Network Interface Card Packet Classification for Processor Overload

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network Functions (NF) and Virtual Network Functions (VNFs) face overload due to network traffic flooding, particularly from signaling storms and malicious attacks like Denial of Service (DoS) and Distributed Denial of Service (DDoS), leading to processor overload and unresponsiveness.

Innovation Solution

Modifying the frequency of operation of the uncore or system agent to manage congestion at the processor entry point, reducing the rate of packet processing and allocating additional power to CPU cores to handle packet backlogs, while employing intrusion detection systems to detect and mitigate malicious attacks by adjusting the frequency of the uncore and core interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the processor processes all received packets at high speed, then network throughput is improved, but the processor becomes overloaded and unresponsive during traffic flooding

Engineering Contradiction:
Improvenetwork throughputVSAvoidprocessor availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary classification of incoming packets at the network interface card (NIC) before they reach the processor. By identifying and marking suspicious packets early in the packet flow, the system prepares for potential attacks without requiring the processor to analyze every packet, thus maintaining processor availability while preserving network throughput for legitimate traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary classification mechanism at the NIC that acts as a buffer between the network interface and the processor. This intermediary layer filters and marks packets based on suspicious patterns, allowing the processor to focus only on unclassified or marked packets rather than processing every packet at full speed, thereby resolving the contradiction between throughput and processor availability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If intrusion detection analyzes every packet, then attack detection accuracy is improved, but processing time increases and network performance degrades

Engineering Contradiction:
Improveattack detection accuracyVSAvoidpacket processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies different processing qualities to different packets based on their characteristics. Legitimate packets receive minimal processing (quick pass-through), while packets exhibiting suspicious patterns undergo more thorough analysis. This localized quality approach maintains high detection accuracy for attacks while minimizing processing time for the majority of legitimate traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The classification mechanism changes parameters such as packet marking and priority levels based on detected patterns. By modifying packet parameters rather than performing full analysis on every packet, the system maintains detection accuracy for suspicious traffic while significantly reducing overall processing time and preserving network performance.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If packet filtering is applied at the processor, then security is improved, but additional processor resources are consumed during overload

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessor resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the primary packet classification and filtering function from the processor and relocates it to the network interface card. This extraction allows security-related filtering to occur before packets reach the processor, improving security without consuming additional processor resources during overload conditions. The processor only handles packets that require more complex analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20200374310A1Protection from network initiated attacks
Publication Date: 2020.11.26 INTEL CORP
  • US20200374310A1 patent drawing
  • US20200374310A1 patent drawing
  • US20200374310A1 patent drawing

AI summary

Examples described herein relate to a computing system that alters a frequency of operation of a peripheral device interface between a network interface card and a processor based on detection of a traffic violation. In some examples, a frequency of operation of a peripheral device interface is reduced based on detection of a traffic violation. In some examples, IP packet fragments can include one or more of: IP packet fragments that are incomplete packets, IP packet fragment that are too small, IP packet fragments that result in excessive packets, or IP packet fragmentation buffer being full. In some examples, detecting a traffic violation is based on detection of IP packet fragments at one or more of: a network appliance, the network interface card, uncore, system agent, operating system, application, or a computing platform. In some examples, the peripheral device interface includes one or more of: a system agent, an uncore, a bus, a device interface, and a cache. In some examples, the peripheral device interface is part of a system on a chip (SoC) and the SoC also includes one or more of: a core, system agent, or uncore.