Network Security Device Traffic Analysis Controller Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security devices face limitations in processing speed and efficiency due to simultaneous demands on processor resources for packet processing and static analysis, especially when handling high-rate network traffic, leading to reduced detection efficacy.
Innovation Solution
A system with a traffic analysis controller (TAC) and threat detection and prevention (TDP) logic, where packet processing and static analysis are compartmentalized, with the TAC using a network processing unit for hardware acceleration and offloading processor-intensive tasks from the host CPU, allowing for scalable processing and increased speed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If packet processing, static analysis and dynamic analysis are performed by a single processor, then the device structure is simple, but the processing speed and detection efficacy are reduced due to resource contention
Solution Approach 1:
The patent divides the network security device into two separate logical units: a traffic analysis controller (TAC) with a network processing unit for packet processing and static analysis, and a host with a processor for dynamic analysis. This segmentation allows each unit to operate independently without resource contention, thereby improving processing speed while maintaining manageable device complexity through modular architecture.
Solution Approach 2:
The patent extracts packet processing and static analysis functions from the host processor and places them in a separate traffic analysis controller. This extraction removes the resource contention bottleneck, allowing the host processor to focus on dynamic analysis while the NPU handles packet processing, thus improving overall processing speed and detection efficacy.
2Area of stationary object
If packet processing and static analysis are performed simultaneously on the same processor, then the device is compact, but the detection efficacy is reduced when handling high-rate network traffic
Solution Approach 1:
The patent segments the analysis functions into two separate units: the TAC for packet processing and static analysis, and the host for dynamic analysis. This segmentation ensures that each unit has dedicated resources, improving detection efficacy for high-rate traffic while maintaining a compact overall device structure through integrated modular design.
Solution Approach 2:
The traffic analysis controller acts as an intermediary between the network traffic and the host processor. It performs packet processing and static analysis first, then passes selected traffic to the host for dynamic analysis. This intermediary approach improves detection efficacy by filtering traffic before it reaches the host, reducing the load and improving overall system reliability.
3Ease of operation
If a single processor handles all analysis tasks, then the system is simple to manage, but the processing efficiency decreases due to processes waiting for processor resources
Solution Approach 1:
The patent segments processing tasks into two independent units with separate processors: the TAC for packet processing and static analysis, and the host for dynamic analysis. This segmentation eliminates process waiting times and resource contention, improving processing efficiency while maintaining simple management through standardized interfaces and protocols between the two units.
Data Source
AI summary
According to one embodiment, a system features a network security device and a cloud computing service. The network security device is configured to determine whether an object includes one or more characteristics associated with a malicious attack. The cloud computing service, communicatively coupled to and remotely located from the network security device, includes virtual execution logic that, upon execution by a processing unit deployed as part of the cloud computing service and after the network security device determining that the object includes the one or more characteristics associated with the malicious attack, processes the object and monitors for behaviors of at least the object suggesting the object is associated with a malicious attack.


