SmartNIC Firewall Policy Processing for Application-Aware Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud data centers face challenges in efficiently monitoring and managing network and application layers due to the distributed nature of cloud-native applications, leading to underutilization of network capabilities and increased costs in monitoring, with existing solutions focusing on network edges and lacking real-time application-aware policy enforcement.
Innovation Solution
A closed-loop framework utilizing SmartNICs (Data Processing Units) for integrated network and application monitoring, enabling real-time application-aware services such as threat detection and SLA enforcement by offloading datapath processing to SmartNICs, which include a hybrid architecture of programmable ARM processors and ASICs for dynamic policy generation and enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If datapath processing is performed by host CPU, then basic packet forwarding functionality is achieved, but CPU resources are shared by applications and datapath processing reducing application performance
Solution Approach 1:
The patent extracts datapath processing functionality from the host CPU and relocates it to a separate SmartNIC device. This extraction resolves the resource contention by isolating packet processing tasks from application workloads, allowing the host CPU to dedicate full resources to applications while the SmartNIC handles network packet processing independently.
Solution Approach 2:
The SmartNIC acts as an intermediary device between the network and the host system. It mediates packet processing tasks by performing L2/L3/L4 packet processing, policing, and security functions before packets reach the host CPU, thereby reducing the burden on host resources while maintaining network connectivity and processing capabilities.
2Measurement precision
If network monitoring is performed at network edges with existing solutions, then network layer monitoring is achieved, but application-aware monitoring is lacking and costs increase
Solution Approach 1:
The patent merges network layer monitoring and application layer monitoring into a unified monitoring architecture implemented on the SmartNIC. This combination enables simultaneous observation of both network traffic patterns and application-level behaviors, providing comprehensive application-aware monitoring capabilities without requiring separate monitoring systems and reducing overall complexity.
Solution Approach 2:
The SmartNIC is designed with multi-functional capabilities that include both traditional network processing and advanced monitoring functions. It can perform packet processing, security enforcement, and application-aware monitoring simultaneously, making it a universal device that handles multiple networking and observability tasks without requiring additional specialized hardware.
3Productivity
If SmartNICs are used for offloading datapath processing, then CPU resources are freed for applications, but policy enforcement complexity increases
Solution Approach 1:
The system performs preliminary actions by pre-configuring security policies and packet processing rules on the SmartNIC before actual network traffic arrives. The control plane communicates policy requirements in advance, allowing the SmartNIC to prepare processing pipelines and rule sets beforehand, which simplifies real-time enforcement and reduces the complexity of dynamic policy management during operation.
Solution Approach 2:
The patent implements feedback mechanisms where the SmartNIC reports status, performance metrics, and policy enforcement results back to the control plane. This feedback loop enables automated policy adjustments and optimization, reducing the manual complexity of policy management while maintaining high application processing capacity through intelligent, adaptive policy enforcement.
Data Source
AI summary
An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which cause the system to obtain telemetry data, the telemetry data being associated with a plurality of applications running on a plurality of hosts. The instructions cause the system to, based on the telemetry data, determine a subset of applications of the plurality of applications that run on a first host of the plurality of hosts. The instructions cause the system to determine a subset of firewall policies of a plurality of firewall polices, each of the subset of firewall policies applying to at least one respective application of the subset of applications. The instructions cause the system to generate an indication of the subset of firewall policies and send the indication to a management plane of a distributed firewall.


