Router CPU Protection via ASIC Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices, such as routers, face vulnerabilities due to overwhelming traffic from attacking hosts attempting to access management functions, which can overwhelm the CPU's ability to filter and authenticate access effectively.

Innovation Solution

The implementation of a management virtual local area network (MVLAN) is defined, where only communications through a designated management port can access management functions, with the ASIC and CAM-ACL filtering data packets on non-management ports to prevent unauthorized access and reduce CPU processing load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the CPU filters and authenticates access attempts from all ports, then security is maintained, but the CPU becomes overwhelmed by large volumes of traffic from attacking hosts

Engineering Contradiction:
ImprovesecurityVSAvoidCPU processing capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network interface processing by separating packet filtering functions from CPU processing. The ASIC performs initial packet filtering and authentication for management traffic, dividing the workload so that only authenticated packets reach the CPU. This segmentation prevents the CPU from being overwhelmed by attack traffic while maintaining security validation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component (ASIC with CAM-ACL) that sits between the network ports and the CPU. This intermediary performs preliminary filtering of management traffic based on source IP addresses and authentication credentials before packets reach the CPU, acting as a mediator that protects the CPU from processing malicious traffic while allowing legitimate management access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If all ports are configured to accept management traffic, then management access flexibility is improved, but vulnerability to remote attacks increases

Engineering Contradiction:
Improvemanagement access flexibilityVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing different access control characteristics for different ports. Each port can be individually configured with specific source IP address filters and authentication requirements stored in the CAM-ACL. This allows management access flexibility on authorized ports while simultaneously restricting access on other ports, effectively reducing the overall attack surface while maintaining necessary management capabilities.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7774833B1System and method for protecting CPU against remote access attacks
Publication Date: 2010.08.10 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US7774833B1 patent drawing
  • US7774833B1 patent drawing
  • US7774833B1 patent drawing

AI summary

A system and method that provides for protection of a CPU of a router, by establishing a management port on a router. Hosts which are connected to a non-management ports of the router are denied access to management functions of a CPU of the router. The system and method can utilize an application specific integrated circuit, in conjunction with a CAM-ACL, which analyzes data packets received on the ports of router, and the ASIC operates to drop data packets which are directed to the CPU of the router. This system and method operates to filter data packets which may be generated in attempts to hack in to control functions of a network device, and the operation does not require that the CPU analyze all received data packets in connection with determining access to the control functions of the router.