IP Library Granted Patent US 7,937,756
Granted Patent B2
US 7,937,756 · App. 11/208,022 · Granted May 3, 2011

Apparatus and method for facilitating network security

Assignee: Cpacket Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,937,756
App. No.
11/208,022
Granted
May 3, 2011
Kind
B2
Abstract

An embodiment of an apparatus that facilitates network security and traffic monitoring for input network traffic includes a plurality of microcode controlled state machines, each of which includes a computation kernel. A plurality of rules applied to a network traffic segment are distributed across the computation kernels. Each of the computation kernels includes condition logic configured by microcode stored in an associated control store to evaluate a unique configured rule in the microcode to produce an associated output. A distribution circuit routes the network traffic segment to each of the plurality of microcode controlled state machines. An aggregation circuit generates a decision on which forwarding of the network traffic segment is based, where the decision is a logical combination of the associated output of each of the computation kernels.

Claims (38)

1. An apparatus to facilitate network security and traffic monitoring for input network traffic, comprising:

a plurality of microcode controlled state machines, each of said plurality of microcode controlled state machines including a computation kernel, wherein a plurality of rules to be applied to a network traffic segment are distributed across said computation kernels such that each of said computation kernels includes condition logic configured by microcode stored in an associated control store to evaluate evaluates a unique configured rule in said microcode stored in an associated control store to produce an associated output, wherein said condition logic includes:

a condition analysis circuit configured to compare a first value of an internal state variable stored by said condition logic and updated based on network traffic conditions to a second value stored by said condition logic to evaluate a behavioral rule associated with network traffic conditions;

a distribution circuit to route said network traffic segment to each of said plurality of microcode controlled state machines;

an aggregation circuit to generate a decision on which forwarding of said network traffic segment is based, wherein said decision is a logical combination of said associated output of each of said computation kernels; and

an output circuit, wherein said distribution circuit provides said network traffic segment directly to said output circuit for forwarding, bypassing said plurality of microcode controlled state machines, in response to receiving said decision from said aggregation circuit.

2. The apparatus of claim 1 wherein each of said plurality of microcode controlled state machines has a local buffer to selectively buffer said individual network traffic segments prior to processing by said computational kernel.

3. The apparatus of claim 2 wherein said local buffers of said plurality of microcode controlled state machines operate synchronously to define a processing window for said individual network traffic segments.

4. The apparatus of claim 1 wherein each of said plurality of microcode controlled state machines has a computation kernel including a condition analysis circuit to process an internal state value and microcode from said associated control store.

5. The apparatus of claim 1 wherein said condition analysis circuit generates an output specifying whether conditions defined by said microcode are satisfied.

6. The apparatus of claim 5 wherein said condition analysis circuit generates an output specifying whether a comparison between a microcode stored internal state variable and an internal state value from said associated control store is satisfied.

7. The apparatus of claim 1 wherein each of said plurality of microcode controlled state machines has a computation kernel including a condition check circuit to process a network traffic segment and microcode from said associated control store.

8. The apparatus of claim 7 wherein said condition check circuit generates an output specifying whether conditions defined by said microcode are satisfied.

9. The apparatus of claim 8 wherein said condition check circuit generates an output specifying whether a comparison between a microcode stored operand and data from said traffic segment is satisfied.

10. The apparatus of claim 1 wherein each of said plurality of microcode controlled state machines has a circuit to process a portion of said network traffic segment, output from a condition analysis circuit and output from a condition check circuit.

11. The apparatus of claim 10 wherein each of said plurality of microcode controlled state machines has a circuit to implement a microcode specified Boolean logic operation.

12. The apparatus claim 10 wherein said circuit generates a next address value.

13. The apparatus of claim 1 wherein said plurality of microcode controlled state machines apply signature-based rules specified by said microcode.

14. The apparatus of claim 1 wherein said plurality of microcode controlled state machines operate collaboratively.

15. The apparatus of claim 14 wherein said plurality of microcode controlled state machines operate to activate and deactivate selected ones of said plurality of microcode controlled state machines.

16. The apparatus of claim 1 wherein said distribution circuit divides said input network traffic into said individual network traffic segments.

17. The apparatus of claim 1 further comprising a pre-processor circuit to divide said input network traffic into said individual network traffic segments.

18. The apparatus of claim 1 wherein said distribution circuit includes at least one frame buffer.

19. The apparatus of claim 1 wherein said at least one frame buffer is configured to support cut-through network traffic processing.

20. The apparatus of claim 1 wherein said at least one frame buffer is configured to support store and forward network traffic processing.

21. The apparatus of claim 1 wherein said distribution circuit includes an input logic circuit and an output logic circuit.

22. The apparatus of claim 1 wherein said aggregation circuit generates control signals to activate and deactivate selected microcode controlled state machines.

23. The apparatus of claim 1 wherein said aggregation circuit generates rule feedback for said microcode stored in said associated control stores of said plurality of microcode controlled state machines.

24. The apparatus of claim 1 wherein said plurality of microcode controlled state machines are configured to monitor any bit of said input network traffic.

25. The apparatus of claim 1 wherein said plurality of microcode controlled state machines, said distribution circuit, and said aggregation circuit operate to redirect said input network traffic.

26. The apparatus of claim 1 wherein said plurality of microcode controlled state machines, said distribution circuit, and said aggregation circuit operate to duplicate said input network traffic.

27. The apparatus of claim 1 wherein said plurality of microcode controlled state machines, said distribution circuit, and said aggregation circuit operate to limit the rate of said input network traffic.

28. The apparatus of claim 1 wherein said plurality of microcode controlled state machines, said distribution circuit, and said aggregation circuit operate to process header and payload of said input network traffic in a unified manner.

29. The apparatus of claim 1 positioned inside a firewall perimeter.

30. The apparatus of claim 1 including a first port to receive said input network traffic, a second port to route said output network traffic, and a third port for management communications and routing of selective output network traffic.

31. The apparatus of claim 1 wherein said distribution circuit, said plurality of microcode controlled state machines and said aggregation circuit form a first path routing traffic in a first direction, said apparatus further comprising a second path routing traffic in a second direction opposite said first direction, said second path including a second distribution circuit aligned with said aggregation circuit, a second plurality of microcode controlled state machines aligned with said plurality of microcode controlled state machines, and a second aggregation circuit aligned with said distribution circuit.

32. The apparatus of claim 31 wherein said plurality of microcode controlled state machines and said second plurality of microcode controlled state machines exchange control information.

33. The apparatus of claim 1 , wherein all of said plurality of microcode state machines have simultaneous access to a global state table.

Assignments (11)
SECURITY INTEREST Recorded Jan 31, 2024
From: CPACKET NETWORKS INC.
To: TRINITY CAPITAL INC., AS COLLATERAL AGENT
Reel/Frame 066313/0479 →
RELEASE OF SECURITY INTEREST Recorded Jan 30, 2024
From: NH EXPANSION CREDIT FUND HOLDINGS LP
To: CPACKET NETWORKS INC.
Reel/Frame 066296/0675 →
SECURITY INTEREST Recorded Apr 17, 2020
From: CPACKET NETWORKS INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 052424/0412 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2019
From: PARTNERS FOR GROWTH V, L.P.
To: CPACKET NETWORKS INC.
Reel/Frame 050953/0721 →
SECURITY INTEREST Recorded Nov 5, 2019
From: CPACKET NETWORKS, INC.
To: NH EXPANSION CREDIT FUND HOLDINGS LP
Reel/Frame 050924/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 18, 2019
From: SILICON VALLEY BANK
To: CPACKET NETWORKS INC.
Reel/Frame 050764/0597 →
SECURITY INTEREST Recorded Oct 27, 2017
From: CPACKET NETWORKS INC.
To: PARTNERS FOR GROWTH V, L.P.
Reel/Frame 043975/0953 →
SECURITY INTEREST Recorded Aug 3, 2014
From: CPACKET NETWORKS INC.
To: SILICON VALLEY BANK
Reel/Frame 033463/0506 →
SECURITY AGREEMENT Recorded Jun 8, 2012
From: CPACKET NETWORKS INC.
To: SILICON VALLEY BANK
Reel/Frame 028343/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2008
From: KAY, RONY
To: CRYPTOWARE, INC.
Reel/Frame 021625/0556 →
CHANGE OF NAME Recorded Aug 8, 2006
From: CRYPTOWARE, INC.
To: CPACKET NETWORKS, INC.
Reel/Frame 018083/0502 →
Continuity (1)
Related Publication 20070058540A1 · Mar 15, 2007