Dynamic Control Plane CPU Overload Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for preventing control plane CPU overload in communication networks are inadequate, as statically configured filter rules can lead to denial of service issues and rate limiting approaches fail to dynamically adapt to changes in network configurations, causing legitimate control packets to be dropped during traffic anomalies or attacks.

Innovation Solution

Implementing dynamically configured meters to pre-classify and meter control packets based on input ports and protocols, with per-CPU core flow control to adjust rate limits and prevent CPU overload, allowing legitimate traffic to be processed even during bursts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If statically configured filter rules are used to prevent CPU overload, then CPU overload protection is improved, but legitimate control packets may be dropped during traffic anomalies or attacks

Engineering Contradiction:
ImproveCPU overload protectionVSAvoidlegitimate control packets dropped
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamically configurable filter rules that adapt to changing network conditions. The system monitors traffic patterns and automatically adjusts filter parameters in real-time, transitioning from static to dynamic filtering. This allows the system to maintain CPU overload protection while adapting to legitimate traffic variations and avoiding false drops of valid control packets during anomalies or attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms that monitor both traffic characteristics and CPU load levels. Based on this feedback, the filter rules are continuously optimized - tightening protection when CPU load is high and relaxing filters when legitimate traffic patterns are recognized. This closed-loop control ensures reliable CPU protection while minimizing loss of legitimate control packets through adaptive response to system state.

Inventive Principle:
Principle #23Feedback

2Reliability

If rate limiting is applied to control packets, then CPU overload is prevented, but the system fails to adapt to changes in network configuration

Engineering Contradiction:
ImproveCPU overload preventionVSAvoidadaptation to network configuration changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamically configurable filter rules that adapt to changing network conditions. The system monitors traffic patterns and automatically adjusts filter parameters in real-time, transitioning from static to dynamic filtering. This allows the system to maintain CPU overload protection while adapting to legitimate traffic variations and avoiding false drops of valid control packets during anomalies or attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system dynamically changes filter parameters such as rate limits, threshold values, and packet classification criteria based on monitored network conditions and configuration changes. When network topology or traffic patterns change, the system automatically adjusts these parameters to maintain optimal protection levels while accommodating new legitimate traffic flows, thus preventing CPU overload without sacrificing adaptability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If strict filter rules are enforced, then CPU resource capacity is protected, but control plane functionality may be compromised during traffic bursts

Engineering Contradiction:
ImproveCPU resource protectionVSAvoidcontrol plane functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamically configurable filter rules that adapt to changing network conditions. The system monitors traffic patterns and automatically adjusts filter parameters in real-time, transitioning from static to dynamic filtering. This allows the system to maintain CPU overload protection while adapting to legitimate traffic variations and avoiding false drops of valid control packets during anomalies or attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system dynamically changes filter parameters such as rate limits, threshold values, and packet classification criteria based on monitored network conditions and configuration changes. When network topology or traffic patterns change, the system automatically adjusts these parameters to maintain optimal protection levels while accommodating new legitimate traffic flows, thus preventing CPU overload without sacrificing adaptability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8693335B2Method and apparatus for control plane CPU overload protection
Publication Date: 2014.04.08 EXTREME NETWORKS INC
  • US8693335B2 patent drawing
  • US8693335B2 patent drawing
  • US8693335B2 patent drawing

AI summary

Control packets received at a network element are pre-classified to enable out of profile traffic to be traced to an offending port. Pre-classified control packets are metered at a desired granularity using dynamically configured meters which adjust as ports are put into service or removed from service, and as services are applied to ports. CPU metering is implemented on a per-CPU core basis, but the per-CPU meters are used to perform flow control rather than as thresholds for ejecting errant control traffic. The combination of these three aspects provides robust CPU overload protection while allowing appropriate levels of control traffic to be provided to the control plane for processing, even in the event of a control traffic burst on one or more ports of the network element.