Deep Packet Inspection Engine for Virtual Network Interface Controller Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual network firewalls lack the performance levels expected for secure operation on logical overlay networks, as they primarily offer transport layer and network layer security, falling short of the high throughput capabilities of physical devices with ASIC processors.

Innovation Solution

Implementing a deep packet inspection engine at the virtual network interface controller (VNIC) level that de-capsulates network traffic and utilizes a plurality of packet analyzers to perform security operations in parallel, generating recommendations for allowing or denying packets, thereby enhancing security features without relying on third-party appliances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual network firewalls operate on logical overlay networks using general purpose CPUs, then security coverage is improved, but performance throughput deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidperformance throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the firewall functionality into multiple independent packet analyzers that operate in parallel. Each analyzer handles specific security checks, allowing the system to process multiple packets simultaneously, thereby improving throughput while maintaining comprehensive security coverage on logical overlay networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new architectural dimension by implementing packet analyzers at the virtual network interface controller (VNIC) level rather than at higher software layers. This dimensional shift enables closer integration with the network stack, reducing overhead and improving performance while maintaining security effectiveness.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If physical devices with ASIC processors are used, then performance throughput is improved, but adaptability to logical overlay networks deteriorates

Engineering Contradiction:
Improveperformance throughputVSAvoidadaptability to logical overlay networks
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal packet analyzer architecture that can handle both physical network traffic and logical overlay network traffic. The analyzers are designed to work at the VNIC level, which is common to both physical and virtual networks, enabling the same hardware resources to serve multiple networking models simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses the virtual network interface controller (VNIC) as an intermediary between the physical network infrastructure and the logical overlay networks. The packet analyzers operate at this intermediary layer, allowing them to inspect traffic from logical overlay networks while leveraging the performance capabilities of physical network hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If deep packet inspection is implemented at VNIC level with multiple packet analyzers, then security effectiveness is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple packet analyzer functions into a unified architecture at the VNIC level. Rather than having separate security devices for different network layers, the system combines layer 2, layer 3, and layer 4 security functions into a single integrated packet inspection framework, reducing overall system complexity while improving security effectiveness.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11184324B2Deep packet inspection with enhanced data packet analyzers
Publication Date: 2021.11.23 VMWARE INC
  • US11184324B2 patent drawing
  • US11184324B2 patent drawing
  • US11184324B2 patent drawing

AI summary

Examples provide a deep packet inspection for performing security operations on network data packets by a plurality of enhanced packet analyzers. A copy of a mirrored network data packet is sent to each of the packet analyzers. Each packet analyzer performs one or more security operations on the copy in parallel, and generates an allow recommendation or a deny recommendation. If all the recommendations are allow recommendations, a virtual network interface controller (VNIC) routes the network data packet to its destination. If at least one of the recommendations is a deny recommendation, the VNIC discards the network data packet.