Network Traffic Prioritized Matching Using Microcode State Machines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security and monitoring systems, including firewalls and anti-virus software, are inadequate in detecting new types of attacks and reacting to threats effectively, as they rely on outdated hardware architectures that are costly, inefficient, and inflexible, failing to provide comprehensive monitoring and rapid reaction capabilities for high-speed networks.

Innovation Solution

An apparatus utilizing microcode controlled state machines and a distribution circuit to process network traffic according to provisioned rules and policies, enabling prioritized matching and flexible, advanced network security and monitoring features, which includes granular traffic modifications and deep packet inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls and anti-virus software are used for network security, then basic filtering and virus detection are provided, but the systems cannot detect new types of attacks and lack flexibility in reaction capabilities

Engineering Contradiction:
Improvedetection capabilityVSAvoidreaction flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its behavior based on detected attack patterns. The monitoring apparatus learns from observed traffic patterns and automatically adjusts its detection rules and reaction strategies, transitioning from static signature-based detection to dynamic behavior-based detection that can identify new attack types without explicit signatures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes its operational parameters based on the type and severity of detected threats. Different detection thresholds, inspection depths, and reaction intensities are applied depending on the situation, allowing the system to optimize its detection capability while maintaining network performance and adapting to various attack scenarios.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If advanced security systems with multiple co-processors and content addressable memories are deployed, then enhanced monitoring and detection capabilities are achieved, but the cost and device complexity increase substantially

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring apparatus is designed as a universal platform that can perform multiple security functions including intrusion detection, traffic analysis, pattern recognition, and automated response. A single integrated system replaces the need for multiple specialized co-processors and content addressable memories, reducing overall complexity while maintaining comprehensive monitoring capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system incorporates automated self-learning and self-adjustment capabilities. The monitoring apparatus automatically analyzes traffic patterns, updates detection rules, and adjusts its operational parameters without requiring complex external configuration or management infrastructure, thereby reducing system complexity while enhancing monitoring effectiveness.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If hardware architectures are not customized for network security applications, then general-purpose computing resources are used, but performance becomes non-deterministic and validation is difficult

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidperformance predictability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs preliminary analysis and classification of network traffic using optimized algorithms and data structures that are pre-configured for security monitoring. By preparing detection patterns and classification rules in advance, the system achieves deterministic performance characteristics while maintaining the flexibility of software-based implementation on general-purpose hardware.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If memory hierarchy and complex queuing structures are added to support high bandwidth networks, then network performance degradation is avoided, but the device complexity and cost increase

Engineering Contradiction:
Improvenetwork throughputVSAvoidarchitecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The monitoring apparatus processes network traffic in a continuous stream without requiring complex buffering or queuing structures. By implementing efficient real-time analysis algorithms and maintaining continuous operation at wire speed, the system achieves high network throughput while avoiding the complexity of memory hierarchies and sophisticated queue management mechanisms.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8665868B2Apparatus and method for enhancing forwarding and classification of network traffic with prioritized matching and categorization
Publication Date: 2014.03.04 CPACKET NETWORKS
  • US8665868B2 patent drawing
  • US8665868B2 patent drawing
  • US8665868B2 patent drawing

AI summary

An apparatus is described that performs prioritized matching through processing of network traffic in accordance with provisioned rules and policies. The apparatus includes a plurality of microcode controlled state machines, and a distribution circuit that routes input data to the plurality of microcode controlled state machines, such that the plurality of microcode controlled state machines apply rules to the input data to determine matches and produce priority indicators, wherein each match has an associated priority indicator. At least one of the matches is selected based on the priority indicators. Advantageously, the apparatus provides an architectural framework well suited to a low cost, high speed, robust implementation of flexible, advanced network security and monitoring features and network traffic analysis.