Multi-Layer Network Security Appliance with Parallel Protocol Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security methods often sacrifice thoroughness for speed or vice versa, leading to bottlenecks that degrade network performance when defending against malicious codes and unauthorized data packets.

Innovation Solution

A network security appliance comprising a logic circuit, network processing unit, and general purpose processor that scans incoming data packets at different layers of the OSI protocol stack, utilizing hardware-based scanners for fast threat detection and software-based processors for thorough malicious code scanning, allowing for parallel and pipelined operations to minimize impact on data transfer rates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If thorough malicious code scanning is performed at all layers of the OSI protocol stack, then detection reliability is improved, but data transfer rate deteriorates due to processing bottleneck

Engineering Contradiction:
Improvedetection reliabilityVSAvoiddata transfer rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The scanning process is divided into multiple independent layers (physical, data link, network, transport, application layers) that can be processed simultaneously. Each layer has dedicated scanning logic that operates in parallel, allowing thorough multi-layer scanning without creating a single processing bottleneck that would reduce data transfer rate.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from sequential scanning (one layer at a time) to parallel scanning across multiple layers simultaneously. By adding the dimension of concurrent multi-layer processing, the system achieves both thorough detection and maintained data transfer rates through hardware-based parallel scanning engines.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If hardware-based fast scanning is used, then data transfer rate is maintained, but scanning thoroughness deteriorates

Engineering Contradiction:
Improvedata transfer rateVSAvoidscanning thoroughness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The hardware-based scanning system is designed to perform multiple scanning functions across different OSI layers simultaneously. The same hardware platform executes both fast scanning operations and thorough multi-layer analysis, eliminating the need to choose between speed and comprehensiveness by making the scanning system universally capable of handling both requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary scanning at lower layers (physical, data link) before proceeding to higher layers. This preliminary action filters out obviously malicious packets early, allowing the thorough scanning of remaining packets at higher layers to be both fast and comprehensive, as the workload is distributed rather than concentrated.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multi-layer protocol scanning is implemented, then detection thoroughness is improved, but device complexity increases

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidscanning system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex software-based multi-layer scanning with hardware-based scanning logic. By implementing scanning functions in dedicated hardware circuits rather than software, the system reduces the operational complexity of managing multiple scanning threads and processes, while maintaining thorough multi-layer detection capability through hardware parallelism.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8656488B2Method and apparatus for securing a computer network by multi-layer protocol scanning
Publication Date: 2014.02.18 TREND MICRO INC
  • US8656488B2 patent drawing
  • US8656488B2 patent drawing
  • US8656488B2 patent drawing

AI summary

In one embodiment, a network security appliance includes a logic circuit, a network processing unit, and a general purpose processor to protect a computer network from malicious codes, unauthorized data packets, and other network security threats. The logic circuit may include one or more programmable logic devices configured to scan incoming data packets at different layers of a multi-layer protocol, such as the OSI-seven layer model. The network processing unit may work in conjunction with the logic circuit to perform protocol parsing, to form higher layer data units from the data packets, and other network communications-related tasks. The general purpose processor may execute software for performing functions not available from the logic circuit or the network processing unit. For example, the general purpose processor may remove malicious code from infected data or perform malicious code scanning on data when the logic circuit is not configured to do so.