Virtual Machine Deep Packet Inspection for Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hardware implementations of deep packet inspection systems, such as those using content addressable memories, face high system costs due to the need for numerous entries to distinguish varying RTP data packets from different sources, which can lead to inefficient processing and increased costs.

Innovation Solution

A system and method employing a virtual machine component to perform deep packet inspection, allowing for flexible inspection of data packets based on predetermined rules, which can inspect any sequence of bits at any depth, reducing the reliance on hardware-specific CAMs and enabling efficient processing of RTP data packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If hardware implementation using CAM is adopted to achieve good processing speed, then processing speed is improved, but system cost increases due to the need for numerous entries to distinguish varying RTP data packets

Engineering Contradiction:
Improveprocessing speedVSAvoidsystem cost
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent applies the copying principle by using a virtual machine that creates a software-based copy of the packet inspection functionality instead of requiring expensive hardware CAM entries. The virtual machine emulates the packet inspection process through software simulation, eliminating the need for costly hardware resources while maintaining inspection capabilities.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical hardware CAM system with a software-based virtual machine implementation. This substitution eliminates the need for physical hardware entries and uses software processing to achieve packet inspection, thereby reducing system cost while maintaining functional equivalence.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Speed

If hardware implementation using CAM is adopted to achieve good processing speed, then processing speed is improved, but device complexity increases due to the need for numerous entries to distinguish varying RTP data packets

Engineering Contradiction:
Improveprocessing speedVSAvoiddevice complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The virtual machine creates a software copy of the packet inspection functionality, replacing the need for numerous hardware CAM entries. This copying approach maintains the inspection capabilities while significantly reducing device complexity by using software instead of hardware resources.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual machine provides a universal platform that can perform packet inspection for various RTP data packets from different sources through a single software implementation, eliminating the need for multiple specialized hardware entries and reducing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If virtual machine component is used to perform deep packet inspection, then system cost is reduced, but processing speed may be affected

Engineering Contradiction:
Improvesystem costVSAvoidprocessing speed
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The patent segments the packet inspection process into two stages: a hardware-based initial filtering stage that quickly identifies candidate packets, followed by a virtual machine-based deep inspection stage. This segmentation allows the system to maintain speed by performing quick hardware filtering while using the virtual machine only for packets that require deep inspection, thereby reducing overall system cost without significantly impacting processing speed.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9288159B2Systems and methods for deep packet inspection with a virtual machine
Publication Date: 2016.03.15 MARVELL ASIA PTE LTD
  • US9288159B2 patent drawing
  • US9288159B2 patent drawing
  • US9288159B2 patent drawing

AI summary

System and methods are provided for performing deep packet inspection of data packets. An example system includes a packet forwarding component and a virtual machine component. The packet forwarding component is configured to receive data packets for transmission and to select one or more of the data packets based at least in part on a first set of rules for deep packet inspection. The virtual machine component is configured to perform deep packet inspection on the selected data packets according to a second set of rules to determine whether the selected data packets are allowed for transmission. The packet forwarding component is further configured to transmit the selected data packets when the selected data packets are allowed for transmission after the deep packet inspection.