IP Library Granted Patent US 7,979,368
Granted Patent B2
US 7,979,368 · App. 11/926,307 · Granted Jul 12, 2011

Systems and methods for processing data flows

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,979,368
App. No.
11/926,307
Granted
Jul 12, 2011
Kind
B2
Abstract

A flow processing facility, which uses a set of artificial neurons for pattern recognition, such as a self-organizing map, in order to provide security and protection to a computer or computer system supports unified threat management based at least in part on patterns relevant to a variety of types of threats that relate to computer systems, including computer networks. Flow processing for switching, security, and other network applications, including a facility that processes a data flow to address patterns relevant to a variety of conditions are directed at internal network security, virtualization, and web connection security. A flow processing facility for inspecting payloads of network traffic packets detects security threats and intrusions across accessible layers of the IP-stack by applying content matching and behavioral anomaly detection techniques based on regular expression matching and self-organizing maps. Exposing threats and intrusions within packet payload at or near real-time rates enhances network security from both external and internal sources while ensuring security policy is rigorously applied to data and system resources. Intrusion Detection and Protection (IDP) is provided by a flow processing facility that processes a data flow to address patterns relevant to a variety of types of network and data integrity threats that relate to computer systems, including computer networks.

Claims (33)

1. A method in a flow processing facility for securing a computer resource, comprising:

providing a data flow processing facility comprising a plurality of network addressable data processing modules;

receiving a data flow;

identifying data packets associated with a subscriber profile in the data flow;

employing a policy to make a determination, the determination indicating a first plurality of network addresses of a portion of the plurality of network addressable data processing modules for processing the identified data packets based on at least one of the subscriber profile in the data flow and the policy;

accessing a configuration, the configuration associating one or more processing actions with the policy;

delivering the identified data packets in parallel to each of the first plurality of network addresses that the determination indicates; and

processing the identified data packets with the one or more processing actions in each of the network addressable data processing modules identified by the first plurality of network addresses to secure a computer resource.

2. The method of claim 1 , wherein processing the data packets is based on the policy.

3. The method of claim 1 , wherein processing the data packets in each of the network addressable data processing modules comprises:

processing the data packets in a first of the network addressable data processing modules with a first application; and

processing the data packets in a second of the network addressable data processing modules with a second application.

4. The method of claim 3 , wherein the first application is based on the policy.

5. The method of claim 3 , wherein the first application is based on the subscriber profile.

6. The method of claim 3 , wherein the second application is based on the policy.

7. The method of claim 1 , wherein delivering the identified data packets in parallel to each of the first plurality of determined network addresses includes delivering the identified data packets through a network switch fabric.

8. The method of claim 1 , wherein identifying data packets associated with a subscriber profile is performed by a network processor module of the data flow processing facility.

9. The method of claim 8 , further including delivering data packets from at least one of the network addressable data processing modules identified by the first plurality of network addresses to the network processor module based on a network address of the network processor module.

10. The method of claim 1 , wherein employing the policy is based on the subscriber profile.

11. A parallel data flow processing facility to secure a computer resource, comprising:

a plurality of network addressable data processing modules;

a policy for applying to data packets;

a network processor module for identifying data packets associated with a subscriber profile in a stream of data packets, determining a first plurality of network addresses of a portion of the plurality of network addressable data processing modules for processing the identified data packets based on at least one of the subscriber profile and the policy, and delivering the identified data packets in parallel to each of the first plurality of determined network addresses; and

the network addressable data processing modules identified by the first plurality of network addresses for processing the delivered data packets to secure a computer resource.

12. The parallel data flow processing facility of claim 11 , wherein processing the delivered data packets is based on the policy.

13. The parallel data flow processing facility of claim 11 , wherein processing the delivered data packets includes:

processing the data packets in a first of the network addressable data processing modules identified by the first plurality of network addresses with a first application; and

processing the data packets in a second of the network addressable data processing modules identified by the first plurality of network addresses with a second application.

14. The parallel data flow processing facility of claim 13 , wherein the first application is based on the policy.

15. The parallel data flow processing facility of claim 13 , wherein the first application is based on the subscriber profile.

16. The parallel data flow processing facility of claim 13 , wherein the second application is based on the policy.

17. The parallel data flow processing facility of claim 11 , further including a network switch fabric for delivering the identified data packets in parallel to each of the first plurality of determined network addresses.

18. The parallel data flow processing facility of claim 11 , wherein the policy is based on the subscriber profile.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 29877/0668 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC. AS SUCCESSOR BY MERGER TO CROSSBEAM SYSTEMS, INC.
Reel/Frame 035797/0004 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
MERGER Recorded May 28, 2013
From: CROSSBEAM SYSTEMS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 030492/0146 →
SECURITY AGREEMENT Recorded Feb 26, 2013
From: CROSSBEAM SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 029877/0668 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2013
From: SILICON VALLEY BANK
To: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
Reel/Frame 029599/0731 →
SECURITY AGREEMENT Recorded Nov 9, 2012
From: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
To: SILICON VALLEY BANK
Reel/Frame 029275/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2011
From: KAPOOR, HARSH; AKERMAN, MOISEY; JUSTUS, STEPHEN D.; FERGUSON, JC; KORSUNSKY, YEVGENY; GALLO, PAUL S.; LEE, CHARLES CHING; MARTIN, TIMOTHY M.; FU, CHUNSHENG; XU, WEIDONG
To: CROSSBEAM SYSTEMS, INC.
Reel/Frame 026075/0174 →