Configurable Network Security with Distributed IPS Modules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Dedicated hardware appliances face challenges with latency in processing network traffic, especially when inspecting traffic between modules within a server, and scalability issues as traffic increases, leading to performance bottlenecks.
Innovation Solution
A configurable network security apparatus with removable IPS data plane modules and a programmable switch module that distributes packet flows across multiple IPS data plane modules, using a network processing unit (NPU) and field-programmable gate array (FPGA) for high-performance, scalable, and distributed network security functionality, integrated into the server's switching fabric.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If dedicated hardware appliances are used for network security inspection, then performance is improved, but latency increases when inspecting traffic between modules within a server
Solution Approach 1:
The patent combines network security inspection functionality directly into the server's switching fabric by integrating IPS data plane modules and NPUs within the server chassis. This merging eliminates the need to route traffic outside the server for inspection, thereby maintaining high performance while reducing latency compared to external dedicated hardware appliances.
2Productivity
If dedicated hardware appliances are used for network security, then performance is improved, but scalability is limited as traffic increases
Solution Approach 1:
The patent segments the network security inspection function into multiple independent IPS data plane modules that can be distributed across the server's switching fabric. Each module can handle a portion of the traffic, allowing the system to scale horizontally by adding more modules as traffic increases, thereby overcoming the scalability limitations of traditional dedicated hardware appliances.
Solution Approach 2:
The system dynamically adapts to increasing traffic loads by enabling the addition of more IPS data plane modules and NPUs as needed. The configurable architecture allows the inspection capacity to grow with traffic demands, providing scalable performance that dedicated hardware appliances cannot match.
3Adaptability or versatility
If general purpose computers are used for network security inspection, then adaptability is improved, but performance is reduced compared to dedicated hardware appliances
Solution Approach 1:
The patent creates a universal platform within the server that can perform both general computing functions and specialized network security inspection. The configurable IPS data plane modules and NPUs provide dedicated hardware-level performance for security inspection while remaining integrated into the server's general-purpose architecture, thus achieving both adaptability and high performance.
Data Source
AI summary
According to an example, configurable network security may include receiving data flows directed to end node modules of a server, and selecting data flows from the received data flows based on an analysis of attributes of the received data flows. The selected data flows may be less than the received data flows. A number of IPS data plane modules of the server that are available for inspection of the selected data flows may be determined. The selected data flows may be distributed between the IPS data plane modules based on the determined number of the IPS data plane modules. The distributed data flows may be inspected using the IPS data plane modules to identify malicious and benign data flows, and to determine whether to drop the malicious data flows, direct the malicious data flows to a predetermined destination, or forward the benign data flows to the end node modules.


