PCIe Traffic Anomaly Detection via Hardware Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security of PCIe topologies in integrated systems with devices from different vendors is compromised due to varying attack methods, and software-only solutions fail to meet performance and latency requirements in high-speed PCIe networks.

Innovation Solution

A traffic anomaly detector is implemented within the PCIe controller, comprising filters, a classifier, event counters, a push controller, read counters, a reset controller, and a trigger controller to monitor and respond to anomalies in PCIe transaction layer packets, generating metadata for evaluation by software to maintain network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-only solutions are used to monitor PCIe traffic patterns, then security assessment capability is provided, but performance and latency requirements are not met due to high data rates

Engineering Contradiction:
Improvesecurity assessment capabilityVSAvoidperformance and latency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The monitoring function is segmented into two parts: a hardware-based anomaly detector in the PCIe controller that performs initial filtering and detection of suspicious traffic patterns, and a software-based analysis component that processes only the flagged anomalies. This segmentation allows the high-speed hardware to handle the time-critical monitoring tasks while the software provides comprehensive security assessment, thus meeting both performance and security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary hardware anomaly detector is introduced between the PCIe traffic and the software security analysis system. This intermediary performs real-time filtering and generates condensed anomaly reports, acting as a buffer that protects the software system from being overwhelmed by high-speed traffic while still providing accurate security assessment capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If continuous monitoring of PCIe traffic patterns is implemented, then security threats are detected, but system complexity increases

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-configuring filter criteria and anomaly detection rules in the hardware controller before monitoring begins. The hardware anomaly detector is pre-programmed with security policies and traffic pattern signatures, enabling it to automatically identify and flag suspicious activities without requiring complex real-time software analysis for every packet, thus reducing overall system complexity while maintaining detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The PCIe controller's anomaly detector is designed to be self-service by autonomously monitoring traffic patterns, comparing them against predefined criteria, and generating anomaly reports without requiring continuous external control or complex coordination with other system components. This self-contained approach reduces system complexity while providing continuous security monitoring.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12034749B2Anamoly detection system for peripheral component interconnect express
Publication Date: 2024.07.09 INFINEON TECHNOLOGIES AG
  • US12034749B2 patent drawing
  • US12034749B2 patent drawing
  • US12034749B2 patent drawing

AI summary

A traffic anomaly detector of a Peripheral Component Interconnect express (PCIe) system, including filters configured to filter headers of PCIe transaction layer packets (TLPs) based on respective filter criterion; a classifier configured to trigger an event based on one of the filter criterion or a logical combination of a plurality of the filter criteria; an event counter configured to count a number of the events; and a processor configured to detect, based on a value of the event counter, an anomaly in the PCIe TLP traffic.