Virtual Machine Deep Packet Inspection for Network Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hardware implementations of deep packet inspection systems, such as those using content addressable memories, face high system costs due to the need for numerous entries to distinguish varying RTP data packets from different sources, which can lead to inefficient processing and increased costs.
Innovation Solution
A system and method employing a virtual machine component to perform deep packet inspection, allowing for flexible inspection of data packets based on predetermined rules, which can inspect any sequence of bits at any depth, reducing the reliance on hardware-specific CAMs and enabling efficient processing of RTP data packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If hardware implementation using CAM is adopted to achieve good processing speed, then processing speed is improved, but system cost increases due to the need for numerous entries to distinguish varying RTP data packets
Solution Approach 1:
The patent applies the copying principle by using a virtual machine that creates a software-based copy of the packet inspection functionality instead of requiring expensive hardware CAM entries. The virtual machine emulates the packet inspection process through software simulation, eliminating the need for costly hardware resources while maintaining inspection capabilities.
Solution Approach 2:
The patent replaces the mechanical hardware CAM system with a software-based virtual machine implementation. This substitution eliminates the need for physical hardware entries and uses software processing to achieve packet inspection, thereby reducing system cost while maintaining functional equivalence.
2Speed
If hardware implementation using CAM is adopted to achieve good processing speed, then processing speed is improved, but device complexity increases due to the need for numerous entries to distinguish varying RTP data packets
Solution Approach 1:
The virtual machine creates a software copy of the packet inspection functionality, replacing the need for numerous hardware CAM entries. This copying approach maintains the inspection capabilities while significantly reducing device complexity by using software instead of hardware resources.
Solution Approach 2:
The virtual machine provides a universal platform that can perform packet inspection for various RTP data packets from different sources through a single software implementation, eliminating the need for multiple specialized hardware entries and reducing overall device complexity.
3Device complexity
If virtual machine component is used to perform deep packet inspection, then system cost is reduced, but processing speed may be affected
Solution Approach 1:
The patent segments the packet inspection process into two stages: a hardware-based initial filtering stage that quickly identifies candidate packets, followed by a virtual machine-based deep inspection stage. This segmentation allows the system to maintain speed by performing quick hardware filtering while using the virtual machine only for packets that require deep inspection, thereby reducing overall system cost without significantly impacting processing speed.
Data Source
AI summary
System and methods are provided for performing deep packet inspection of data packets. An example system includes a packet forwarding component and a virtual machine component. The packet forwarding component is configured to receive data packets for transmission and to select one or more of the data packets based at least in part on a first set of rules for deep packet inspection. The virtual machine component is configured to perform deep packet inspection on the selected data packets according to a second set of rules to determine whether the selected data packets are allowed for transmission. The packet forwarding component is further configured to transmit the selected data packets when the selected data packets are allowed for transmission after the deep packet inspection.


