Packet Processing Distribution Algorithm for Network Appliance Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network appliances, such as intrusion prevention systems, often introduce latency and have slower throughput compared to traditional network devices like routers and switches, which can negatively impact real-time applications and overall network performance.

Innovation Solution

Implementing a distribution algorithm to bifurcate configuration instructions between a first logical entity, typically a network device, and a second logical entity, such as a network appliance, to efficiently coordinate packet processing, focusing the network appliance's efforts on pattern searches only when pre-conditions are met, thereby reducing work duplication and improving performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network appliances perform comprehensive packet processing, then security detection capability is improved, but throughput and latency performance deteriorate

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments packet processing into two distinct phases: a fast path for common packets that bypass deep inspection, and a slow path for suspicious packets requiring thorough analysis. This segmentation allows the network appliance to maintain high throughput for most traffic while performing comprehensive security checks only when necessary, resolving the contradiction between security detection capability and throughput.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by performing only the necessary level of packet inspection based on pre-established criteria. Rather than universally applying comprehensive analysis to all packets, the system applies deep inspection only to packets that meet specific suspicion thresholds, thereby improving throughput while maintaining adequate security detection for problematic traffic.

Inventive Principle:
Principle #16Partial or excessive action

2Adaptability or versatility

If network appliances replicate bridging and routing functions, then security service capability is improved, but processing speed and latency performance deteriorate

Engineering Contradiction:
Improvesecurity service capabilityVSAvoidprocessing speed
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The patent introduces a mediator mechanism that coordinates between the network appliance's security functions and the network infrastructure devices. The mediator handles the replication of bridging and routing functions while maintaining performance by using efficient data structures and algorithms, allowing the appliance to provide comprehensive security services without severely impacting processing speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes operational parameters by adjusting the level of processing applied to different packet types. By dynamically modifying processing depth based on packet characteristics and threat intelligence, the system can provide comprehensive security services when needed while maintaining fast processing speeds for benign traffic, thus resolving the contradiction between security capability and processing speed.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If more raw processing power is added to network appliances, then security detection capability is improved, but cost increases without proportional performance gain

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidcost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the most critical security detection functions from the general packet processing pipeline and implements them as specialized, optimized modules. By taking out only the essential security inspection capabilities and implementing them efficiently, the system achieves improved security detection capability without proportionally increasing hardware complexity or cost.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent substitutes mechanical processing power with intelligent software-based decision-making mechanisms. Instead of relying solely on increased raw processing capacity, the system uses sophisticated algorithms and data-driven approaches to identify and process only the packets that require attention, achieving better security detection with lower overall system complexity and cost.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS7849503B2Packet processing using distribution algorithms
Publication Date: 2010.12.07 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7849503B2 patent drawing
  • US7849503B2 patent drawing
  • US7849503B2 patent drawing

AI summary

Network devices, systems, and methods are provided for packet processing. One method includes receiving a checking functionality rule set as an input to a distribution algorithm. The method includes bifurcating and providing configuration instructions, as an output from the distribution algorithm, to a first logic plane associated with a first logical entity and a second logic plane associated with a second logical entity. A collaboration algorithm is used to provide processing coordination between the first logical entity and the second logical entity.