IP Library Patent Application 11852073
Patent Application
App. No. 11/852,073

Controlling and Monitoring Propagation Within a Network

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/852,073
Abstract

Described are methods and apparatus, including computer program products, for propagation protection within a network. A management station sends an event message to a transparent network appliance, the event message comprising a command for the transparent network appliance to shape traffic being transmitted through the transparent network appliance. The management station receives statistical information from the transparent network appliance relating to the traffic being transmitted through the transparent network device.

Claims (44)

1 . A computerized method for propagation protection within a network, the method comprising:

sending, by a management station, an event message to a transparent network appliance, the event message comprising a command for the transparent network appliance to shape traffic being transmitted through the transparent network appliance; and

receiving, by the management station, statistical information from the transparent network appliance relating to the traffic being transmitted through the transparent network device.

2 . The method of claim 1 wherein the management station is located within a network in which the transparent network appliance is located.

3 . The method of claim 1 , further comprising generating, by the management station, a graphical user interface and user interface elements to shape the traffic being transmitted through the transparent network appliance.

4 . The method of claim 3 , wherein generating comprises generating user interface elements to prioritize the data based on a source IP address, source port, destination IP address, destination port, source MAC address, tcp acknowledgment or any combination thereof.

5 . The method of claim 3 , wherein generating further comprises generating user interface elements to prioritize data being transmitted through the transparent network appliance based on a plurality of parameters.

6 . The method of claim 5 , wherein generating further comprises generating user interface elements to allocate a bandwidth of the prioritized data.

7 . The method of claim 1 , wherein receiving comprises receiving statistical information relating to the traffic, the statistical information comprising a bandwidth, an average bandwidth, an IP protocol, an IP address, information related to traffic sent at a host level, information related to traffic received at a host level, information related to traffic sent at a port level, information related to traffic received at a port level, information related to traffic sent at a stream level, information related to traffic received at a stream level, or any combination thereof.

8 . The method of claim 1 , further comprising:

generating, by the management station, a user interface;

formatting, by the management station, the statistical information from the transparent network appliance; and

displaying, by the management station, the statistical information on the user interface.

9 . The method of claim 8 , further comprising generating, by the management station, user interface elements to download a file relating to the statistical information.

10 . The method of claim 1 , wherein sending further comprises sending, by the management station, an event message to the transparent network appliance, the event message comprising a command to activate a module that shapes the traffic, a command to deactivate the module that shapes the traffic, a command to update a configuration used to shape the traffic, a command to establish a connection with a module that generates the statistical information relating to the traffic, a command to end the connection with the module that generates the statistical information relating to the traffic, a command to update software relating to the transparent network appliance, or any combination thereof.

11 . The method of claim 1 , wherein sending further comprises sending, by the management station, a command for the transparent network appliance to shape traffic based on a configurable rule.

12 . The method of claim 11 , further comprising employing a user interface associated with the management station to generate and/or prioritize the configurable rule used to shape the traffic.

13 . The method of claim 11 , wherein the configurable rule is one of a plurality of rules used to shape the traffic.

14 . A transparent network appliance for propagation protection within a network, the network appliance comprising:

a network interface card configured to act as a bridge between a first portion of the network and a second portion of the network;

a first data analyzer module configured to analyze traffic being transmitted through the transparent network appliance and to transmit statistical information relating to the traffic to a management station; and

a second data analyzer module configured to analyze an event message from the management station, the event message comprising a command to shape the traffic being transmitted through the transparent network appliance.

15 . A computer program product, tangibly embodied in an information carrier, for monitoring propagation protection within a network, the computer program product including instructions being operable to cause a data processing apparatus to:

send, by a management station, an event message to a transparent network appliance, the event message comprising a command for the transparent network appliance to shape traffic being transmitted through the transparent network appliance; and

receive, by the management station, statistical information from the transparent network appliance relating to the traffic being transmitted through the transparent network device.

16 . A computerized method for propagation protection within a network, the method comprising:

repeatedly storing, by a network appliance, packets of a data stream in a buffer;

reassembling the packets of data to generate a portion of the data stream; and

preventing the packets of data from being transmitted from the network appliance until a threat determination is made.

17 . The method of claim 16 wherein the data stream is associated with a TCP session.

18 . The method of claim 16 wherein the portion of the data stream is not the entire data stream.

19 . The method of claim 16 , wherein storing further comprises storing packets of data until a next sequential packet is not available.

20 . The method of claim 16 , further comprising analyzing a header associated with the packets of data to determine if the reassembled portion of data is sufficient to make a threat determination.

21 . The method of claim 16 , wherein reassembling further comprises determining a sequence number of a packet.

22 . The method of claim 21 , further comprising determining if the sequence number of the packet is received with a sequence number less than a next expected sequence number and the sequence number plus a data length of the packet is greater than the next expected sequence number.

23 . The method of claim 22 , further comprising analyzing a trailing data of the packet equal to the difference between the sequence number plus a data length of the packet and the next expected sequence number.

24 . The method of claim 23 , further comprising incrementing the next expected sequence number by the packet data length.

25 . A transparent network appliance for propagation protection within a network, the network appliance comprising:

a network interface card configured to act as a bridge between a first portion of the network and a second portion of the network; and

a data analyzer module configured to repeatedly store packets of a data stream in a buffer, reassemble packets of data to reassemble a portion of the data stream, and prevent packets of data from being transmitted from the network appliance until a threat determination is made.

26 . A computer program product, tangibly embodied in an information carrier, for monitoring propagation protection within a network, the computer program product including instructions being operable to cause a data processing apparatus to:

repeatedly store, by a network appliance, packets of a data stream in a buffer;

reassemble the packets of data to generate a portion of the data stream; and

prevent the packets of data from being transmitted from the network appliance until a threat determination is made.

Assignments (3)
RELEASE Recorded Jun 13, 2013
From: SILICON VALLEY BANK
To: CYMTEC SYSTEMS INC.
Reel/Frame 030630/0755 →
SECURITY AGREEMENT Recorded Jan 31, 2012
From: CYMTEC SYSTEMS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027629/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2007
From: MESTER, MICHAEL L.; GUNSALUS, BRAD W.; BOLAM, NATE C.
To: CYMTEC SYSTEMS, INC.
Reel/Frame 020181/0692 →