Dynamic Control Plane CPU Overload Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for preventing control plane CPU overload in communication networks are inadequate, as statically configured filter rules can lead to denial of service issues and rate limiting approaches fail to dynamically adapt to changes in network configurations, causing legitimate control packets to be dropped during traffic anomalies or attacks.
Innovation Solution
Implementing dynamically configured meters to pre-classify and meter control packets based on input ports and protocols, with per-CPU core flow control to adjust rate limits and prevent CPU overload, allowing legitimate traffic to be processed even during bursts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If statically configured filter rules are used to prevent CPU overload, then CPU overload protection is improved, but legitimate control packets may be dropped during traffic anomalies or attacks
Solution Approach 1:
The patent implements dynamically configurable filter rules that adapt to changing network conditions. The system monitors traffic patterns and automatically adjusts filter parameters in real-time, transitioning from static to dynamic filtering. This allows the system to maintain CPU overload protection while adapting to legitimate traffic variations and avoiding false drops of valid control packets during anomalies or attacks.
Solution Approach 2:
The system incorporates feedback mechanisms that monitor both traffic characteristics and CPU load levels. Based on this feedback, the filter rules are continuously optimized - tightening protection when CPU load is high and relaxing filters when legitimate traffic patterns are recognized. This closed-loop control ensures reliable CPU protection while minimizing loss of legitimate control packets through adaptive response to system state.
2Reliability
If rate limiting is applied to control packets, then CPU overload is prevented, but the system fails to adapt to changes in network configuration
Solution Approach 1:
The patent implements dynamically configurable filter rules that adapt to changing network conditions. The system monitors traffic patterns and automatically adjusts filter parameters in real-time, transitioning from static to dynamic filtering. This allows the system to maintain CPU overload protection while adapting to legitimate traffic variations and avoiding false drops of valid control packets during anomalies or attacks.
Solution Approach 2:
The system dynamically changes filter parameters such as rate limits, threshold values, and packet classification criteria based on monitored network conditions and configuration changes. When network topology or traffic patterns change, the system automatically adjusts these parameters to maintain optimal protection levels while accommodating new legitimate traffic flows, thus preventing CPU overload without sacrificing adaptability.
3Reliability
If strict filter rules are enforced, then CPU resource capacity is protected, but control plane functionality may be compromised during traffic bursts
Solution Approach 1:
The patent implements dynamically configurable filter rules that adapt to changing network conditions. The system monitors traffic patterns and automatically adjusts filter parameters in real-time, transitioning from static to dynamic filtering. This allows the system to maintain CPU overload protection while adapting to legitimate traffic variations and avoiding false drops of valid control packets during anomalies or attacks.
Solution Approach 2:
The system dynamically changes filter parameters such as rate limits, threshold values, and packet classification criteria based on monitored network conditions and configuration changes. When network topology or traffic patterns change, the system automatically adjusts these parameters to maintain optimal protection levels while accommodating new legitimate traffic flows, thus preventing CPU overload without sacrificing adaptability.
Data Source
AI summary
Control packets received at a network element are pre-classified to enable out of profile traffic to be traced to an offending port. Pre-classified control packets are metered at a desired granularity using dynamically configured meters which adjust as ports are put into service or removed from service, and as services are applied to ports. CPU metering is implemented on a per-CPU core basis, but the per-CPU meters are used to perform flow control rather than as thresholds for ejecting errant control traffic. The combination of these three aspects provides robust CPU overload protection while allowing appropriate levels of control traffic to be provided to the control plane for processing, even in the event of a control traffic burst on one or more ports of the network element.


