Network Infrastructure Pre-Filter Rules for Traffic Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deep packet inspection devices, such as IDS, IPS, and NGFWs, are slow relative to current network speeds and increasing their capacity to check all network data is expensive, making it challenging to effectively detect malware and other patterns in network traffic.

Innovation Solution

Implementing pre-filter rules on network infrastructure devices to selectively send packets to deep packet inspection devices for further scrutiny, using multiple subsets of rules across network devices to tag packets and route them intelligently, thereby reducing the load on single devices and enhancing detection efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep packet inspection devices are used to detect malware and patterns in network traffic, then detection capability is improved, but processing speed deteriorates relative to current network speeds

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidpacket processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments the network infrastructure into multiple devices, each implementing a subset of pre-filter rules. Instead of one device handling all deep packet inspection, the system divides the rule set across multiple devices, allowing parallel processing of network traffic while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies pre-filter rules to network packets before they reach deep packet inspection devices. This preliminary filtering action identifies and tags packets that require further inspection, reducing the volume of traffic that needs resource-intensive deep packet inspection and thereby improving overall processing speed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If deep packet inspection capacity is increased to check all network data, then detection capability is improved, but cost increases

Engineering Contradiction:
Improvenetwork security detectionVSAvoidinspection capacity requirement
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements partial inspection by applying pre-filter rules to all packets and reserving deep packet inspection only for tagged packets that match specific criteria. This partial action approach provides sufficient security detection for the majority of traffic without requiring full inspection capacity, thereby reducing cost while maintaining detection effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If pre-filter rules are implemented on network infrastructure devices, then processing speed is improved, but device complexity increases

Engineering Contradiction:
Improvepacket processing speedVSAvoidrule implementation complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the complex rule set into multiple subsets distributed across different network infrastructure devices. Each device implements only a portion of the total rules, reducing individual device complexity while collectively providing comprehensive pre-filtering capability across the network.

Inventive Principle:
Principle #1Segmentation

4Productivity

If multiple subsets of rules are distributed across network devices, then detection scalability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection scalabilityVSAvoiddistributed rule management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal tagging mechanism that works across multiple devices implementing different rule subsets. The tag structure and packet routing logic serve multiple functions: identifying matched rules, directing traffic flow, and enabling coordinated detection across the distributed system, thereby managing complexity through multi-functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3266156B1Network infrastructure device to implement pre-filter rules
Publication Date: 2022.11.23 HEWLETT PACKARD ENTERPRISE DEV LP
  • EP3266156B1 patent drawingFigure 1~2
  • EP3266156B1 patent drawingFigure 3~4
  • EP3266156B1 patent drawingFigure 5

AI summary

Example embodiments disclosed herein relate to implementing pre-filter rules at a network infrastructure device. In one example, the network infrastructure device receives a packet flow including a first pre-filter tag including information from implementation of a first subset of a set of pre-filter rules. In the example, the network infrastructure device includes logic to implement a second subset of the pre-filter rules. The second subset of pre-filter rules are different from the first subset of pre-filter rules. The second subset of pre-filter rules are implemented on the packet flow to yield a pre-filter result.