Processor Traffic Segregation in Network Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network devices are vulnerable to denial-of-service (DoS) attacks, such as ARP packet flooding, which overwhelm the processor, disrupting routine user traffic and requiring costly and time-consuming manual diagnosis.

Innovation Solution

A network switch apparatus with a processor interface that segregates traffic by assigning processor codes with allowance flags, allowing only packets from specific protocols and source ports to reach the processor, while queuing and prioritizing others, and limiting packet rates to prevent overload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the processor interface is included in all flooding domains to receive packets from any network interface, then the processor can handle all network traffic, but the processor becomes vulnerable to DoS attacks and overload

Engineering Contradiction:
Improveprocessor traffic handling capabilityVSAvoidprocessor availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments processor traffic from general network traffic by creating a dedicated processor flooding domain that is separate from regular network flooding domains. This segmentation allows the processor to receive only authorized traffic while isolating it from DoS attacks affecting general network traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the allowance flag and classifier) between network interfaces and the processor. This intermediary filters and controls which packets reach the processor, preventing direct exposure to malicious traffic while maintaining legitimate communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If all packets addressed to the processor are accepted from any network interface, then complete network accessibility is maintained, but the processor cannot distinguish between legitimate and malicious traffic

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidtraffic authorization verification
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary authorization by setting an allowance flag in the packet header before packets reach the processor. This flag is set by the classifier based on pre-configured authorization rules, enabling the processor to quickly identify legitimate traffic without complex verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent modifies packet parameters by adding an allowance flag to the packet header. This parameter change enables automated differentiation between authorized and unauthorized traffic, transforming the processor's ability to detect legitimate packets from difficult to easy.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If the processor processes all network packets without filtering, then no packets are dropped, but network performance degrades under attack conditions

Engineering Contradiction:
Improvepacket processing throughputVSAvoidDoS attack impact
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts harmful traffic from the general packet flow by using the allowance flag to identify and separate authorized packets. Packets without the flag are dropped before reaching the processor, effectively removing the harmful DoS traffic while preserving legitimate communication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies preliminary anti-action by preemptively dropping packets that lack the allowance flag before they can overwhelm the processor. This preventive measure counteracts DoS attacks by blocking malicious traffic in advance, maintaining processor productivity under attack conditions.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS8537823B1Processor traffic segregation for network switching and routing
Publication Date: 2013.09.17 MARVELL ASIA PTE LTD
  • US8537823B1 patent drawing
  • US8537823B1 patent drawing
  • US8537823B1 patent drawing

AI summary

A network switch includes a memory to store associations between at least one flooding domain and a plurality of network interfaces. A classifier assigns a processor code to selected packets received at one or more of the network interfaces. The processor code includes a flag indicating if a packet is to be processed by a processor. A transfer circuit transfers packets among the network interfaces based on the associations and transfers the selected packets to the processor based on the processor code independently of transfer of packets to at least one flooding domain.