IP Library Granted Patent US 8,402,540
Granted Patent B2
US 8,402,540 · App. 11/877,819 · Granted Mar 19, 2013

Systems and methods for processing data flows

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,402,540
App. No.
11/877,819
Granted
Mar 19, 2013
Kind
B2
Abstract

A flow processing facility, which uses a set of artificial neurons for pattern recognition, such as a self-organizing map, in order to provide security and protection to a computer or computer system supports unified threat management based at least in part on patterns relevant to a variety of types of threats that relate to computer systems, including computer networks. Flow processing for switching, security, and other network applications, including a facility that processes a data flow to address patterns relevant to a variety of conditions are directed at internal network security, virtualization, and web connection security. A flow processing facility for inspecting payloads of network traffic packets detects security threats and intrusions across accessible layers of the IP-stack by applying content matching and behavioral anomaly detection techniques based on regular expression matching and self-organizing maps. Exposing threats and intrusions within packet payload at or near real-time rates enhances network security from both external and internal sources while ensuring security policy is rigorously applied to data and system resources. Intrusion Detection and Protection (IDP) is provided by a flow processing facility that processes a data flow to address patterns relevant to a variety of types of network and data integrity threats that relate to computer systems, including computer networks.

Claims (40)

1. A method of securing a plurality of virtual networks with a virtualized network security system (VNSS), comprising:

providing a plurality of flow processors, each configured as elements of the VNSS for processing a data flow, said data flow being transferred between a first port and a second port of the VNSS, the data flow comprising subscriber profile data;

establishing a first security policy for a first virtual network based at least in part on the subscriber profile data included in the data flow;

establishing a second security policy for a second virtual network based at least in part on the subscriber profile data included in the data flow;

processing the data flow received at said first port for the first and second virtual networks through at least one of the plurality of flow processors, wherein portions of the data flow that are associated with the first virtual network are processed according to the first security policy, and wherein portions of the data flow that are associated with the second virtual network are processed according to the second security policy, said processing further comprising:

making a first determination, in accordance with one of the first security policy and the second security policy, of abnormalities that are associated with the data flow, the first determination based at least in part on the subscriber identified by the subscriber profile data; and

making a second determination, in accordance with one of the first security policy and the second security policy, based at least in part on the subscriber identified by the subscriber profile data, and

transferring said data flow to said second port.

2. The method of claim 1 , wherein the data flow is comprised of data packets.

3. The method of claim 2 , wherein the portions of the data flow associated with the first virtual network comprise the data packets associated with the first virtual network, and wherein the portions of the data flow associated with the second virtual network comprise the data packets associated with the second virtual network.

4. The method of claim 1 , wherein each virtual network supports one or more of an enterprise, individual user, home user, home office user, service provider, security provider, central office, remote office, data provider, university, social club, public facility, library, town offices, state offices, federal offices, and virtual private network.

5. The method of claim 1 , wherein each security policy supports one or more of unified threat management, intrusion detection, intrusion prevention, intrusion detection and prevention, internet firewall, URL filtering, anti-virus, anti-spam, anti-spyware, http scanning, application firewall, xml firewall, and vulnerability scanning.

6. A method of configuring virtual network security in a virtualized network security system (VNSS), comprising:

configuring two or more of a plurality of flow processing facilities into a VNSS, said data flow being transferred between a first port and a second port of the VNSS, the data flow comprising subscriber profile data;

connecting a network management facility with the plurality of flow processing facilities through the VNSS;

establishing a first security policy for a first virtual network based at least in part on the subscriber profile data included in the data flow;

establishing a second security policy for a second virtual network based at least in part on the subscriber profile data included in the data flow; and

managing the first and second security policies, wherein the two or more flow processing facilities in the VNSS receive and execute the first and second security policies while receiving said data flow on said plurality of first ports and transferring said data flow to said plurality of second ports, said managing further comprising:

making a first determination, in accordance with one of the first security policy and the second security policy, of abnormalities that are associated with the data flow, the first determination based at least in part on the subscriber identified by the subscriber profile data; and

making a second determination, in accordance with one of the first security policy and the second security policy, based at least in part on the subscriber identified by the subscriber profile data.

7. The method of claim 6 , wherein managing comprises updating the two or more flow processing facilities simultaneously.

8. The method of claim 6 , wherein each of the two or more flow processing facilities are connected to different virtual network segments.

9. The method of claim 6 , wherein at least one of the two or more flow processing facilities is located remotely from the others of the two or more flow processing facilities.

10. The method of claim 9 , wherein at least one of the two or more flow processing facilities connects to the others of the two or more flow processing facilities through the internet.

11. The method of claim 6 , wherein at least one of the first security policy and the second security policy of is managed by the network management facility.

12. The method of claim 6 , further comprising:

routing different portions of the data flow through a switch fabric to each of the two or more flow processing facilities.

13. A virtualized network security system (VNSS) comprising:

a plurality of flow processing facilities configured as elements of the VNSS for processing a data flow, said data flow being transferred between a first port and a second port of the VNSS, the data flow comprising subscriber profile data;

a network management facility that is networked with the plurality of flow processing facilities; and

a first security policy for a first virtual network, based at least in part on the subscriber profile data included in the data flow;

a second security policy for a second virtual network, based at least in part on the subscriber profile data included in the data flow, wherein the two or more flow processing facilities receive at least one of the first security policy and the second security policy while receiving said data flow on said plurality of first ports and transferring said data flow to said plurality of second ports,

wherein the plurality of flow processing facilities make a first determination, in accordance with one of the first security policy and the second security policy, of abnormalities that are associated with the data flow, the first determination based at least in part on the subscriber identified by the subscriber profile data; and

wherein the plurality of flow processing facilities make a second determination, in accordance with one of the first security policy and the second security policy, based at least in part on the subscriber identified by the subscriber profile data.

14. The system of claim 13 , wherein the network management facility updates updating the two or more flow processing facilities simultaneously.

15. The system of claim 13 , wherein each of the two or more flow processing facilities are connected to different virtual network segments.

16. The system of claim 13 , wherein at least one of the two or more flow processing facilities is located remotely from the others of the two or more flow processing facilities.

17. The system of claim 16 , wherein at least one of the two or more flow processing facilities connects to the others of the two or more flow processing facilities through the internet.

18. The system of claim 13 , further comprising:

a switch fabric for routing different portions of the data flow to each of the two or more flow processing facilities.

Assignments (13)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 29877/0668 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC. AS SUCCESSOR BY MERGER TO CROSSBEAM SYSTEMS, INC.
Reel/Frame 035797/0004 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
MERGER Recorded May 28, 2013
From: CROSSBEAM SYSTEMS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 030492/0146 →
SECURITY AGREEMENT Recorded Feb 26, 2013
From: CROSSBEAM SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 029877/0668 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR NAME PREVIOUSLY RECORDED ON REEL 027395, FRAME 0446. Recorded Feb 7, 2013
From: KAPOOR, HARSH; AKERMAN, MOISEY; JUSTUS, STEPHEN D.; FERGUSON, JC; KORSUNSKY, YEVGENY; GALLO, PAUL S.; LEE, CHARLES CHING; MARTIN, TIMOTHY M.; FU, CHUNSHENG; XU, WEIDONG
To: CROSSBEAM SYSTEMS, INC.
Reel/Frame 029781/0634 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2013
From: SILICON VALLEY BANK
To: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
Reel/Frame 029599/0731 →
SECURITY AGREEMENT Recorded Nov 9, 2012
From: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
To: SILICON VALLEY BANK
Reel/Frame 029275/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2011
From: KAPOOR, HARSH; AKERMAN, MOISEY; JUSTUS, STEPHEN D.; FERGUSON, JOHN C.; KORSUNSKY, YEVGENY; GALLO, PAUL S.; LEE, CHARLES CHING; MARTIN, TIMOTHY M.; FU, CHUNSHENG; XU, WEIDONG
To: CROSSBEAM SYSTEMS, INC.
Reel/Frame 027395/0446 →