Network Infrastructure Pre-Filter Rules for Traffic Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deep packet inspection devices, such as IDS, IPS, and NGFWs, are slow relative to current network speeds and increasing their capacity to check all network data is expensive, making it challenging to effectively detect malware and other patterns in network traffic.
Innovation Solution
Implementing pre-filter rules on network infrastructure devices to selectively send packets to deep packet inspection devices for further scrutiny, using multiple subsets of rules across network devices to tag packets and route them intelligently, thereby reducing the load on single devices and enhancing detection efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If deep packet inspection devices are used to detect malware and patterns in network traffic, then detection capability is improved, but processing speed deteriorates relative to current network speeds
Solution Approach 1:
The patent segments the network infrastructure into multiple devices, each implementing a subset of pre-filter rules. Instead of one device handling all deep packet inspection, the system divides the rule set across multiple devices, allowing parallel processing of network traffic while maintaining comprehensive detection coverage.
Solution Approach 2:
The patent applies pre-filter rules to network packets before they reach deep packet inspection devices. This preliminary filtering action identifies and tags packets that require further inspection, reducing the volume of traffic that needs resource-intensive deep packet inspection and thereby improving overall processing speed.
2Reliability
If deep packet inspection capacity is increased to check all network data, then detection capability is improved, but cost increases
Solution Approach 1:
The patent implements partial inspection by applying pre-filter rules to all packets and reserving deep packet inspection only for tagged packets that match specific criteria. This partial action approach provides sufficient security detection for the majority of traffic without requiring full inspection capacity, thereby reducing cost while maintaining detection effectiveness.
3Speed
If pre-filter rules are implemented on network infrastructure devices, then processing speed is improved, but device complexity increases
Solution Approach 1:
The patent segments the complex rule set into multiple subsets distributed across different network infrastructure devices. Each device implements only a portion of the total rules, reducing individual device complexity while collectively providing comprehensive pre-filtering capability across the network.
4Productivity
If multiple subsets of rules are distributed across network devices, then detection scalability is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal tagging mechanism that works across multiple devices implementing different rule subsets. The tag structure and packet routing logic serve multiple functions: identifying matched rules, directing traffic flow, and enabling coordinated detection across the distributed system, thereby managing complexity through multi-functionality.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
Example embodiments disclosed herein relate to implementing pre-filter rules at a network infrastructure device. In one example, the network infrastructure device receives a packet flow including a first pre-filter tag including information from implementation of a first subset of a set of pre-filter rules. In the example, the network infrastructure device includes logic to implement a second subset of the pre-filter rules. The second subset of pre-filter rules are different from the first subset of pre-filter rules. The second subset of pre-filter rules are implemented on the packet flow to yield a pre-filter result.