Load Balancer for Scalable Network Security Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Communications networks face challenges in scaling network security infrastructure to handle increasing traffic volumes effectively, as existing solutions either require larger capacity appliances (scale up) or spread security tasks across multiple appliances (scale out), but these approaches may not efficiently manage load balancing and packet processing.
Innovation Solution
A system and method that utilize a load balancer to determine the optimal instance of a security application for processing bidirectional packet flows based on relative loading, ensuring stateful load balancing and efficient distribution across multiple instances, while maintaining transparency to network nodes at and above the layer 2 data link layer of the Open Systems Interconnect model.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network security infrastructure scales up by using larger capacity appliances, then security processing capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent segments the network security function into multiple identical instances running on a host machine, each capable of independent packet flow processing. Instead of using a single large-capacity appliance, the system divides the security processing task across multiple smaller instances, thereby improving overall processing capability while avoiding the complexity and cost associated with scaling up a single appliance.
Solution Approach 2:
The patent merges multiple identical security application instances on a single host machine to achieve scalable security processing. By combining the processing power of multiple instances and using a load balancer to distribute traffic, the system achieves enhanced security capability without requiring multiple separate physical appliances, thus reducing complexity.
2Productivity
If network security infrastructure scales out by spreading security tasks across multiple appliances, then processing capacity is improved, but load balancing complexity increases
Solution Approach 1:
The load balancer in the patent is designed as a universal component that can distribute traffic to multiple identical security application instances using simple routing rules. Rather than implementing complex load balancing logic across heterogeneous appliances, the system uses a universal load balancer that works with any number of identical instances, thereby increasing processing capacity while minimizing load balancing complexity.
Solution Approach 2:
The patent employs multiple identical instances of the security application, ensuring homogeneity in the system architecture. This homogeneity simplifies load balancing because the load balancer only needs to distribute traffic based on simple criteria (such as instance availability) rather than managing complex differences between heterogeneous appliances, thus improving processing capacity without significantly increasing load balancing complexity.
3Adaptability or versatility
If multiple instances of security application are used, then scalability is improved, but packet flow management complexity increases
Solution Approach 1:
The load balancer serves as an intermediary between the external network and multiple security application instances. It manages all packet flow distribution to instances, absorbing the complexity of flow management internally. This allows the system to scale by simply adding more instances without increasing the complexity visible to external systems, as the load balancer continues to handle all flow management uniformly.
Solution Approach 2:
Each security application instance operates independently and autonomously, managing its own packet processing without requiring complex coordination with other instances. The instances self-serve by handling their assigned traffic independently, which simplifies overall flow management. The load balancer simply directs traffic to available instances without needing to manage state across instances, enabling easy scalability.
Data Source
AI summary
The present disclosure relates to scalable network security functions and handling of packet flows between network security zones in a communications network. Packets that are part of a bidirectional packet flow between the network security zones are received, and a determination is made as to an instance of a security application to which to assign the bidirectional packet flow for security processing. The determination is made based on relative loading of a plurality of identical instances of the security application running on a host machine. All of the received packets that are part of the bidirectional packet flow are directed for processing on the host machine by the one of the security application instances.


