Policy-Based Packet Inspection via SmartNICs for Zero-Trust Workloads
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional perimeter-based security models are inadequate in modern networks due to the dispersion of data and access points beyond the traditional network perimeter, making it difficult to enforce security controls effectively against sophisticated cyber threats that can bypass defenses and move laterally within the network.
Innovation Solution
Implementing a transparent intercepting agent within network interfaces, such as SmartNICs or DPUs, to perform policy-based deep packet inspection and enforce zero-trust principles by continuously verifying and blocking malicious content at the endpoint level, using a control plane to dynamically update security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If perimeter-based security models are used, then network boundary protection is simplified, but security effectiveness deteriorates due to dispersed data and access points beyond the traditional perimeter
Solution Approach 1:
The patent segments the security function by deploying intercepting agents at individual endpoint devices rather than relying on a centralized perimeter firewall. Each endpoint device independently performs packet inspection and security enforcement, dividing the security function across multiple distributed locations to address the dispersion of data and access points beyond the traditional network perimeter.
2Reliability
If deep packet inspection is performed at the endpoint level, then threat detection capability is improved, but processing time and network throughput are reduced
Solution Approach 1:
The patent applies local quality by enabling each endpoint device to perform security inspection only for packets relevant to its specific workload and policy requirements, rather than inspecting all traffic uniformly. The intercepting agent selectively inspects packets based on local security policies and packet characteristics, optimizing the balance between detection capability and processing efficiency.
Solution Approach 2:
The system performs partial deep packet inspection by examining only the necessary portions of packets based on policy rules and threat indicators, rather than always performing full inspection. This selective inspection approach maintains threat detection capability while reducing processing overhead for legitimate traffic.
3Reliability
If transparent intercepting agents are injected into network interfaces, then zero-trust verification is achieved, but device complexity and configuration overhead increase
Solution Approach 1:
The intercepting agents perform self-service by automatically enforcing security policies locally at each endpoint without requiring manual configuration or intervention. The agents independently make security decisions based on received policies, eliminating the need for complex centralized management and reducing configuration overhead while maintaining zero-trust verification.
Solution Approach 2:
The patent introduces an intermediary control plane that communicates security policies to the intercepting agents, separating the complex policy management function from the endpoint devices. This intermediary layer simplifies endpoint configuration by delivering pre-processed security rules rather than requiring direct configuration of complex security logic at each device.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed are systems, apparatuses, methods, and computer-readable media for policy-based transparent packet inspection for last mile zero-trust workload protection. The method comprises receiving a packet on a network interface of a provisioned resource in a data center or a user device within a network; determining, by a first intercepting agent provisioned within the network interface, whether to inspect the packet based on rules received from a control plane of the network, wherein the network interface comprises a smart network interface card (SmartNIC) or a data processing unit (DPU) and is configured with the first intercepting agent based on the control plane; selectively invoking a deep packet inspection of the packet based on inspection of the packet by the first intercepting agent using the rules from the control plane; and blocking the packet at the network interface based on the deep packet inspection identifying malicious content within the packet.