Router CPU Protection via ASIC Packet Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network devices, such as routers, face vulnerabilities due to overwhelming traffic from attacking hosts attempting to access management functions, which can overwhelm the CPU's ability to filter and authenticate access effectively.
Innovation Solution
The implementation of a management virtual local area network (MVLAN) is defined, where only communications through a designated management port can access management functions, with the ASIC and CAM-ACL filtering data packets on non-management ports to prevent unauthorized access and reduce CPU processing load.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the CPU filters and authenticates access attempts from all ports, then security is maintained, but the CPU becomes overwhelmed by large volumes of traffic from attacking hosts
Solution Approach 1:
The patent segments the network interface processing by separating packet filtering functions from CPU processing. The ASIC performs initial packet filtering and authentication for management traffic, dividing the workload so that only authenticated packets reach the CPU. This segmentation prevents the CPU from being overwhelmed by attack traffic while maintaining security validation.
Solution Approach 2:
The patent introduces an intermediary component (ASIC with CAM-ACL) that sits between the network ports and the CPU. This intermediary performs preliminary filtering of management traffic based on source IP addresses and authentication credentials before packets reach the CPU, acting as a mediator that protects the CPU from processing malicious traffic while allowing legitimate management access.
2Adaptability or versatility
If all ports are configured to accept management traffic, then management access flexibility is improved, but vulnerability to remote attacks increases
Solution Approach 1:
The patent applies local quality by implementing different access control characteristics for different ports. Each port can be individually configured with specific source IP address filters and authentication requirements stored in the CAM-ACL. This allows management access flexibility on authorized ports while simultaneously restricting access on other ports, effectively reducing the overall attack surface while maintaining necessary management capabilities.
Data Source
AI summary
A system and method that provides for protection of a CPU of a router, by establishing a management port on a router. Hosts which are connected to a non-management ports of the router are denied access to management functions of a CPU of the router. The system and method can utilize an application specific integrated circuit, in conjunction with a CAM-ACL, which analyzes data packets received on the ports of router, and the ASIC operates to drop data packets which are directed to the CPU of the router. This system and method operates to filter data packets which may be generated in attempts to hack in to control functions of a network device, and the operation does not require that the CPU analyze all received data packets in connection with determining access to the control functions of the router.


