institute of Electrical and Electronics Engineers (IEEE) Standard 1394 bus (Firewire).

[0053] In one example, system 600 includes an interface 614 that can be coupled to interface 612. In one example, interface 614 represents interface circuitry, which can include standalone components and integrated circuits. In one example, multiple user interface components, peripheral components, or both, couple to interface 614. Network interface 650 provides system 600 with the ability to communicate with remote devices (e.g., servers or other computing devices) over one or more networks. Network interface 650 can include an Ethernet adapter, a wireless interconnection component, a cellular network interconnection component, a universal serial bus (USB), or other wired or wireless standards-based or proprietary interface. Network interface 650 can transmit data to devices in the same data center or rack or to remote devices, including transmitting data stored in memory. Network interface 650 can receive data from remote devices, which can include storing the received data in memory. Various embodiments can be used in connection with network interface 650, processor 610, and memory subsystem 620.

[0054] In one example, system 600 includes one or more input / output (I / O) interfaces 660. I / O interface 660 can include one or more interface components through which a user interacts with system 600 (e.g., audio, alphanumeric, haptic / touch, or other interfaces). Peripheral interface 670 can include any hardware interface not specifically mentioned. Peripherals generally refer to devices that connect dependently to system 600. A dependent connection is one in which system 600 provides a software or hardware platform, or both, on which operations are executed and with which a user interacts.

[0055] In one example, system 600 includes a storage subsystem 680 for storing data in a nonvolatile manner. In one example, in a particular system implementation, at least certain components of storage 680 can overlap with components of memory subsystem 620. Storage subsystem 680 includes storage device 684, which can be or can include any conventional medium for storing large amounts of data in a nonvolatile manner, such as one or more magnetic, solid-state, or optical disks, or a combination thereof. Storage 684 holds code or instructions and data 686 in a persistent state (e.g., values ​​are retained even upon interruption of power to system 600). While storage 684 can be generally considered "memory," memory 630 is typically an execution or operating memory for providing instructions to processor 610. While storage 684 is nonvolatile, memory 630 can include volatile memory (e.g., if power is interrupted to system 600, the value or state of the data becomes indeterminate). In one example, storage subsystem 680 includes a controller 682 that interfaces with storage 684. In one example, controller 682 can be a physical part of interface 614 or processor 610, or can include circuitry or logic in both processor 610 and interface 614.

[0056] Volatile memory is memory whose state (i.e., the data stored in it) is indeterminate when power to the device is interrupted. Dynamic volatile memory requires the data stored in the device to be refreshed in order to maintain its state. An example of dynamic volatile memory includes Dynamic Random Access Memory (DRAM) or variants such as Synchronous DRAM (SDRAM). Another example of volatile memory includes cache or static random access memory (SRAM). The memory subsystem as described herein may be any of a variety of memory technologies, including DDR3 (Double Data Rate version 3, originally released by JEDEC (Joint Electronic Device Engineering Council) on June 27, 2007), DDR4 (DDR version 4, initial specification published by JEDEC in September 2012), DDR4E (DDR version 4), LPDDR3 (Low Power DDR version 3, JESD209-3B, originally published by JEDEC in August 2014), LPDDR4 (LPDDR version 4, JESD209-4, originally published in August 2014), WIO2 (Wide Input / Output version 2, JESD229-2, originally published by JEDEC in August 2014), HBM (High Bandwidth It may be compatible with many memory technologies, such as JEDEC Memory, JESD325 (originally published by JEDEC in October 2013), LPDDR5 (currently under discussion by JEDEC), HBM2 (HBM version 2, currently under discussion by JEDEC), or any other combination of memory technologies, technologies based on derivatives or extensions of such specifications. JEDEC standards are available at www.jedec.org.

[0057] A nonvolatile memory (NVM) device is memory whose state is deterministic even when power to the device is interrupted. In some embodiments, the NVM device may include a block-addressable memory device, such as NAND technology, more specifically, multi-threshold level NAND flash memory (e.g., single-level cell ("SLC"), multi-level cell ("MLC"), quad-level cell ("QLC"), tri-level cell ("TLC"), or some other NAND). The NVM device may also include a byte-addressable write-in-place three-dimensional cross-point memory device or other byte-addressable write-in-place NVM device (also referred to as persistent memory), such as single- or multi-level phase-change memory (PCM) or phase-change memory with switches (PCMS), Intel® Optane® memory, NVM devices using chalcogenide phase change materials (e.g., chalcogenide glasses), resistive memories including metal oxide-based, oxygen vacancy-based, and conductive bridge random access memories (CB-RAM), nanowire memories, ferroelectric random access memories (FeRAM, FRAM®), magnetoresistive random access memories (MRAM) incorporating memristor technology, spin-transfer torque (STT)-MRAM, spintron magnetic junction memory-based devices, magnetic tunnel junction (MTJ)-based devices, DW (domain wall) and SOT (spin-orbit transfer)-based devices, thyristor-based memory devices, or any combination of these or other memories.

[0058] A power source (not shown) provides power to the components of system 600. More specifically, the power source typically interfaces to one or more power sources within system 600 to provide power to the components of system 600. In one example, the power source includes an AC-DC (alternating current-direct current) adapter for plugging into a wall outlet. Such AC power can be a renewable energy (e.g., solar) power source. In one example, the power source includes a DC power source, such as an external AC-DC converter. In one example, the power source or power supply includes wireless charging hardware for charging in the vicinity of a charging field. In one example, the power source can include an internal battery, an AC power source, a motion-based power source, a solar power source, or a fuel cell power source.

[0059] In one example, system 600 may be implemented using interconnected computational threads of processors, memory, storage, network interfaces, and other components, and may use high-speed interconnects such as PCIe, Ethernet, or optical interconnects (or combinations thereof).

[0060] FIG. 7 illustrates an environment 700 including multiple computing racks 702, each including a top-of-rack (ToR) switch 704, a pod manager 706, and multiple pooled system drawers. The environment can employ embodiments described herein to adjust the operating frequencies of peripheral device interfaces, system agents, non-core portions, cores, or devices in response to detecting an attack or not detecting an attack. Generally, the pooled system drawers can include pooled computing drawers and pooled storage drawers. Optionally, the pooled system drawers can include pooled memory drawers and pooled input / output (I / O) drawers. In the illustrated embodiment, the pooled system drawers include an Intel® XEON® pooled computer drawer 708, an Intel® ATOM® pooled computer drawer 710, a pooled storage drawer 712, a pooled memory drawer 714, and a pooled I / O drawer 716. Each of the pooled system drawers is connected to the ToR switch 704 via a high-speed link 718, such as a 40 Gigabits per second (Gb / s) or 100 Gb / s Ethernet link or a 100+ Gb / s Silicon Photonics (SiPh) optical link. In some embodiments, the high-speed link 718 includes an 800 Gb / s SiPh optical link.

[0061] Multiple computing racks 702 may be interconnected via their ToR switches 704 (e.g., pod-level switches or data center switches), as shown by their connection to network 720. In some embodiments, groups of computing racks 702 are managed as separate pods via pod managers 706. In some embodiments, a single pod manager is used to manage all racks in a pod. Alternatively, a distributed pod manager may be used for pod management operations.

[0062] Environment 700 further includes a management interface 722 that is used to manage various aspects of the environment, including managing rack configurations along with corresponding parameters that are stored as rack configuration data 724. Environment 700 can be used for computing racks.

[0063] Embodiments herein may be implemented in various types of computing and networking devices, such as switches, routers, racks, and blade servers (such as those used in data center and / or server farm environments). Servers used in data centers and server farms include arrayed server configurations, such as rack-based servers or blade servers. These servers are interconnected via various networking facilities to form private intranets, partitioning sets of servers into local area networks (LANs) with appropriate switching and routing capabilities between the LANs. For example, cloud hosting facilities typically utilize large data centers with numerous servers. Blades comprise separate computing platforms configured to perform server-type functions, i.e., "server-on-a-card." Thus, each blade includes components common to a traditional server, including a main printed circuit board (main board) that provides internal wiring (e.g., buses) for coupling appropriate integrated circuits (ICs) and other components mounted on the board.

[0064] FIG. 8 illustrates a network interface that can employ or be used by embodiments. The network interface can employ embodiments described herein to adjust the operating frequency of a peripheral device interface, system agent, non-core portion, core, or device in response to a detected or undetected attack. The network interface 800 can include a transceiver 802, a processor 804, a transmit queue 806, a receive queue 808, a memory 810, a bus interface 812, and a DMA engine 852. The transceiver 802 can transmit and receive packets according to an applicable protocol, such as Ethernet, as described in IEEE 802.3, although other protocols may be used. The transceiver 802 can receive packets from and transmit packets to a network via a network medium (not shown). The transceiver 802 can include a PHY circuit 814 and a medium access control (MAC) circuit 816. The PHY circuitry 814 may include encoding and decoding circuitry (not shown) for encoding and decoding data packets according to applicable physical layer specifications or standards. The MAC circuitry 816 may be configured to construct data to be transmitted into packets, which include destination and source addresses along with network control information and error detection hash values. The processor 804 may be any combination of processors, cores, graphics processing units (GPUs), field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), or other programmable hardware devices that enable programming of the network interface 800. For example, the processor 804 may provide identification of resources to use to execute a workload and generation of a bitstream to execute on the selected resources. For example, a "smart network interface" may use the processor 804 to provide packet processing capabilities within the network interface.

[0065] The packet allocator 824 can use time slot allocation or RSS as described herein to provide distribution of received packets for processing by multiple CPUs or cores. If the packet allocator 824 uses RSS, the packet allocator 824 can calculate a hash or make another determination based on the contents of the received packet to determine which CPU or core should process the packet.

[0066] The interrupt coalescing unit 822 can perform interrupt moderation, whereby the network interface interrupt coalescing unit 822 waits for multiple packets to arrive or for a timeout to expire before generating an interrupt to the host system to process the received packets. Receive segment coalescing (RSC) can be performed by the network interface 800, whereby portions of incoming packets are combined into packet segments. The network interface 800 provides the combined packets to the application.

[0067] The direct memory access (DMA) engine 852 can copy packet headers, packet payloads, and / or descriptors directly from host memory to the network interface or vice versa, instead of copying the packet to an intermediate buffer in the host and then using another copy operation from the intermediate buffer to the destination buffer.

[0068] Memory 810 may be any type of volatile or non-volatile memory device and may store any queues or instructions used to program network interface 800. Transmit queue 806 may contain data or references to data for transmission by the network interface. Receive queue 808 may contain data or references to data received by the network interface from the network. Descriptor queue 820 may contain descriptors that reference data or packets in transmit queue 806 or receive queue 808. Bus interface 812 may provide an interface to a host device (not shown). For example, bus interface 812 may be compatible with a PCI, PCI Express, PCI-x, Serial ATA, and / or USB-compatible interface (although other interconnect standards may be used).

[0069] In some embodiments, the processor 804 may perform one or more of: Large Receive Offload (LRO), Large Send / Segmentation Offload (LSO), TCP Segmentation Offload (TSO), Transport Layer Security (TLS) offload, and Receive Side Scaling (RSS) to allocate queues or cores to process payloads. LRO reassembles incoming network packets and transfers the contents (e.g., payload) of the packets into larger packets, resulting in fewer packets for access by the host system or VEE.

[0070] LSO may refer to creating a multi-packet buffer and providing the contents of the buffer for transmission. The host device may construct a larger TCP (or other transport layer) message (e.g., 64 KB long), and the processor 804 may segment the message into smaller data packets for transmission.

[0071] TLS is defined in at least TLS (Transport Layer Security) Protocol version 1.3, RFC 8446 (August 2018). TLS offloading may refer to the offloading of encryption or decryption of content conforming to TLS within the processor 804. The network interface 800 may receive data for encryption and perform encryption of the data prior to transmission of the encrypted data in one or more packets. The network interface 800 may receive packets and decrypt the packet contents prior to forwarding the decrypted data to the host system. In some embodiments, any type of encryption or decryption may be performed, such as, but not limited to, Secure Sockets Layer (SSL).

[0072] In some examples, the network interfaces and other embodiments described herein may be used in connection with base stations (e.g., 3G, 4G, 5G, etc.), macro base stations (e.g., 5G networks), pico stations (e.g., IEEE 802.11-enabled access points), nano stations (e.g., point-to-multipoint (PtMP) applications), on-premises data centers, off-premises data centers, edge network elements, fog network elements, and / or hybrid data centers (e.g., data centers using virtualization, cloud, and software-defined networking to distribute application workloads across physical data centers and distributed multi-cloud environments).

[0073] Various embodiments may be implemented using hardware elements, software elements, or a combination thereof. In some embodiments, hardware elements may include devices, components, processors, microprocessors, circuits, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, ASICs, PLDs, DSPs, FPGAs, memory units, logic gates, registers, semiconductor devices, chips, microchips, chip sets, etc. In some embodiments, software elements may include: A software component may include a program, application, computer program, application program, system program, machine program, operating system software, middleware, firmware, software module, routine, subroutine, function, method, procedure, software interface, API, instruction set, computing code, computer code, code segment, computer code segment, word, value, symbol, or any combination thereof. The decision whether to implement an embodiment using hardware and / or software elements may vary according to any number of factors, such as desired computation speed, power level, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints, as desired for a given implementation. Note that hardware, firmware, and / or software elements may be collectively or individually referred to herein as "modules" or "logic." A processor may be a hardware state machine, digital control logic, a central processing unit, or a combination of one or more of any hardware, firmware, and / or software elements.

[0074] Some embodiments may be implemented using or as an article of manufacture or at least one computer-readable medium. The computer-readable medium may include a non-transitory storage medium for storing logic. In some embodiments, the non-transitory storage medium may include one or more types of computer-readable storage media capable of storing electronic data, including volatile or non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, etc. In some embodiments, the logic may include various software elements such as software components, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, APIs, instruction sets, computing code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof.

[0075] According to some embodiments, a computer-readable medium may include a non-transitory storage medium that stores or maintains instructions that, when executed by a machine, computing device, or system, cause the machine, computing device, or system to perform methods and / or actions according to described embodiments. The instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, etc. The instructions may be implemented according to a predetermined computer language, manner, or syntax to instruct the machine, computing device, or system to perform a predetermined function. The instructions may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled, and / or interpreted programming language.

[0076] One or more aspects of at least one embodiment may be implemented by representative instructions stored on at least one machine-readable medium, which represent various logic within a processor and, when loaded by a machine, computing device, or system, cause the machine, computing device, or system to perform the techniques described herein. Such representations, known as "IP cores," may be stored on tangible machine-readable media and supplied to various customers or manufacturing facilities for loading into manufacturing machines that actually create the logic or processor.

[0077] Appearances of the phrase "in one embodiment" or "example" do not necessarily all refer to the same embodiment or embodiment. Any aspect described herein may be combined with any other aspect described herein or with similar aspects, regardless of whether those aspects are described in connection with the same drawing or element. The division, omission, or inclusion of block functions depicted in the accompanying drawings does not imply that hardware components, circuits, software, and / or elements for achieving those functions will necessarily be divided, omitted, or included in the embodiments.

[0078] Some embodiments may be described using the terms "coupled" and "connected," along with their derivatives. These terms are not necessarily intended as synonyms for each other. For example, a description using the terms "connected" and / or "coupled" may indicate that two or more elements are in direct physical or electrical contact with each other. However, the term "coupled" may also mean that two or more elements are not in direct contact with each other, but yet still cooperate or interact with each other.

[0079] As used herein, the terms “first,” “second,” etc. do not denote any order, quantity, or importance, but rather are used to distinguish one element from another. The terms “a” and “an” do not denote a limitation of quantity, but rather denote the presence of at least one of the referenced items. The term “asserted,” as used herein with respect to a signal, refers to the state of the signal where the signal is active, which state can be achieved by applying any logic level, either logic 0 or logic 1, to the signal. The terms “following” or “after” can refer to immediately after or after some other event or events. Other sequences of steps may be performed according to alternative embodiments. Furthermore, additional steps may be added or deleted depending on the particular application. Any combination of variations may be used, and one of ordinary skill in the art having the benefit of this disclosure will recognize numerous variations, modifications, and alternative embodiments thereof.

[0080] Disjunctive terms, such as the phrase "at least one of X, Y, or Z," are understood in their commonly used context to indicate that a term, item, etc. may be either X, Y, or Z, or any combination thereof (e.g., X, Y, and / or Z), unless specifically stated otherwise. Thus, such disjunctive terms are generally not intended to, and should not, indicate that a particular embodiment requires that at least one of X, at least one of Y, or at least one of Z, respectively, be present. Furthermore, conjunctive terms, such as the phrase "at least one of X, Y, and Z," should be understood to mean X, Y, Z, or any combination thereof, including "X, Y, and / or Z," unless specifically stated otherwise.

[0081] Illustrative examples of the devices, systems, and methods disclosed herein are provided below. Embodiments of the devices, systems, and methods may include any one or more, and any combination, of the examples described below.

[0082] Flow diagrams as illustrated herein provide examples of sequences of various process operations. Flow diagrams may depict not only physical operations but also operations to be performed by software or firmware routines. In some embodiments, flow diagrams may depict the states of a finite state machine (FSM), which may be implemented in hardware and / or software. Although shown in a particular sequence or order, the order of operations may be changed unless otherwise noted. Therefore, the illustrated embodiments should be understood as examples only, and processes may be performed in a different order, and some operations may be performed in parallel. Furthermore, one or more operations may be omitted in various embodiments; therefore, not all operations are required in all embodiments. Other process flows are possible.

[0083] Various components described herein may be means for performing the described operations or functions. Each component described herein includes software, hardware, or a combination thereof. Components may be implemented as software modules, hardware modules, special-purpose hardware (e.g., application-specific hardware, application-specific integrated circuits (ASICs), digital signal processors, etc.), embedded controllers, hardwired circuitry, etc.

[0084] Example 1 includes a method, the method including altering an operating frequency of a peripheral device interface between a network interface card and a processor based on detecting a traffic violation.

[0085] Example 2 includes any example, including detecting a traffic violation based on detecting an IP packet fragment, and changing the operating frequency of a peripheral device interface between the network interface card and the processor based on the detection of the traffic violation includes reducing the operating frequency of the peripheral device interface between the network interface card and the processor based on the detection of the traffic violation.

[0086] Example 3 includes any example, wherein the IP packet fragments include one or more of: IP packet fragments that are incomplete packets, IP packet fragments that are too small, IP packet fragments that result in excessive packets, or an IP packet fragment buffer that is full.

[0087] Example 4 includes any example, wherein detecting a traffic violation based on detecting IP packet fragments comprises: Detecting a traffic violation based on detecting IP packet fragments in one or more of a network appliance, a network interface card, a non-core portion, a system agent, an operating system, an application, or a computing platform.

[0088] Example 5 includes any example, wherein the peripheral device interface includes one or more of a system agent, a non-core portion, a bus, a Peripheral Component Interconnect Express (PCIe) interface, and a cache.

[0089] Example 6 includes any example where the peripheral device interface is part of a system on a chip (SoC), and the SoC includes one or more of a core, a system agent, or a non-core portion.

[0090] Example 7 includes any example where the processor includes one or more of a core, an accelerator, or a graphics processing unit (GPU).

[0091] p includes any specific example, wherein altering the operating frequency of a peripheral device interface between the network interface card and the processor based on detecting a traffic violation includes increasing the operating frequency of the peripheral device interface based on one or more of managing a traffic violation in the processor or not detecting a traffic violation, and increasing the operating frequency of the processor if a power budget allocated to the processor and the peripheral device interface allows for increasing the operating frequency of the processor.

[0092] Example 9 includes any example, wherein changing the operating frequency of a peripheral device interface between a network interface card and a processor based on detection of a traffic violation includes changing the frequency of a clock provided to a non-core circuit based on network traffic.

[0093] Example 10 includes any example and includes a non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to detect a traffic violation based on detecting an IP packet fragment and reduce an operating frequency of a peripheral device interface between the network interface card and the processor based on the detection of the traffic violation.

[0094] Example 11 includes any example, wherein the IP packet fragments include one or more of: IP packet fragments that are incomplete packets, IP packet fragments that are too small, IP packet fragments that result in excessive packets, or an IP packet fragment buffer that is full.

[0095] Example 12 includes any example, including instructions stored therein that, when executed by one or more processors, cause the one or more processors to detect a traffic violation based on detection of IP packet fragments in one or more of a network appliance, a network interface card, a non-core portion, a system agent, an operating system, an application, or a computing platform.

[0096] Example 13 includes any example where the peripheral device interface includes a system agent or a non-core portion.

[0097] Example 14 includes any example in which the peripheral device interface includes a bus, a Peripheral Component Interconnect Express (PCIe) interface, and a cache.

[0098] Example 15 includes any example where the processor includes a core, an accelerator, or a graphics processing unit (GPU).

[0099] Example 16 includes any example, including instructions stored therein that, when executed by one or more processors, cause the one or more processors to increase an operating frequency of a peripheral device interface based on one or more of managing a traffic violation in a core or not detecting a traffic violation.

[0100] Example 17 includes any example, including instructions stored therein that, when executed by one or more processors, cause the one or more processors to increase the operating frequency of the processors when a peripheral device interface and a power budget for the processors allow the processors to increase their operating frequency.

[0101] Example 18 includes any example, including an apparatus, the apparatus including at least one core, a system agent coupled to receive packets from a network interface and provide the received packets for processing by the core, and a power manager that reduces an operating frequency of the system agent based on a request, the request being based on detection of a traffic violation.

[0102] Example 19 includes any example, including a processor that detects a traffic violation based on detecting IP packet fragments, the IP packet fragments including one or more of IP packet fragments that are incomplete packets, IP packet fragments that are too small, IP packet fragments that result in excessive packets, or an IP packet fragment buffer being full.

[0103] Example 20 includes any example, including a processor increasing the operating frequency of a system agent and requesting a power manager to increase the operating frequency of the system agent based on one or more of managing a traffic violation in a core or not detecting a traffic violation.

Claims

1. Detecting traffic violations based on detecting Internet Protocol (IP) packet fragments; and Reducing the operating frequency of a peripheral device interface between a network interface card and a processor based on detection of a traffic violation Detecting a traffic violation based on detecting IP packet fragments, the method comprising: Detecting a traffic violation based on detecting the IP packet fragment in one or more of a network appliance, the network interface card, a non-core portion, a system agent, an operating system, an application, or a computing platform.

2. The IP packet fragments include one or more of IP packet fragments that are incomplete packets, IP packet fragments that are too small, IP packet fragments that result in excessive packets, or an IP packet fragment buffer being full. The method of claim 1.

3. the peripheral device interface includes one or more of a system agent, a non-core portion, a bus, a Peripheral Component Interconnect Express (PCIe) interface, and a cache; The method of claim 1.

4. the peripheral device interface is part of a system on a chip (SoC), the SoC including one or more of a core, a system agent, or a non-core portion; The method of claim 1.

5. the processor includes one or more of a central processing unit (CPU) core, an accelerator, or a graphics processing unit (GPU); The method of claim 1. increasing an operating frequency of the peripheral device interface based on one or more of managing the traffic violation in the processor or not detecting a traffic violation; and increasing the operating frequency of the processor if a power budget allocated to the processor and the peripheral device interface allows for the operating frequency of the processor to be increased; The method of claim 1 , wherein the system further comprises:

7. Reducing an operating frequency of a peripheral device interface between a network interface card and a processor based on detection of a traffic violation includes: reducing the frequency of a clock provided to non-core circuitry based on network traffic; 7. The method according to any one of claims 1 to 6.

8. One or more processors Detecting traffic violations based on detecting Internet Protocol (IP) packet fragments; and Reducing the operating frequency of a peripheral device interface between a network interface card and a processor based on detection of a traffic violation wherein detecting a traffic violation based on detecting IP packet fragments comprises: detecting a traffic violation based on detecting the IP packet fragment in one or more of a network appliance, the network interface card, a non-core portion, a system agent, an operating system, an application, or a computing platform.

9. The IP packet fragments include one or more of IP packet fragments that are incomplete packets, IP packet fragments that are too small, IP packet fragments that result in excess packets, or an IP packet fragment buffer being full.

9. A computer program according to claim 8.

10. the peripheral device interface includes a system agent or non-core portion; 9. A computer program according to claim 8.

11. the peripheral device interface includes a bus, a Peripheral Component Interconnect Express (PCIe) interface, and a cache; 9. A computer program according to claim 8.

12. the processor includes a central processing unit (CPU) core, an accelerator, or a graphics processing unit (GPU); 9. A computer program according to claim 8.

13. the one or more processors; and further causing the peripheral device interface to increase an operating frequency based on one or more of managing a traffic violation in the core or not detecting a traffic violation.

9. A computer program according to claim 8.

14. the one or more processors; further causing the processor to increase its operating frequency if a power budget for the peripheral device interface and the processor allows for the processor to increase its operating frequency. A computer program according to any one of claims 8 to 13.

15. At least one core; a system agent coupled to receive packets from the network interface and provide the received packets for processing by the core; a processor for detecting traffic violations based on detecting Internet Protocol (IP) packet fragments; a power manager that reduces an operating frequency of the system agent based on a request, the request being based on the detection of the traffic violation; and detecting a traffic violation based on the detection of the IP packet fragments comprises: detecting a traffic violation based on the detection of the IP packet fragment in one or more of a network appliance, the network interface card, a non-core portion, a system agent, an operating system, an application, or a computing platform.

16. The device described in claim 15, wherein the IP packet fragments include one or more of IP packet fragments that are incomplete packets, IP packet fragments that are too small, IP packet fragments that result in excessive packets, or an IP packet fragment buffer that is full.

17. increasing an operating frequency of the system agent based on one or more of managing a traffic violation in a core or not detecting a traffic violation; and A processor requesting the power manager to increase the operating frequency of the system agent.

17. The apparatus of claim 15 or 16, comprising:

Citation Information

Patent Citations

  • Packet switching apparatus

    JP2004179705A

  • Operation mode change device and communication apparatus

    JP2010193298A

  • Communication method, communication system and communication device

    JP2015043520A

  • Apparatus and method for adjusting processor power usage based on network load

    JP2018512648A

  • JPP4391455B