Biased Network Traffic Sampling via Microcode State Machines
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security and monitoring systems, including firewalls and anti-virus software, are inadequate in detecting new types of attacks and reacting to threats, especially in high-speed networks, due to limited monitoring capabilities and inflexibility, leading to inefficiencies and performance issues.
Innovation Solution
An apparatus that performs biased and weighted sampling of network traffic using microcode controlled state machines and a distribution circuit, enabling advanced monitoring and reaction capabilities through rule-based processing, including signature-based and behavioral rules, to detect and respond to potential breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewalls and anti-virus software are used for network security, then basic filtering and virus detection are provided, but monitoring capabilities are limited and new attack types cannot be detected
Solution Approach 1:
The system dynamically adapts its monitoring and detection capabilities based on observed network traffic patterns and behaviors. The monitoring apparatus can adjust its analysis depth, sampling rates, and detection thresholds in real-time to respond to emerging threats while maintaining efficient operation during normal conditions.
Solution Approach 2:
The network monitoring system is divided into multiple independent components including packet capture modules, analysis engines, and response mechanisms. This segmentation allows each component to specialize in specific detection tasks and enables parallel processing of different attack vectors, improving both reliability and adaptability.
2Reliability
If comprehensive network traffic monitoring is implemented to detect all attack types, then detection capability is improved, but network performance degradation occurs
Solution Approach 1:
The monitoring system applies partial inspection to most traffic, examining only critical header fields and using statistical sampling. Full packet inspection is reserved for suspicious traffic that triggers specific detection rules. This approach provides sufficient detection capability for most threats while minimizing the performance overhead of comprehensive monitoring.
Solution Approach 2:
The system dynamically changes monitoring parameters such as packet sampling rate, inspection depth, and analysis intensity based on current network conditions and threat levels. During normal operation, monitoring operates at low intensity to minimize impact. When threats are detected, the system increases monitoring granularity and resource allocation to improve detection effectiveness.
3Productivity
If high-speed network processing is implemented to maintain performance, then network throughput is maintained, but monitoring and detection capabilities are reduced
Solution Approach 1:
The processing architecture segments network traffic into different handling paths: critical security-related packets receive full inspection and analysis, while normal traffic flows through optimized high-speed paths with minimal processing. This segmentation allows the system to maintain high overall throughput while ensuring thorough monitoring of potentially malicious traffic.
Solution Approach 2:
The patent introduces specialized intermediary components such as network processors and content addressable memory that act as mediators between high-speed network interfaces and analysis engines. These intermediaries perform initial filtering, classification, and packet manipulation at line rate, enabling subsequent detailed monitoring without becoming a bottleneck to overall network performance.
4Reliability
If advanced monitoring features are added to provide comprehensive security, then detection capability is improved, but device complexity and cost increase
Solution Approach 1:
The monitoring apparatus employs universal components that can perform multiple functions. For example, the same packet processing engine handles both high-speed forwarding and security analysis, while content addressable memory serves both exact match lookup and pattern matching operations. This multi-functionality reduces the need for separate specialized hardware for each monitoring feature, thereby reducing overall system complexity.
Data Source
AI summary
An apparatus is described that performs biased and weighted sampling of network traffic to facilitate network monitoring. One embodiment of the apparatus includes a plurality of microcode controlled state machines, and a distribution circuit that routes input data to the plurality of microcode controlled state machines. A first individual microcode controlled state machine applies a first rule to the input data to determine first instructions associated with a first subset of the input data based on first sampling information associated with the first rule. A second individual microcode controlled state machine applies a second rule to the input data to determine second instructions associated with a second subset of the input data based on second sampling information associated with the second rule. The second sampling information differs from the first sampling information. This embodiment further includes a first circuit that generates first routing instructions for the first subset of the input data based on the first instructions, and that generates second routing instructions for the second subset of the input data based on the second instructions. This embodiment further includes a second circuit that routes the input data based on the first routing instructions and the second routing instructions. Advantageously, the apparatus provides an architectural framework well suited to a low cost, high speed, robust implementation of flexible, advanced network security and monitoring features and network traffic analysis.


