Per-Input Port Control Plane Policing via Virtual Output Queues
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network elements, such as routers and switches, are vulnerable to denial of service attacks that flood control plane processors with innocuous control plane network data, leading to resource exhaustion and disruption of legitimate traffic processing.
Innovation Solution
Implementing per-input port, per-control plane network data traffic class policing using virtual output queues (VOQs) that classify and manage control plane network data based on traffic classes, applying policer tests to isolate and drop excessive traffic, thereby protecting the control plane processor from resource exhaustion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If control plane network data is processed without classification and policing, then all control plane traffic is handled uniformly, but denial of service attacks can exhaust control plane processor resources
Solution Approach 1:
The patent segments control plane network data into multiple classes based on traffic characteristics, creating separate output queues for each class. This segmentation allows differential policing strategies to be applied to different traffic types, protecting the control plane processor from resource exhaustion by attack traffic while maintaining proper handling of legitimate control plane data.
Solution Approach 2:
The patent introduces virtual output queues (VOQs) as an intermediary mechanism between the input ports and the control plane processor. These VOQs act as buffers and classification points that enable policing of excessive traffic before it reaches the control plane processor, thereby protecting the processor without requiring direct modification of the processing logic.
2Object-affected harmful factors
If per-input port, per-class policing is implemented, then excessive attack traffic can be isolated and dropped, but the network element requires more complex queue management
Solution Approach 1:
The patent creates a matrix of virtual output queues where each queue corresponds to a specific combination of input port and traffic class. This segmentation enables precise policing at the intersection of port and class dimensions, allowing attack traffic from specific ports to be isolated without affecting other ports or traffic classes.
Solution Approach 2:
The patent applies different policing parameters and thresholds to different virtual output queues based on their specific input port and traffic class characteristics. This local quality approach allows the system to be highly selective in dropping only the excessive attack traffic while maintaining lenient policies for legitimate traffic classes.
3Productivity
If control plane network data is queued without classification, then queue management is simpler, but legitimate traffic may be disrupted by attack traffic in the same queue
Solution Approach 1:
The patent segments control plane network data into distinct traffic classes based on characteristics such as protocol type, source/destination addresses, or other identifying features. Each class receives dedicated virtual output queues, ensuring that legitimate traffic in one class cannot be disrupted by attack traffic in another class.
Solution Approach 2:
The policing mechanism monitors the rate of traffic arrival at each virtual output queue and provides feedback by dropping packets that exceed configured thresholds. This feedback loop prevents any single traffic class from monopolizing control plane processor resources, thereby protecting legitimate traffic processing.
Data Source
AI summary
Methods and systems for per-input port, per-control plane network data traffic class control plane policing in a network element are described. In one embodiment, the method comprises receiving control plane network data at an input port of a network element, wherein the control plane network data is data that is processed by the control plane. The method may also include classifying the control plane network data based on characteristics of the control plane network data. Furthermore, the method may include storing the control plane network data in one of a plurality of output queues for the input port based on a class of the control plane network data, and forwarding control plane network data from a selected one of the plurality of output queues to a control plane of the network element.


