XDSL Single Service Board Hardware Packet Filtering for CPU Load Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting DSLAMs from high CPU loads due to excessive protocol packets are either cumbersome to manage or result in the loss of important protocol packets, as they either require manual configuration of MAC addresses or indiscriminately discard packets, failing to effectively differentiate between attack and non-attack packets.

Innovation Solution

The method involves hardware on the XDSL single service board capturing specific protocol packets and determining if their traffic exceeds a predefined threshold, submitting only non-excessive packets to the host CPU for processing, while excessive packets are discarded, thereby reducing CPU load and packet loss without manual configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the number of subscribers is limited through binding static MAC addresses or setting maximum MAC address learning numbers, then the DSLAM is protected from attacks by multiple terminals, but the management and maintenance workload increases significantly

Engineering Contradiction:
Improveprotection against multiple terminal attacksVSAvoidmanagement and maintenance workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically monitors and limits the number of MAC addresses learned on each XDSL port without requiring manual configuration. The DSLAM autonomously tracks MAC address counts and blocks ports that exceed the threshold, eliminating the need for operators to manually bind MAC addresses or configure protection parameters on each port.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediate protection mechanism at the MAC address learning layer between the subscriber terminals and the upper-layer protocol processing. This intermediate layer filters out excessive MAC addresses before they can generate large volumes of protocol packets, reducing the load on the DSLAM's CPU without requiring direct intervention in terminal authentication or upper-layer protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the traffic amount of protocol packets is limited and excessive packets are discarded, then the DSLAM is protected from single subscriber attacks, but important non-attack protocol packets are also lost causing status confusion

Engineering Contradiction:
Improveprotection from single subscriber attacksVSAvoidloss of important protocol packets
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies different protection strategies at different network layers. At the data link layer (Layer 2), it limits MAC address learning counts to prevent flooding attacks. At the network layer (Layer 3), it selectively processes protocol packets based on their types and sources. This localized quality control ensures that legitimate protocol packets are distinguished from attack packets, preventing loss of important information while maintaining protection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The protection mechanism is segmented into multiple independent layers: MAC address learning limitation at Layer 2, and selective protocol packet processing at Layer 3. This segmentation allows each layer to handle specific aspects of attack prevention without interfering with legitimate traffic at other layers, thereby protecting against attacks while preserving important protocol packets.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If all protocol packets are processed by the host CPU, then comprehensive protocol analysis is achieved, but the CPU load becomes extremely heavy and may cause DSLAM reset

Engineering Contradiction:
Improveprotocol packet analysis accuracyVSAvoidCPU load
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements partial processing of protocol packets by the CPU. Instead of processing all protocol packets, the system selectively submits only those from legitimate sources (identified through MAC address validation and traffic pattern analysis) to the CPU for detailed analysis. Excessive packets from suspicious sources are filtered out earlier in the processing chain, reducing CPU workload while maintaining analysis accuracy for legitimate traffic.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary filtering and validation of protocol packets before they reach the CPU. MAC address learning limits and port security mechanisms pre-screen incoming traffic, identifying and blocking potential attack sources in advance. This preliminary action reduces the volume of packets requiring CPU processing, thereby lowering CPU load while preserving the ability to accurately analyze legitimate protocols.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP1843624B1Method for protecting digital subscriber line access multiplexer, DSLAM and XDSL single service board
Publication Date: 2010.06.30 HUAWEI TECH CO LTD
  • EP1843624B1 patent drawingFigure 1~2
  • EP1843624B1 patent drawingFigure 3

AI summary

A method for protecting a Digital Subscriber Line Access Multiplexer (DSLAM) includes: capturing specific protocol packets at an XDSL port by hardware of an XDSL single service board; and sending the captured specific protocol packets to a CPU of the XDSL single service board; determining whether the traffic amount of the specific protocol packets in a time unit exceeds a predefined threshold, if the traffic amount does not exceed the predefined threshold, submitting the specific protocol packets to a CPU of the host; otherwise stopping submitting the specific protocol packets to the CPU of the host. The method and the XDSL single service board provided by embodiments of the present invention need not manually set Media Access Control (MAC) address or maximum MAC address learning number for each XDSL port, which cuts down the maintenance workload, and on the other hand, reduces the loss of important protocol packets and lowers the load of the CPU.