Network Processor Offloading Scanning Tasks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network scanning technologies, particularly in CPU-driven systems, face challenges in efficiently scanning large volumes of data from un-trusted networks while minimizing resource usage, leading to inadequate performance due to the need to drop data to prevent resource overload.

Innovation Solution

A system that employs a network processor, capable of receiving updates and offloading scanning tasks from the central processing unit, utilizing drivers and regular expressions to conditionally scan data based on file types, thereby optimizing resource usage and accelerating the scanning process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If CPU-driven scanning is used to ensure thorough security scanning, then scanning coverage is improved, but system resource consumption increases excessively

Engineering Contradiction:
Improvescanning coverageVSAvoidCPU resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent divides the scanning system into two segments: a network processor that performs initial data filtering and classification, and a CPU that performs detailed scanning only on high-risk files. This segmentation allows thorough scanning of critical files while filtering out low-risk files earlier in the process, reducing overall CPU resource consumption while maintaining scanning coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network processor as an intermediary component between the network interface and the CPU. This intermediary performs preliminary processing, classification, and filtering of network data, separating the high-volume data filtering task from the CPU to reduce its resource consumption while maintaining comprehensive scanning capability for risky files.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all data is scanned to maximize security, then security reliability is improved, but scanning speed decreases due to resource constraints

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidscanning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different scanning intensities to different types of files based on their risk profiles. High-risk files (executables, scripts) receive thorough scanning, while low-risk files (images, text documents) receive minimal or no scanning. This local differentiation of scanning quality maintains security reliability for critical files while significantly improving overall scanning speed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs partial scanning by filtering out low-risk files before detailed inspection. The network processor performs preliminary analysis and discards obviously safe files, allowing the system to process large volumes of data quickly while maintaining security through focused detailed scanning of only the necessary subset of files.

Inventive Principle:
Principle #16Partial or excessive action

3Use of energy by moving object

If conditional scanning based on file type is implemented to save resources, then resource efficiency is improved, but scanning precision may be reduced

Engineering Contradiction:
Improveresource efficiencyVSAvoidscanning precision
Core Design Contradiction:
Use of energy by moving objectVSMeasurement precision

Solution Approach 1:

The patent changes the parameter of scanning intensity based on file type parameters. Different file types receive different levels of scanning scrutiny - executables and scripts receive high-intensity scanning with multiple security checks, while images and text files receive low-intensity or skipped scanning. This parameter adjustment maintains resource efficiency while preserving scanning precision for high-risk file types.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8634309B2Security network processor system and method
Publication Date: 2014.01.21 MCAFEE LLC
  • US8634309B2 patent drawing
  • US8634309B2 patent drawing
  • US8634309B2 patent drawing

AI summary

A system, method and computer program product are provided for scanning data received from a computer network. Included is a central processing unit for processing data. Coupled between the central processing unit and a network is a network processor. Such network processor is capable of scanning data received from the network based on an update. Such network processor is further capable of receiving the update via the network.