Distributed Packet Flow Inspection Reducing Redundant Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In packet-switched networks, redundant packet inspection across multiple intrusion prevention system (IPS) units leads to duplicative processing cycles without added value, necessitating techniques to avoid redundant packet inspection.
Innovation Solution
A network architecture that distributes packet processing load across multiple packet processing devices, where one device detects if another has already processed packets, allowing it to skip redundant operations by using unique identifiers or network topology information to optimize processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple IPS units are distributed throughout a network to protect and segment the network, then network security coverage is improved, but redundant packet inspection occurs leading to increased processing overhead
Solution Approach 1:
The patent merges the packet inspection functionality across multiple IPS units by implementing a distributed filter set that is shared among all IPS devices. Each IPS unit receives copies of the same filter set from a master IPS, allowing them to coordinate their inspection efforts and avoid redundant processing of identical packets by multiple units.
Solution Approach 2:
The patent introduces a master IPS unit that acts as an intermediary between the network and the distributed IPS units. This master IPS maintains the authoritative filter set and distributes it to other IPS units, coordinating their operations to eliminate redundancy while maintaining comprehensive security coverage.
2Stability of the object's composition
If the same filter set is executed at each IPS unit, then consistent security policy enforcement is improved, but duplicative processing cycles increase without added value
Solution Approach 1:
The patent uses copying by distributing copies of the master filter set to multiple IPS units. Each IPS unit receives and executes identical copies of the filter set, ensuring consistent security policy enforcement across the network while allowing the system to track which packets have been processed to avoid duplicative work.
Solution Approach 2:
The patent implements feedback mechanisms where IPS units report packet processing status back to the system, enabling the coordination of filter execution. This feedback allows the network to track which packets have already been inspected by other IPS units, preventing duplicative processing cycles while maintaining policy consistency.
3Reliability
If packet processing is performed at every IPS unit in the network path, then security inspection thoroughness is improved, but traffic latency increases
Solution Approach 1:
The patent applies preliminary action by having the master IPS unit prepare and distribute the filter set to all IPS units in advance, before packets need to be processed. This preconfiguration allows IPS units to quickly determine whether they need to process a packet based on the distributed filter information, reducing per-packet processing time and latency while maintaining thorough security inspection.
Data Source
AI summary
Distribution of network processing load among a set of packet processing devices is improved by employing means for eliminating, controlling, or otherwise affecting redundant packet processing operations. In one embodiment, at least two packet processing devices are present, both capable of processing data packets flowing therethrough, such as, inspecting, detecting, and filtering data packets pursuant to one or more filters from a filter set. Redundancy is controlled by providing or enabling either or both of the packet processing devices with capability for detecting during its said inspection of said data packets that, for example, one or more filters had been previously executed on said data packets by the other packet processing device, and then not executing the previously-executed filters on said data packets.


