SmartNIC Firewall Policy Processor for Microservices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring tools are not fully integrated with the rest of the infrastructure, leading to under-utilization of network capabilities and increased costs due to the need for separate tools for network and application monitoring.
Innovation Solution
A closed-loop framework using SmartNICs (Data Processing Units) to perform application-aware network services, including continuous monitoring of application performance metrics and real-time remediation of security or performance issues, through the integration of machine learning models and edge services platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate network monitoring tools are used, then network monitoring capability is provided, but system complexity and cost increase
Solution Approach 1:
The patent combines network monitoring and application monitoring into a single integrated system using SmartNICs. The SmartNIC consolidates multiple monitoring functions that previously required separate tools, reducing system complexity while maintaining comprehensive monitoring capability. The NIC processes both network traffic and application performance metrics through unified hardware resources.
Solution Approach 2:
The SmartNIC is designed to perform multiple functions including network packet processing, application performance monitoring, and security enforcement. This multi-functional approach eliminates the need for separate specialized tools, reducing overall system complexity while providing comprehensive monitoring capabilities.
2Reliability
If host CPU performs datapath processing, then basic network functionality is achieved, but CPU resources are consumed by non-application tasks
Solution Approach 1:
The patent extracts datapath processing functions from the host CPU and relocates them to the SmartNIC. The SmartNIC handles packet forwarding, filtering, and other network datapath tasks independently, freeing the host CPU cores to dedicate full capacity to application processing and business logic.
Solution Approach 2:
The SmartNIC acts as an intermediary between the network and the host CPU. It offloads network processing tasks from the CPU while maintaining the necessary network functionality, allowing the CPU to focus on application-level operations without being burdened by low-level network processing.
3Productivity
If SmartNIC performs application-aware network services, then network utilization improves, but device complexity increases
Solution Approach 1:
The SmartNIC performs self-configuration and self-management for application-aware network services. It automatically monitors application performance metrics and adjusts network processing accordingly without requiring external control, reducing the operational complexity despite increased functional capabilities.
Solution Approach 2:
The SmartNIC dynamically adapts its behavior based on real-time application performance data. It adjusts network processing priorities and resource allocation dynamically to optimize network utilization for different application workloads, managing complexity through adaptive rather than static configurations.
Data Source
AI summary
An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which cause the system to obtain telemetry data, the telemetry data being associated with a plurality of applications running on a plurality of hosts. The instructions cause the system to, based on the telemetry data, determine a subset of applications of the plurality of applications that run on a first host of the plurality of hosts. The instructions cause the system to determine a subset of firewall policies of a plurality of firewall polices, each of the subset of firewall policies applying to at least one respective application of the subset of applications. The instructions cause the system to generate an indication of the subset of firewall policies and send the indication to a management plane of a distributed firewall.


