Data Plane Smart Sensors for Network Appliance Traffic Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network appliances such as switches and routers face challenges in adapting to changes in feature sets, protocols, operating systems, and hardware configurations, requiring flexibility in processing high volumes of network traffic while maintaining rapid decision-making capabilities.

Innovation Solution

Implementing a data plane with special purpose hardware and a match-action pipeline that monitors network traffic flows according to flow monitoring policies, measures flow metrics, and triggers reporting policies to adapt to changing conditions and report anomalies, enabling smart sensing within the data plane without the need for external traffic mirroring systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network appliances use traditional external traffic mirroring systems for monitoring, then traffic flow analysis can be performed, but network bandwidth is consumed and system complexity increases

Engineering Contradiction:
Improvetraffic flow monitoring capabilityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent merges the traffic monitoring function with the data plane by implementing sensors directly within the packet processing pipeline. This integration eliminates the need for separate external mirroring systems, allowing traffic flow analysis to occur without consuming additional network bandwidth while reducing overall system complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces special-purpose hardware sensors as intermediaries within the data plane that can monitor traffic flows without extracting or replicating traffic to external systems. These sensors measure traffic parameters directly from the processing stream, providing monitoring capability without the bandwidth overhead of traditional mirroring approaches

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network appliances implement flexible adaptation to changing protocols and configurations, then versatility improves, but processing speed may decrease

Engineering Contradiction:
Improveprotocol and configuration flexibilityVSAvoidpacket processing speed
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The patent implements dynamic adaptability by making the data plane programmable through configuration data that can be modified without hardware changes. The match-action pipeline can be dynamically reconfigured to handle different protocols and traffic patterns while maintaining high-speed processing through hardware-accelerated packet classification and forwarding decisions

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables versatility through parameter changes by allowing the data plane to be configured with different match criteria, action sequences, and policy rules. These parameter modifications can be applied dynamically to adapt to changing network requirements while the underlying hardware maintains wire-speed processing capabilities

Inventive Principle:
Principle #35Parameter changes

3Productivity

If network appliances process packets at wire speed, then productivity is maintained, but the ability to perform complex monitoring and analysis diminishes

Engineering Contradiction:
Improvepacket forwarding speedVSAvoidmonitoring and analysis capability
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the network appliance into distinct functional components: a data plane for high-speed packet forwarding and a control plane for complex monitoring and analysis. The data plane handles wire-speed processing using simplified hardware logic, while the control plane performs sophisticated traffic analysis, enabling both high productivity and complex monitoring capabilities to coexist

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces complex mechanical or software-based monitoring systems with specialized hardware sensors integrated into the data plane. These sensors use dedicated circuitry to measure traffic parameters directly from the packet stream, providing analysis capability without the overhead of software processing and maintaining wire-speed operation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If network appliances use external traffic mirroring for anomaly detection, then detection capability is provided, but system complexity and bandwidth usage increase

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges anomaly detection functionality directly into the data plane by implementing sensors that monitor traffic flows and compare them against defined policies. This integration eliminates the need for separate external analysis systems, reducing architectural complexity while maintaining detection capability through hardware-accelerated comparison and classification operations

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enables the data plane to perform self-monitoring through integrated sensors that automatically detect anomalies by comparing traffic patterns against configured policies. The system serves its own monitoring needs without requiring external traffic mirroring or separate analysis infrastructure, reducing overall system complexity while maintaining detection precision

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11374844B2Methods and systems for smart sensor implementation within a network appliance data plane
Publication Date: 2022.06.28 PENSANDO SYSTEMS INC
  • US11374844B2 patent drawing
  • US11374844B2 patent drawing
  • US11374844B2 patent drawing

AI summary

A network appliance having a control plane and a data plane can process substantially every input packet at wire speed in a programmable packet processing pipeline of the data plane. Sensors, which can be processes implemented within the pipeline, can measure parameters of the network traffic flows and of the network appliance in accordance with monitoring policies. Reporting policies can be triggered when any one of many criteria are met by the parameters. The reporting policy can result in a report being sent to an outside recipient. Alternatively, the reporting policy can result in the network appliance implementing additional monitoring or reporting policies.