Dynamic Security Operation Reordering for Network Throughput

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security devices have static ordering of security operations, which limits their performance and throughput, as they do not adapt to specific network traffic patterns, leading to inefficient processing of malicious packets and wastage of CPU cycles.

Innovation Solution

The method involves dynamically reordering security operations based on the rate of dropped malicious packets, prioritizing those that effectively detect and drop such packets, thereby optimizing CPU usage and improving throughput.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If static ordering of security operations is used, then device complexity is reduced and ease of operation is improved, but productivity is limited and cannot adapt to specific network traffic patterns

Engineering Contradiction:
ImprovethroughputVSAvoiddynamic reordering mechanism
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic reordering of security operations based on real-time network traffic patterns and attack detection rates. The system continuously monitors packet drop rates across different security operations and adjusts their execution order dynamically, transforming the static processing pipeline into an adaptive system that optimizes throughput for current traffic conditions

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs feedback mechanisms by monitoring packet drop rates from each security operation and using this information to adjust the ordering of subsequent operations. The feedback loop captures performance metrics from each security plugin and uses them to dynamically reorder operations, creating a self-optimizing system that responds to actual network conditions

Inventive Principle:
Principle #23Feedback

2Productivity

If CPU processing power is increased to handle more packets, then productivity is improved, but loss of energy increases and processing cycles are wasted on malicious packets

Engineering Contradiction:
Improvepacket processing capacityVSAvoidCPU processing cycles
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent places high-priority security operations that can quickly detect malicious packets at the beginning of the processing pipeline. By performing preliminary detection with operations having high packet drop rates for malicious traffic, the system eliminates attacking packets early before they consume CPU cycles in subsequent processing stages

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies different processing strategies to different types of packets by dynamically ordering security operations based on traffic patterns. Legitimate packets receive optimized processing through the reordered pipeline, while malicious packets are identified and dropped early by specific high-priority operations, applying quality differentiation to processing intensity

Inventive Principle:
Principle #3Local quality

3Productivity

If early detection of malicious packets is implemented, then productivity is improved by skipping redundant processing, but device complexity increases due to monitoring and analysis mechanisms

Engineering Contradiction:
Improveefficient packet processingVSAvoidmonitoring and reordering system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The security operations themselves provide the monitoring data needed for reordering by reporting their own packet drop rates. Each security plugin inherently generates performance metrics about its effectiveness, and the system uses this self-reported data to dynamically adjust ordering, eliminating the need for external monitoring infrastructure

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7765591B2Method and system for prioritizing security operations in a communication network
Publication Date: 2010.07.27 CISCO TECHNOLOGY INC
  • US7765591B2 patent drawing
  • US7765591B2 patent drawing
  • US7765591B2 patent drawing

AI summary

A method, system and apparatus for filtering data packets through an integrated network security device are provided. Various security operations are performed on the data packets belonging to a network connection while they pass through the integrated network security device in a communication network. A classification engine is applied to the first packet of the connection. The result of this filtering is stored in a per-connection control key, and determines which of the security operations must be applied to each of the data packets of the connection. These security operations may be prioritized and re-ordered, based on the rate at which they detect and drop malicious data packets.