Scalable Virtual Appliance Cloud Packet Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity of data center security and service acceleration in cloud-ready environments, particularly with the rise of server-to-server communications and virtualized networks, makes it difficult to manage firewall configurations and provide deep packet inspection services effectively.
Innovation Solution
A system comprising switching distributed line cards (DLCs) and a central switch fabric coupler (SFC) that apply Access Control Lists (ACLs) to direct packets for deep packet inspection services, fragmenting and reassembling packets to ensure efficient service delivery across a scalable virtual appliance cloud (SVAC).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall configurations are used to secure data centers, then security management is straightforward, but it becomes difficult to manage firewall configurations for securing data centers with overlay networks and VM mobility
Solution Approach 1:
The patent segments the firewall configuration management into multiple components: virtual firewall instances associated with individual virtual networks, policy templates for standardized security rules, and automated provisioning systems. This allows each virtual network to have its own simplified firewall configuration while maintaining overall security through centralized policy management.
Solution Approach 2:
The patent introduces virtual network controllers and policy management intermediaries that automatically translate high-level security policies into specific firewall rules. These intermediaries handle the complexity of configuration management, allowing administrators to define security requirements at a higher level without manually managing individual firewall rules for each VM or virtual network.
2Reliability
If deep packet inspection services are performed on all packets, then security inspection is thorough, but processing time and system latency increase
Solution Approach 1:
The patent implements selective deep packet inspection where only packets matching specific criteria (suspicious patterns, unauthorized protocols, policy violations) undergo thorough inspection. Routine packets that comply with established policies are processed through faster pathing mechanisms, applying inspection only when necessary rather than uniformly to all traffic.
Solution Approach 2:
The patent uses packet copying to create inspection copies of packets for deep analysis while allowing original packets to continue through the network path. Multiple copies can be sent to different inspection engines simultaneously, enabling thorough security analysis without blocking the primary data flow and minimizing latency impact on legitimate traffic.
3Adaptability or versatility
If multiple networking appliances are deployed to provide various services, then service functionality is comprehensive, but infrastructure complexity increases
Solution Approach 1:
The patent merges multiple networking appliance functions (firewall, intrusion prevention, load balancing, VPN) into integrated virtual network services that can coexist within the same virtual network infrastructure. These combined services are managed through unified policy frameworks and centralized control planes, reducing the operational complexity that would arise from managing separate physical appliances for each function.
Solution Approach 2:
The patent creates universal virtual network services that can perform multiple functions depending on configuration and policy settings. A single virtual network service can dynamically provide firewall protection, intrusion prevention, and load balancing based on the same infrastructure, eliminating the need for separate specialized appliances and simplifying the overall infrastructure while maintaining comprehensive service functionality.
Data Source
AI summary
According to one embodiment, a system includes at least one switching distributed line card (DLC) configured to apply Access Control Lists (ACLs) on each switching interface of the at least one switching DLC to direct certain received packets to at least one appliance DLC to have deep packet inspection services performed on the certain received packets, and at least one central switch fabric coupler (SFC) in communication with the at least one switching DLC, where the at least one appliance DLC and the at least one switching DLC are connected to the at least one central SFC. Other systems, methods and computer program products for providing scalable virtual appliance cloud (SVAC) services are described in more embodiments.


