Deep Packet Inspection Engine for Virtual Network Interface Controller Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtual network firewalls lack the performance levels expected for secure operation on logical overlay networks, as they primarily offer transport layer and network layer security, falling short of the high throughput capabilities of physical devices with ASIC processors.
Innovation Solution
Implementing a deep packet inspection engine at the virtual network interface controller (VNIC) level that de-capsulates network traffic and utilizes a plurality of packet analyzers to perform security operations in parallel, generating recommendations for allowing or denying packets, thereby enhancing security features without relying on third-party appliances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual network firewalls operate on logical overlay networks using general purpose CPUs, then security coverage is improved, but performance throughput deteriorates
Solution Approach 1:
The patent segments the firewall functionality into multiple independent packet analyzers that operate in parallel. Each analyzer handles specific security checks, allowing the system to process multiple packets simultaneously, thereby improving throughput while maintaining comprehensive security coverage on logical overlay networks.
Solution Approach 2:
The patent introduces a new architectural dimension by implementing packet analyzers at the virtual network interface controller (VNIC) level rather than at higher software layers. This dimensional shift enables closer integration with the network stack, reducing overhead and improving performance while maintaining security effectiveness.
2Productivity
If physical devices with ASIC processors are used, then performance throughput is improved, but adaptability to logical overlay networks deteriorates
Solution Approach 1:
The patent creates a universal packet analyzer architecture that can handle both physical network traffic and logical overlay network traffic. The analyzers are designed to work at the VNIC level, which is common to both physical and virtual networks, enabling the same hardware resources to serve multiple networking models simultaneously.
Solution Approach 2:
The patent uses the virtual network interface controller (VNIC) as an intermediary between the physical network infrastructure and the logical overlay networks. The packet analyzers operate at this intermediary layer, allowing them to inspect traffic from logical overlay networks while leveraging the performance capabilities of physical network hardware.
3Reliability
If deep packet inspection is implemented at VNIC level with multiple packet analyzers, then security effectiveness is improved, but device complexity increases
Solution Approach 1:
The patent merges multiple packet analyzer functions into a unified architecture at the VNIC level. Rather than having separate security devices for different network layers, the system combines layer 2, layer 3, and layer 4 security functions into a single integrated packet inspection framework, reducing overall system complexity while improving security effectiveness.
Data Source
AI summary
Examples provide a deep packet inspection for performing security operations on network data packets by a plurality of enhanced packet analyzers. A copy of a mirrored network data packet is sent to each of the packet analyzers. Each packet analyzer performs one or more security operations on the copy in parallel, and generates an allow recommendation or a deny recommendation. If all the recommendations are allow recommendations, a virtual network interface controller (VNIC) routes the network data packet to its destination. If at least one of the recommendations is a deny recommendation, the VNIC discards the network data packet.


