Configurable Network Security with Distributed IPS Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Dedicated hardware appliances face challenges with latency in processing network traffic, especially when inspecting traffic between modules within a server, and scalability issues as traffic increases, leading to performance bottlenecks.

Innovation Solution

A configurable network security apparatus with removable IPS data plane modules and a programmable switch module that distributes packet flows across multiple IPS data plane modules, using a network processing unit (NPU) and field-programmable gate array (FPGA) for high-performance, scalable, and distributed network security functionality, integrated into the server's switching fabric.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If dedicated hardware appliances are used for network security inspection, then performance is improved, but latency increases when inspecting traffic between modules within a server

Engineering Contradiction:
Improvenetwork security inspection performanceVSAvoidlatency
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent combines network security inspection functionality directly into the server's switching fabric by integrating IPS data plane modules and NPUs within the server chassis. This merging eliminates the need to route traffic outside the server for inspection, thereby maintaining high performance while reducing latency compared to external dedicated hardware appliances.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If dedicated hardware appliances are used for network security, then performance is improved, but scalability is limited as traffic increases

Engineering Contradiction:
Improvenetwork security inspection performanceVSAvoidscalability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network security inspection function into multiple independent IPS data plane modules that can be distributed across the server's switching fabric. Each module can handle a portion of the traffic, allowing the system to scale horizontally by adding more modules as traffic increases, thereby overcoming the scalability limitations of traditional dedicated hardware appliances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adapts to increasing traffic loads by enabling the addition of more IPS data plane modules and NPUs as needed. The configurable architecture allows the inspection capacity to grow with traffic demands, providing scalable performance that dedicated hardware appliances cannot match.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If general purpose computers are used for network security inspection, then adaptability is improved, but performance is reduced compared to dedicated hardware appliances

Engineering Contradiction:
ImproveconfigurabilityVSAvoidnetwork security inspection performance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent creates a universal platform within the server that can perform both general computing functions and specialized network security inspection. The configurable IPS data plane modules and NPUs provide dedicated hardware-level performance for security inspection while remaining integrated into the server's general-purpose architecture, thus achieving both adaptability and high performance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10243988B2Configurable network security
Publication Date: 2019.03.26 TREND MICRO INC
  • US10243988B2 patent drawing
  • US10243988B2 patent drawing
  • US10243988B2 patent drawing

AI summary

According to an example, configurable network security may include receiving data flows directed to end node modules of a server, and selecting data flows from the received data flows based on an analysis of attributes of the received data flows. The selected data flows may be less than the received data flows. A number of IPS data plane modules of the server that are available for inspection of the selected data flows may be determined. The selected data flows may be distributed between the IPS data plane modules based on the determined number of the IPS data plane modules. The distributed data flows may be inspected using the IPS data plane modules to identify malicious and benign data flows, and to determine whether to drop the malicious data flows, direct the malicious data flows to a predetermined destination, or forward the benign data flows to the end node modules.