SmartNIC Self-Learning Firewall Policy Enforcer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud data centers face challenges in efficiently monitoring and managing network and application layers due to the distributed nature of cloud native applications, leading to underutilization of network capabilities and increased costs in monitoring, with existing solutions limited in their ability to enforce policies within the datacenter and detect threats in real-time.
Innovation Solution
A closed-loop framework utilizing SmartNICs (Data Processing Units) for application-aware network services, which includes edge services platforms for orchestration, API-driven service deployment, monitoring, and management of connectivity, enabling dynamic firewall policy generation, SLA enforcement, and real-time anomaly detection and mitigation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional NICs with host CPU datapath processing are used, then basic packet forwarding is achieved, but CPU resources are shared between applications and datapath processing, reducing application performance
Solution Approach 1:
The patent extracts the datapath processing functionality from the host CPU and relocates it to a dedicated SmartNIC device. This separation allows the host CPU to be exclusively dedicated to application processing, while the SmartNIC handles all packet processing, policing, and networking tasks independently through its integrated DPU, FPGAs, and ASICs.
2Productivity
If SmartNICs with augmented datapath processing are used, then datapath processing is offloaded from host CPU, but network monitoring and policy enforcement capabilities remain limited
Solution Approach 1:
The patent implements a universal SmartNIC architecture that performs multiple functions: high-speed packet forwarding, application-aware network monitoring, real-time threat detection, dynamic policy enforcement, and service level agreement management. The SmartNIC acts as both a network interface and an intelligent security enforcement point.
Solution Approach 2:
The patent implements closed-loop feedback mechanisms where the SmartNIC continuously monitors application performance metrics and network traffic, compares actual performance against defined policies and SLAs, and dynamically adjusts packet forwarding decisions in real-time to enforce policies and remediate issues without external intervention.
3Measurement precision
If distributed monitoring tools are used for cloud native applications, then monitoring coverage is increased, but system complexity and monitoring costs increase
Solution Approach 1:
The patent merges network layer monitoring and application layer monitoring into a single unified SmartNIC device. This consolidation provides comprehensive visibility into both network traffic and application performance metrics from a single point, eliminating the need for multiple separate monitoring tools and reducing system complexity.
4Reliability
If real-time threat detection and policy enforcement are implemented, then security is improved, but additional processing resources and complexity are required
Solution Approach 1:
The patent implements preliminary action by pre-configuring security policies, threat detection rules, and response actions in the SmartNIC before threats occur. The SmartNIC maintains ready-to-execute policy sets and can immediately enforce them upon detecting anomalies, eliminating the need for complex real-time analysis and external coordination during security events.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which, when executed by the processing circuitry, cause the network system to obtain first traffic session metrics data and execute a machine learning model to determine a traffic prediction based on the first traffic session metrics data. The instructions cause the network system to obtain second traffic session metrics data and determine an anomaly in traffic based on a comparison of the traffic prediction and the second traffic session metrics data. The instructions cause the network system to, based on the determination of the anomaly, generate an indication of the anomaly.