Packet Replication Device for Network Security Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional residential network gateways lack the capability to inspect user data traffic flows for security-related issues, failing to meet current network security requirements.
Innovation Solution
A network device with a classification engine, forwarding engine, and packet replication device that identifies packets in flows, replicates them, and forwards them to security engines for inspection without interfering with normal packet forwarding, using a packet replication method that calculates rates and checks flow tables to determine forwarding based on current and cumulative packet numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packet inspection is implemented in traditional residential gateway, then network security is improved, but packet forwarding function is interfered with or affected
Solution Approach 1:
The gateway device is segmented into functionally independent modules: a packet replication device that extracts packets from flows, a flow table for tracking flow states, and application engines for security inspection. This segmentation allows packet inspection to occur in parallel with normal packet forwarding through the forwarding engine, eliminating interference between security functions and forwarding operations.
Solution Approach 2:
A packet replication device acts as an intermediary between the forwarding engine and application engines. It retrieves packets from the forwarding engine and selectively replicates them to application engines based on flow table lookups, without disrupting the main packet forwarding path. This intermediary mechanism enables security inspection while preserving normal forwarding operations.
2Reliability
If packet replication is performed for all packets, then security inspection capability is improved, but processing overhead and system complexity increase
Solution Approach 1:
The system performs preliminary actions by maintaining a flow table that tracks the states of active flows before packets are inspected. When a packet arrives, the system first checks the flow table to determine if the packet belongs to an existing flow and what replication actions are needed, rather than processing every packet through the complete inspection pipeline. This preliminary filtering reduces unnecessary processing overhead.
Solution Approach 2:
Instead of replicating and inspecting all packets, the system performs partial action by selectively replicating only those packets that match flows in the flow table and require security inspection. The replication control circuit determines which packets to replicate based on flow state information, avoiding the excessive processing that would result from universal packet replication.
Data Source
AI summary
A network device and a packet replication method are provided. The network device includes a classification engine, a forwarding engine, and a packet replication device. The packet replication device includes an interface circuit, a replication control circuit, and a storage unit. The interface circuit retrieves a packet of a flow from the forwarding engine and correspondingly outputs a replicated packet to the replication control circuit. The replication control circuit calculates a current rate corresponding to the replicated packet, checks a flow table for a cumulative number of replicated packets of the flow, and determines, according to the current rate and the cumulative number of replicated packets, to forward the replicated packet. The storage unit stores the flow table. The replication control circuit transmits the replicated packet to at least one application engine through at least one communication port for security inspection.


