Security Chip and CPU Traffic Routing for DDoS Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing protection devices, such as firewalls, rely on dedicated security chips with fixed logic, which limits their effectiveness and integrity in defending against network attacks, particularly in scenarios involving complex or high-traffic attacks like DDoS.
Innovation Solution
A method combining a central processing unit (CPU) with a dedicated security chip to collaboratively defend against attacks, where the chip handles traffic related to low-risk IP addresses and forwards high-risk traffic to the CPU for further defense, while sampling and updating IP address lists to enhance detection and defense capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If a dedicated security chip with fixed logic is used, then device complexity is reduced and forwarding speed is improved, but defense effectiveness and integrity deteriorate due to limited capability
Solution Approach 1:
The patent segments the traffic processing function into two parts: the dedicated security chip handles high-speed forwarding of normal traffic, while the CPU handles complex attack detection and high-risk traffic processing. This segmentation allows each component to operate at its optimal performance level, resolving the contradiction between forwarding speed and defense effectiveness.
Solution Approach 2:
The patent introduces an intermediary mechanism where the dedicated security chip forwards high-risk traffic to the CPU for further processing. This intermediary approach enables the system to leverage both the speed of the security chip and the intelligence of the CPU, achieving both fast forwarding and effective defense.
2Device complexity
If only a dedicated security chip is used for attack defense, then device complexity is reduced, but comprehensive attack detection capability deteriorates
Solution Approach 1:
The patent merges the dedicated security chip with the CPU to form a collaborative defense system. The security chip maintains simple traffic forwarding functionality while the CPU provides comprehensive attack detection. This merging combines the advantages of both components, achieving both reduced complexity and enhanced detection capability.
Solution Approach 2:
The patent makes the CPU serve multiple functions: it handles complex attack detection, processes high-risk traffic, and updates the destination IP table. This multi-functionality allows the system to maintain comprehensive attack detection while avoiding the need for additional dedicated hardware, thus managing device complexity effectively.
3Reliability
If the CPU processes all traffic, then comprehensive attack detection is achieved, but CPU load increases and forwarding performance deteriorates
Solution Approach 1:
The patent extracts normal traffic processing from the CPU and assigns it to the dedicated security chip. By taking out the routine forwarding function from the CPU, the system reduces CPU load while maintaining comprehensive attack detection capability for high-risk traffic that requires CPU processing.
Solution Approach 2:
The patent applies partial action by having the CPU process only the necessary high-risk traffic rather than all traffic. This selective approach maintains adequate attack detection completeness for critical threats while significantly improving overall forwarding performance by avoiding unnecessary CPU processing of normal traffic.
Data Source
AI summary
In accordance with an embodiment, a method includes: receiving, by a dedicated security chip, first traffic from a first network interface of the protection device, where the first network interface is configured to receive traffic sent by a first network device, and a destination internet protocol (IP) address of the first traffic comprises a first IP address; determining, by the dedicated security chip, whether the first IP address exists in a first destination IP table stored on the dedicated security chip, wherein the first destination IP table comprises at least one IP address having a risk of being attacked; and in response to a determination that the first IP address exists in the first destination IP table, sending, by the dedicated security chip, the first traffic to the CPU.


