IP Library Granted Patent US 8,010,469
Granted Patent B2
US 8,010,469 · App. 11/926,292 · Granted Aug 30, 2011

Systems and methods for processing data flows

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,010,469
App. No.
11/926,292
Granted
Aug 30, 2011
Kind
B2
Abstract

Methods and systems for flow processing and switching, security, and other network applications, including a facility that processes a data flow to address patterns relevant to a variety of conditions are directed at internal network security, virtualization, and web connection security are described. Such flow processing facilities may be used for inspecting network traffic packet payloads to detect security threats and intrusions across accessible layers of the network IP stack by applying content matching and behavioral anomaly detection techniques based on regular expression matching and self-organizing maps. Exposing threats and intrusions within packet payload at or near real-time rates enhances network security from both external and internal sources while ensuring security policy is rigorously applied to data and system resources.

Claims (17)

1. A method in a flow processing facility for securing a computer resource, comprising:

receiving a data flow in a data flow processing facility comprising a plurality of network addressable data processing modules;

identifying data packets associated with a subscriber profile in the data flow;

employing a set of artificial neurons, the artificial neurons comprising a policy, to make a determination indicating which of a plurality of network addresses of the plurality of the network addressable data processing modules to select for first processing of the identified data packets based on at least one of the subscriber profile and a pattern that is detectable in the data flow based on the policy;

accessing a configuration, the configuration associating two or more processing actions with the policy;

delivering the identified data packets to a first network addressable data processing module, wherein the first network addressable data processing module comprises a processor for executing one of the actions that are associated with the policy, the first network addressable data processing module being accessible at the network address that the determination indicates, the one of the actions modifying the data flow;

determining a second network address of a second network addressable data processing module for a second processing of the identified data packets based on the configuration and at least one of the subscriber profile and the policy; and

delivering the identified data packets from the first network address to the second network address to secure a computer resource.

2. The method of claim 1 , wherein determining the second network address is performed by the first network addressable data processing module.

3. The method of claim 2 , wherein determining the second network address is based on a result of the first processing.

4. The method of claim 1 , wherein delivering the identified data packets from the first network address to the second network address includes delivering the identified data packets through a network switch fabric.

5. The method of claim 1 , further including processing the data packets with a first application in the first network addressable data processing module.

6. The method of claim 5 , wherein the first application is based on the policy.

7. The method of claim 5 , further comprising processing the data packets with a second application in the network addressable data processing module identified by the second network address.

8. The method of claim 7 , wherein the second application is based on the policy.

9. The method of claim 7 , wherein the second application is based at least in part on a result of the first processing.

10. The method of claim 1 , wherein identifying data packets associated with a subscriber profile is performed by a network processor module within the data flow processing facility.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 29877/0668 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC. AS SUCCESSOR BY MERGER TO CROSSBEAM SYSTEMS, INC.
Reel/Frame 035797/0004 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
MERGER Recorded May 28, 2013
From: CROSSBEAM SYSTEMS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 030492/0146 →
SECURITY AGREEMENT Recorded Feb 26, 2013
From: CROSSBEAM SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 029877/0668 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2013
From: SILICON VALLEY BANK
To: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
Reel/Frame 029599/0731 →
SECURITY AGREEMENT Recorded Nov 9, 2012
From: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
To: SILICON VALLEY BANK
Reel/Frame 029275/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2011
From: KAPOOR, HARSH; AKERMAN, MOISEY; JUSTUS, STEPHEN D.; FERGUSON, JOHN C.; KORSUNSKY, YEVGENY; GALLO, PAUL S.; LEE, CHARLES C.; MARTIN, TIMOTHY M.; FU, CHUNSHENG; XU, WEIDONG
To: CROSSBEAM SYSTEMS, INC.
Reel/Frame 026520/0982 →