IP Library Granted Patent US 7,624,142
Granted Patent B2
US 7,624,142 · App. 11/188,260 · Granted Nov 24, 2009

System and method for processing packets according to user specified rules governed by a syntax

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,624,142
App. No.
11/188,260
Granted
Nov 24, 2009
Kind
B2
Abstract

An apparatus and method for enhancing the infrastructure of a network such as the Internet is disclosed. A packet interceptor/processor apparatus is coupled with the network so as to be able to intercept and process packets flowing over the network. Further, the apparatus provides external connectivity to other devices that wish to intercept packets as well. The apparatus applies one or more rules to the intercepted packets which execute one or more functions on a dynamically specified portion of the packet and take one or more actions with the packets. The apparatus is capable of analyzing any portion of the packet including the header and payload. Actions include releasing the packet unmodified, deleting the packet, modifying the packet, logging/storing information about the packet or forwarding the packet to an external device for subsequent processing. Further, the rules may be dynamically modified by the external devices.

Claims (35)

1. A system for processing a plurality of packets according to a first application defined by an entity, each of the plurality of packets being communicated via a network from a source to a destination intended by the source, each of the plurality of packets comprising a plurality of portions, the system comprising:

a packet interceptor coupled with the network and operative to selectively capture a packet of the plurality of packets from the network;

a processor coupled with the packet interceptor and a first memory; and

first logic stored in the first memory, the first logic being executable by the processor to allow the entity to select and relate a first set of at least two of a plurality of packet processing operations to be performed by the processor with respect to the captured packet to implement the first application, the plurality of packet processing operations including at least one of a data gathering operation, decision making operation, action taking operation or combinations thereof, the performance of at least one of the at least two packet processing operations being based on at least a portion of a previously captured packet which was communicated via the network from the destination to the source; and

wherein the processor is further coupled with second logic, the second logic defining a plurality of sub-operations executable by the processor, each of the plurality of packet processing operations being associated with a sub-set of the plurality of sub-operations, the execution of which implements the associated packet processing operation, and further wherein the performance of a packet processing operation of the plurality of packet processing operations causes the processor to automatically execute the associated sub-set of the plurality of sub-operations to implement the packet processing operation transparently to the entity.

2. The system of claim 1 , wherein the data gathering operation comprises at least one of extract data from the packet, retrieve data relating to the packet from a second memory coupled with the processor, retrieve data relating to a past packet from the second memory or combinations thereof.

3. The system of claim 1 , wherein the decision making operation comprises at least one of evaluate a function, determine a next operation to be performed by the processor, or combinations thereof.

4. The system of claim 1 , wherein the action taking operation comprises at least one of store at least a portion of the captured packet in a second memory coupled with the processor, modify at least a portion of the captured packet, delete at least a portion of the captured packet, copy at least a portion of the captured packet, forward at least a portion of the captured packet, substitute for at least a portion of the captured packet, release at least a portion of the captured packet, store data relating to at least a portion of the captured packet, take no action, modify a packet processing operation, delete a packet processing operation, select a packet processing operation, relate a packet processing operation, or combinations thereof.

5. The system of claim 1 , wherein the first logic comprises a syntax operative to define the selection and relation of each of the plurality of packet processing operations to another of the plurality of packet processing operations.

6. The system of claim 5 , wherein the syntax further defines the order in which the first processor performs each of the packet processing operations of the first set.

7. The system of claim 1 , wherein the first logic is further operative to allow the entity to select and relate a second set of at least two of the plurality of packet processing operations to be performed by the processor with respect to the packet to implement a second application, wherein said processor performs the first and second sets substantially simultaneously.

8. The system of claim 1 , wherein the first logic is further operative to allow the entity to select and relate a second set of at least two of the plurality of packet processing operations to be performed by the processor with respect to another packet selectively captured by the packet interceptor to implement a second application, wherein said processor performs the first and second sets substantially simultaneously.

9. The system of claim 1 , wherein the first logic is further operative to allow the selection and relation using graphic representations of each of the plurality of packet processing operations.

10. The system of claim 1 , wherein the first logic is further operative to allow the selection and relation using textual representations of each of the plurality of packet processing operations.

11. The system of claim 1 , wherein the first logic is further operative to encode the first set as interpreted code executable by an interpreter executed by the first processor.

12. The system of claim 1 , wherein the first logic is further operative to encode the first set as object code executable by the first processor.

13. A method for processing a plurality of packets according to a first application defined by an entity, each of the plurality of packets being communicated via a network from a source to a destination intended by the source, each of the plurality of packets comprising a plurality of portions, the method comprising:

capturing, selectively, a packet of the plurality of packets from the network;

allowing the entity to select and relate a first set of at least two of a plurality of packet processing operations to be performed by a processor with respect to the captured packet to implement the first application, the plurality of packet processing operations including at least one of a data gathering operation, decision making operation, action taking operation or combinations thereof, the performance of at least one of the at least two packet processing operations being based on at least a portion of a previously captured packet which was communicated via the network from the destination to the source; and

defining a plurality of sub-operations executable by the processor, each of the plurality of packet processing operations being associated with a sub-set of the plurality of sub-operations, the execution of which implements the associated packet processing operation, and further wherein the performance of a packet processing operation of the plurality of packet processing operations causes the processor to automatically execute the associated sub-set of the plurality of sub-operations to implement the packet processing operation transparently to the entity.

14. The method of claim 13 , wherein the data gathering operation comprises at least one of extracting data from the packet, retrieving data relating to the packet from a memory coupled with the processor, retrieving data relating to a past packet from the memory or combinations thereof.

15. The method of claim 13 , wherein the decision making operation comprises at least one of evaluating a function, determining a next operation to be performed by the processor, or combinations thereof.

16. The method of claim 13 , wherein the action taking operation comprises at least one of storing at least a portion of the captured packet in a memory coupled with the processor, modifying at least a portion of the captured packet, deleting at least a portion of the captured packet, copying at least a portion of the captured packet, forwarding at least a portion of the captured packet, substituting for at least a portion of the captured packet, releasing at least a portion of the captured packet, storing data relating to at least a portion of the captured packet, taking no action, modifying a packet processing operation, deleting a packet processing operation, selecting a packet processing operation, relating a packet processing operation, or combinations thereof.

17. The method of claim 13 , wherein the allowing further comprises defining a syntax specifying the selection and relation of each of the plurality of packet processing operations to another of the plurality of packet processing operations.

18. The method of claim 17 , wherein the syntax further defines the order in which the first processor performs each of the packet processing operations of the first set.

19. The method of claim 13 , wherein the allowing further comprises allowing the entity to select and relate a second set of at least two of the plurality of packet processing operations to be performed by the processor with respect to the packet to implement a second application, wherein said processor performs the first and second sets substantially simultaneously.

20. The method of claim 13 , wherein the allowing further comprises allowing the entity to select and relate a second set of at least two of the plurality of packet processing operations to be performed by the processor with respect to another packet selectively captured by the packet interceptor to implement a second application, wherein said processor performs the first and second sets substantially simultaneously.

21. The method of claim 13 , wherein the allowing further comprises allowing the selection and relation using graphic representations of each of the plurality of packet processing operations.

22. The method of claim 13 , wherein the allowing further comprises allowing the selection and relation using textual representations of each of the plurality of packet processing operations.

23. The method of claim 13 , wherein the allowing further comprises encoding the first set as interpreted code executable by an interpreter executed by the first processor.

24. The method of claim 13 , wherein the allowing further comprises encoding the first set as object code executable by the first processor.

25. A system for processing a plurality of packets according to a first application defined by an entity, each of the plurality of packets being communicated via a network from a source to a destination intended by the source, each of the plurality of packets comprising a plurality of portions, the method comprising:

means for capturing, selectively, a packet of the plurality of packets from the network;

means for allowing the entity to select and relate a first set of at least two of a plurality of packet processing operations to be performed by a processor with respect to the captured packet to implement the first application, the plurality of packet processing operations including at least one of a data gathering operation, decision making operation, action taking operation or combinations thereof, the performance of at least one of the at least two packet processing operations being based on at least a portion of a previously captured packet which was communicated via the network from the destination to the source; and

means for defining a plurality of sub-operations executable by the processor, each of the plurality of packet processing operations being associated with a sub-set of the plurality of sub-operations, the execution of which implements the associated packet processing operation, and further wherein the performance of a packet processing operation of the plurality of packet processing operations causes the processor to automatically execute the associated sub-set of the plurality of sub-operations to implement the packet processing operation transparently to the entity.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: LOOKINGGLASS CYBER SOLUTIONS, LLC
Reel/Frame 067429/0361 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0715 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0803 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2023
From: SILICON VALLEY BANK
To: CLOUDSHIELD TECHNOLOGIES, LLC
Reel/Frame 062872/0851 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2023
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 062847/0569 →
SECURITY INTEREST Recorded May 11, 2022
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: EASTWARD FUND MANAGEMENT, LLC
Reel/Frame 059892/0963 →
SECURITY INTEREST Recorded Aug 24, 2021
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: SILICON VALLEY BANK
Reel/Frame 057274/0638 →
SECURITY INTEREST Recorded Jul 12, 2021
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: EASTWARD FUND MANAGEMENT
Reel/Frame 056823/0269 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2018
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 047205/0192 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2016
From: PACIFIC WESTERN BANK
To: CLOUDSHIELD TECHNOLOGIES, LLC
Reel/Frame 039214/0024 →
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2015
From: VENTURE LENDING & LEASING IV, INC.; VENTURE LENDING & LEASING V, INC.
To: CLOUDSHIELD TECHNOLOGIES, LLC
Reel/Frame 037094/0291 →
SECURITY INTEREST Recorded Nov 19, 2015
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: PACIFIC WESTERN BANK
Reel/Frame 037094/0199 →
SECURITY INTEREST Recorded Apr 22, 2008
From: CLOUDSHIELD TECHNOLOGIES, INC.
To: VENTURE LENDING & LEASING IV, INC.; VENTURE LENDING & LEASING V, INC.
Reel/Frame 020859/0579 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2005
From: JUNGCK, PEDER J.
To: CLOUDSHIELD TECHNOLOGIES, INC.
Reel/Frame 017098/0731 →