Processor Traffic Segregation in Network Switches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network devices are vulnerable to denial-of-service (DoS) attacks, such as ARP packet flooding, which overwhelm the processor, disrupting routine user traffic and requiring costly and time-consuming manual diagnosis.
Innovation Solution
A network switch apparatus with a processor interface that segregates traffic by assigning processor codes with allowance flags, allowing only packets from specific protocols and source ports to reach the processor, while queuing and prioritizing others, and limiting packet rates to prevent overload.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the processor interface is included in all flooding domains to receive packets from any network interface, then the processor can handle all network traffic, but the processor becomes vulnerable to DoS attacks and overload
Solution Approach 1:
The patent segments processor traffic from general network traffic by creating a dedicated processor flooding domain that is separate from regular network flooding domains. This segmentation allows the processor to receive only authorized traffic while isolating it from DoS attacks affecting general network traffic.
Solution Approach 2:
The patent introduces an intermediary mechanism (the allowance flag and classifier) between network interfaces and the processor. This intermediary filters and controls which packets reach the processor, preventing direct exposure to malicious traffic while maintaining legitimate communication channels.
2Ease of operation
If all packets addressed to the processor are accepted from any network interface, then complete network accessibility is maintained, but the processor cannot distinguish between legitimate and malicious traffic
Solution Approach 1:
The patent performs preliminary authorization by setting an allowance flag in the packet header before packets reach the processor. This flag is set by the classifier based on pre-configured authorization rules, enabling the processor to quickly identify legitimate traffic without complex verification.
Solution Approach 2:
The patent modifies packet parameters by adding an allowance flag to the packet header. This parameter change enables automated differentiation between authorized and unauthorized traffic, transforming the processor's ability to detect legitimate packets from difficult to easy.
3Productivity
If the processor processes all network packets without filtering, then no packets are dropped, but network performance degrades under attack conditions
Solution Approach 1:
The patent extracts harmful traffic from the general packet flow by using the allowance flag to identify and separate authorized packets. Packets without the flag are dropped before reaching the processor, effectively removing the harmful DoS traffic while preserving legitimate communication.
Solution Approach 2:
The patent applies preliminary anti-action by preemptively dropping packets that lack the allowance flag before they can overwhelm the processor. This preventive measure counteracts DoS attacks by blocking malicious traffic in advance, maintaining processor productivity under attack conditions.
Data Source
AI summary
A network switch includes a memory to store associations between at least one flooding domain and a plurality of network interfaces. A classifier assigns a processor code to selected packets received at one or more of the network interfaces. The processor code includes a flag indicating if a packet is to be processed by a processor. A transfer circuit transfers packets among the network interfaces based on the associations and transfers the selected packets to the processor based on the processor code independently of transfer of packets to at least one flooding domain.


