Network Interface Card FPGA Packet Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security nodes face challenges in processing high levels of network traffic to identify threats without degrading performance, as they often lack sufficient processing capabilities and may be overwhelmed by analyzing each packet, hindering other functions such as monitoring and routing.
Innovation Solution
Implementing a distributed reputation database system where network interface cards with field programmable gate arrays (FPGAs) offload processing tasks, allowing for efficient packet filtering and threat identification, and transmitting reputation data to a security control center, thereby reducing the load on main processing components and enabling more thorough analysis of network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network nodes perform cursory analysis of each network packet to identify threats, then network security is improved, but node performance degrades
Solution Approach 1:
The patent segments the network security system into multiple distributed reputation database instances deployed across different network nodes. Each node maintains a local instance that can independently filter packets without requiring centralized processing, thereby improving security while maintaining node performance through distributed parallel processing
Solution Approach 2:
The patent introduces reputation data as an intermediary mechanism that enables network nodes to make security decisions without direct communication with centralized authorities. Nodes use locally cached reputation information to quickly determine whether to drop or forward packets, eliminating the need for real-time centralized verification and preserving node performance
2Measurement precision
If network nodes thoroughly analyze network packets for security, then threat detection capability is improved, but processing resources are consumed
Solution Approach 1:
The patent implements preliminary action by pre-computing and caching reputation data in distributed database instances at network nodes before actual packet filtering is needed. This allows nodes to perform quick lookups rather than thorough real-time analysis, maintaining high threat detection capability while minimizing processing resource consumption during operational phases
Solution Approach 2:
The patent applies local quality by enabling each network node to maintain customized local instances of the reputation database with locally relevant filtering rules. Nodes can tailor their security analysis depth based on local traffic patterns and threat profiles, optimizing the balance between detection precision and resource usage for each specific node
Data Source
AI summary
Embodiments relate to systems, computer readable media, devices, and computer-implemented methods for providing improved network security by receiving a network packet, applying a filter rule in a first instance of a distributed reputation database to the network packet, determining, using a network interface card with a field programmable gate array, to drop or modify the network packet based on the applying, and transmitting reputation data to a security control center that includes a second instance of the distributed reputation database, where the reputation data includes information corresponding to the network packet that was dropped or modified.


