Distributed Packet Flow Inspection Reducing Redundant Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In packet-switched networks, redundant packet inspection across multiple intrusion prevention system (IPS) units leads to duplicative processing cycles without added value, necessitating techniques to avoid redundant packet inspection.

Innovation Solution

A network architecture that distributes packet processing load across multiple packet processing devices, where one device detects if another has already processed packets, allowing it to skip redundant operations by using unique identifiers or network topology information to optimize processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple IPS units are distributed throughout a network to protect and segment the network, then network security coverage is improved, but redundant packet inspection occurs leading to increased processing overhead

Engineering Contradiction:
Improvenetwork security coverageVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges the packet inspection functionality across multiple IPS units by implementing a distributed filter set that is shared among all IPS devices. Each IPS unit receives copies of the same filter set from a master IPS, allowing them to coordinate their inspection efforts and avoid redundant processing of identical packets by multiple units.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a master IPS unit that acts as an intermediary between the network and the distributed IPS units. This master IPS maintains the authoritative filter set and distributes it to other IPS units, coordinating their operations to eliminate redundancy while maintaining comprehensive security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If the same filter set is executed at each IPS unit, then consistent security policy enforcement is improved, but duplicative processing cycles increase without added value

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidpacket processing efficiency
Core Design Contradiction:
Stability of the object's compositionVSProductivity

Solution Approach 1:

The patent uses copying by distributing copies of the master filter set to multiple IPS units. Each IPS unit receives and executes identical copies of the filter set, ensuring consistent security policy enforcement across the network while allowing the system to track which packets have been processed to avoid duplicative work.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements feedback mechanisms where IPS units report packet processing status back to the system, enabling the coordination of filter execution. This feedback allows the network to track which packets have already been inspected by other IPS units, preventing duplicative processing cycles while maintaining policy consistency.

Inventive Principle:
Principle #23Feedback

3Reliability

If packet processing is performed at every IPS unit in the network path, then security inspection thoroughness is improved, but traffic latency increases

Engineering Contradiction:
Improvesecurity inspection thoroughnessVSAvoidtraffic latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the master IPS unit prepare and distribute the filter set to all IPS units in advance, before packets need to be processed. This preconfiguration allows IPS units to quickly determine whether they need to process a packet based on the distributed filter information, reducing per-packet processing time and latency while maintaining thorough security inspection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8782787B2Distributed packet flow inspection and processing
Publication Date: 2014.07.15 TREND MICRO INC
  • US8782787B2 patent drawing
  • US8782787B2 patent drawing
  • US8782787B2 patent drawing

AI summary

Distribution of network processing load among a set of packet processing devices is improved by employing means for eliminating, controlling, or otherwise affecting redundant packet processing operations. In one embodiment, at least two packet processing devices are present, both capable of processing data packets flowing therethrough, such as, inspecting, detecting, and filtering data packets pursuant to one or more filters from a filter set. Redundancy is controlled by providing or enabling either or both of the packet processing devices with capability for detecting during its said inspection of said data packets that, for example, one or more filters had been previously executed on said data packets by the other packet processing device, and then not executing the previously-executed filters on said data packets.