Network Security Controller for Dynamic DPI Allocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional deep packet inspection (DPI) deployments are limited by fixed 'bump-in-the-wire' configurations, which are costly and underutilized, failing to provide comprehensive network protection due to oversizing and high per-port costs, making it impractical to distribute multiple high-performance DPI devices across networks effectively.
Innovation Solution
A controller is employed to monitor and control network traffic, allowing network security devices to act as programmable services for multiple switches, optimizing workload and bandwidth usage by selecting the appropriate network security devices based on capabilities and workload, forming a pool of resources accessible to all network components, and dynamically reconfiguring policies to distribute traffic and resources efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional bump-in-the-wire DPI devices are deployed at fixed locations, then network security inspection is provided at specific points, but the solution is costly, underutilized, and limited in scale due to fixed port segments
Solution Approach 1:
The patent transforms fixed bump-in-the-wire DPI deployments into dynamic, programmable service instances that can be dynamically allocated to different network segments on demand. The system allows flexible deployment configurations where DPI services can be moved, scaled, and reconfigured without physical reinstallation, resolving the contradiction between providing reliable security inspection and maintaining deployment flexibility.
Solution Approach 2:
The patent creates a universal DPI service platform that can serve multiple network segments and topologies through a single pooled resource system. Instead of dedicated fixed devices for each segment, the system provides multi-functional DPI capabilities that can be dynamically assigned to various network locations, eliminating the need for separate fixed deployments at each segment while maintaining comprehensive security coverage.
2Reliability
If multiple DPI devices are distributed across the network to provide protection for specific physical links, then coverage is improved, but the per-port cost becomes high and deployment complexity increases
Solution Approach 1:
The patent merges multiple DPI device functions into a single pooled resource system that serves the entire network. Instead of distributing separate DPI devices to each network segment, the system combines DPI capabilities into a shared pool that can be dynamically allocated to multiple segments simultaneously, reducing overall device complexity while maintaining comprehensive coverage.
Solution Approach 2:
The patent introduces a controller as an intermediary component that manages the dynamic allocation of DPI services to network segments. This controller simplifies deployment complexity by centralizing the management logic, allowing automated policy-based distribution of security services without requiring manual configuration at each segment, thus reducing operational complexity while maintaining extensive coverage.
3Ease of manufacture
If fixed bump-in-the-wire DPI devices are used, then implementation is simple at each location, but the solution is oversized and underutilized leading to wasted resources
Solution Approach 1:
The patent implements dynamic resource allocation where DPI processing capacity is dynamically adjusted based on actual network traffic demands at each segment. Instead of fixed oversized devices that run at low utilization, the system dynamically scales resources up or down according to real-time needs, maintaining implementation simplicity through automated policy-based allocation while dramatically improving resource utilization efficiency.
Solution Approach 2:
The patent changes the fundamental parameter of DPI deployment from fixed physical installations to dynamic virtualized services. This allows the system to adjust processing parameters, allocation ratios, and resource capacities dynamically based on network conditions, transforming static oversized devices into flexible resources that adapt to actual workload requirements and eliminate resource waste.
4Reliability
If DPI devices are redeployed to different network segments, then coverage is improved, but the network becomes unprotected during the redeployment process
Solution Approach 1:
The patent ensures continuous security protection during redeployment by maintaining active DPI service instances in the pool that can be dynamically reassigned. Instead of taking devices offline for redeployment, the system continuously allocates active service instances to all network segments, ensuring uninterrupted security coverage while enabling flexible reconfiguration of the underlying infrastructure.
Data Source
AI summary
An example of a computing system is described herein. The computing system includes a plurality of network security devices. The computing system also includes a network switch configured to direct network traffic. The computing system further includes a controller coupled to the network switch. The controller is to instruct the network switch in directing network traffic to the plurality of network security devices.


