IP Library Patent Application 18738137
Patent Application
App. No. 18/738,137

PRE-FLOW GROUPING OF PACKETS FOR OPTIMZED DEEP PACKET INSPECTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/738,137
Abstract

Disclosed herein are methods, systems, and processes for performing optimized batched packet processing in deep packet inspection (DPI) computing systems. A batch of network packets is received. A stateless processing operation is performed for the batch that includes updating a current time for the batch, decoding the network packets in the batch, creating a flow-hash lookup key for each decoded network packet, and generating a first output that includes the current time and corresponding flow-hash lookup keys for the decoded network packets. Next, a stateful processing operation is performed for the batch that includes accessing the first output of the stateless processing operation, dividing the batch into multiple sub-batches, performing a parallel flow-hash table lookup operation on the network packets that are part of the sub-batches, and generating a second output that includes the sub-batches with associated packet flows. Finally, a batch-optimized DPI processing operation is performed that includes accessing the second output of the stateful processing operation and performing the DPI processing operation on a per-packet basis or on a per-flow basis.

Claims (52)

1 .- 14 . (canceled)

15 . A computer-implemented method, comprising:

receiving a plurality of IP packets including a set of packets associated with a flow;

for each packet in the set of packets:

generating a flow-hash lookup key for the packet based on a TCP/IP header of the packet; and

updating flow state of the flow using the flow-hash lookup key;

grouping the set of packets associated with the flow into a batch;

performing a stateful processing of the batch, including:

accessing the flow state of the batch;

determining an application protocol inspection to apply to the batch;

for each packet in the batch:

decoding a payload of the packet; and

performing a deep packet inspection (DPI) processing operation on the payload according to application protocol inspection.

16 . The computer-implemented method of claim 15 , wherein:

the flow state includes flow statistics of the flow; and

the flow state is stored in a hash table.

17 . The computer-implemented method of claim 15 , wherein the updating of the flow state includes performing transport layer state tracking for the individual groups.

18 . The computer-implemented method of claim 15 , wherein the application protocol inspection is performed by a DPI server that executes a DPI engine.

19 . The computer-implemented method of claim 18 , wherein different batches of packets are stored in different receive queues stored at a network interface device of the DPI server.

20 . The computer-implemented method of claim 19 , wherein contents of different receive queues are processed by different CPU threads associated with different CPU cores of the DPI server.

21 . The computer-implemented method of claim 19 , wherein the DPI server implements kernel bypass so that the DPI engine executes in user space to access the different batches directly from user space.

22 . The computer-implemented method of claim 19 , wherein the DPI engine accesses the different batches via a shared memory ring buffer.

23 . The computer-implemented method of claim 19 , wherein the DPI server is connected to a switch port analyzer to receive the IP packets from the switch port analyzer.

24 . The computer-implemented method of claim 18 , wherein the DPI engine includes one or more compiler optimization that increases an instruction throughput of the DPI engine when same-flow packets are batched.

25 . The computer-implemented method of claim 24 , wherein the DPI engine includes a loop unrolling optimization.

26 . A system comprising:

a computer device that implements a deep packet inspection (DPI) server, configured to:

receive a plurality of IP packets including a set of packets associated with a flow;

for each packet in the set of packets:

generate a flow-hash lookup key for the packet based on a TCP/IP header of the packet; and

update flow state of the flow using the flow-hash lookup key;

group the set of packets associated with the flow into a batch;

performing a stateful processing of the batch, including to:

access the flow state of the batch;

determine an application protocol inspection to apply to the batch;

for each packet in the batch:

decode a payload of the packet; and

perform a deep packet inspection (DPI) processing operation on the payload according to application protocol inspection.

27 . The system of claim 26 , wherein:

the flow state includes flow statistics of the flow; and

the flow state is stored in a hash table.

28 . The system of claim 26 , wherein the DPI server is implemented as part of a port scanning system that scans for open ports on a network.

29 . The system of claim 26 , wherein the DPI server implements one or more anomaly detection algorithms based on analysis of packets.

30 . The system of claim 26 , wherein the DPI server is implemented in a cloud computing environment.

31 . The system of claim 26 , wherein the DPI server is configured to perform a stateless processing operation on the received IP packets, including a timer management bookkeeping operation to:

determine a current time of the batch; and

expire flow data associated with the flow-hash lookup keys of the batch if the current time is after a bookkeeping time threshold.

32 . The system claim 26 , wherein to access the flow state, the DPI server is configured to:

access a hash table using the flow-hash lookup key, wherein the hash table is accessed in parallel using a multi-threaded lookup operation.

33 . The system of claim 26 , wherein:

the batch of packets is stored in a queue at a network interface device of the DPI server; and

the stateful processing accesses the batch from user space using a kernel bypass mechanism.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: TEDESCO, GIANPAOLO
To: RAPID7, INC.
Reel/Frame 068702/0722 →