IP Library Granted Patent US 8,756,337
Granted Patent B1
US 8,756,337 · App. 12/183,143 · Granted Jun 17, 2014

Network packet inspection flow management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,756,337
App. No.
12/183,143
Granted
Jun 17, 2014
Kind
B1
Abstract

Deep packet inspection is performed on packets in a network intrusion prevention system. A processing priority may be assigned to a packet based on characteristics such as the protocol type of the packet. Higher-priority packets may be processed before lower-priority packets or otherwise given preferential processing treatment. Deep packet inspection may be performed on the packet, and the processing priority of the packet may be changed based on the amount of time required to complete inspection of the packet. For example, the processing priority of the packet may be lowered if inspection of the packet takes longer than a predetermined time threshold. Furthermore, inspection of such packets may be suspended and either terminated or resumed at a subsequent time.

Claims (60)

1. A computer-implemented method comprising:

(A) dequeueing a first packet from a first packet inspection queue;

(B) applying load balancing to a first network packet flow to produce a plurality of network packet flows, wherein a first one of the plurality of network packet flows includes the first packet;

(C) providing the plurality of network packet flows to a plurality of deep packet inspection engines, comprising providing the first one of the plurality of network packet flows to a first one of the plurality of deep packet inspection engines;

(D) queuing packets, including the first packet, in the first one of the plurality of network packet flows onto a packet inspection queue associated with the first one of the plurality of deep packet inspection engines;

(E) applying deep packet inspection to the first packet; and

(F) if deep packet inspection of the first packet is not completed within a predetermined maximum amount of time, then:

(1) suspending deep packet inspection of the first packet.

2. The method of claim 1 , further comprising:

(G) forwarding the first packet toward its destination if deep packet inspection of the first packet is completed within a predetermined maximum amount of time.

3. The method of claim 1 , wherein (F) further comprises:

(2) receiving a second packet;

(3) applying deep packet inspection to the second packet; and

(4) after (3), resuming deep packet inspection of the first packet.

4. The method of claim 3 , wherein (F) further comprises:

(5) before (3), queuing the first packet on the first packet inspection queue; and

wherein (F)( 4 ) comprises dequeueing the first packet from the first packet inspection queue before resuming deep packet inspection of the first packet.

5. The method of claim 3 , wherein (F)( 2 ) comprises saving a state of the deep packet inspection of the first packet, and wherein (F)( 4 ) comprises restoring the state of the deep packet inspection of the first packet before resuming deep packet inspection of the first packet.

6. The method of claim 1 , wherein (F) further comprises:

(2) dropping the first packet.

7. The method of claim 1 , wherein (F) further comprises:

(2) forwarding the first packet toward its destination.

8. The method of claim 1 , further comprising:

(G) before (E), identifying a state of the first packet indicating a first processing priority;

wherein (E) comprises applying deep packet inspection to the first packet according to the first processing priority; and

wherein (F) further comprises:

(2) updating the state of the first packet to indicate a second processing priority that is lower than the first processing priority; and

(3) applying deep packet inspection to the first packet according to the second processing priority.

9. The method of claim 1 , wherein the predetermined maximum amount of time comprises about 100 microseconds.

10. A computer-implemented method comprising:

(A) dequeueing a first packet from a first packet inspection queue;

(B) applying load balancing to a first network packet flow to produce a plurality of network packet flows, wherein a first one of the plurality of network packet flows includes the first packet;

(C) providing the plurality of network packet flows to a plurality of deep packet inspection engines, comprising providing the first one of the plurality of network packet flows to a first one of the plurality of deep packet inspection engines;

(D) queuing packets, including the first packet, in the first one of the plurality of network packet flows onto a packet inspection queue associated with the first one of the plurality of deep packet inspection engines;

(E) applying deep packet inspection to the first packet according to a first processing priority indicated by a first state of the first packet;

(F) if deep packet inspection of the first packet is not completed within a first predetermined maximum amount of time, then:

(1) changing the first state of the first packet to indicate a second processing priority that is lower than the first processing priority.

11. The method of claim 10 , wherein (E) comprises applying deep packet inspection to the first packet in a first deep packet inspection queue having the first processing priority, wherein (F)(1) comprises moving the first packet to a second deep packet inspection queue having the second processing priority, and wherein the method further comprises:

(G) after (F), if there is a second packet in the first deep packet inspection queue, then applying deep packet inspection to the second packet;

(H) otherwise, applying deep packet inspection to the first packet in the second deep packet inspection queue.

12. The method of claim 10 , wherein (F) further comprises:

(2) before (F)(1), suspending deep packet inspection of the first packet; and

wherein (H) comprises resuming the suspended deep packet inspection of the first packet.

13. The method of claim 10 , further comprising:

(G) applying deep packet inspection to the first packet according to the second processing priority;

(H) if deep packet inspection of the first packet according to the second processing priority is not completed within a second predetermined maximum amount of time, then:

(1) changing the first state of the first packet to indicate a third processing priority that is lower than the second processing priority.

14. The method of claim 10 , wherein (E) comprises using a first processor associated with the first processing priority to apply deep packet inspection to the first packet; and

wherein (F)(1) comprises changing the first state of the first packet to indicate a second processing priority associated with a second processor.

15. The method of claim 10 , wherein (E) comprises using one of a first plurality of processors associated with the first processing priority to apply deep packet inspection to the first packet; and

wherein (F)(1) comprises changing the first state of the first packet to indicate a second processing priority associated with a second plurality of processors that is smaller in number than the first plurality of processors.

16. A network intrusion prevention system comprising:

a memory storing machine readable instructions, the machine readable instructions comprising code to:

dequeue a first packet from a first packet inspection queue;

apply load balancing to a first network packet flow to produce a plurality of network packet flows, wherein a first one of the plurality of network packet flows includes the first packet;

provide the plurality of network packet flows to a plurality of deep packet inspection engines, comprising providing the first one of the plurality of network packet flows to a first one of the plurality of deep packet inspection engines;

queue packets, including the first packet, in the first one of the plurality of network packet flows onto a packet inspection queue associated with the first one of the plurality of deep packet inspection engines;

apply a deep packet inspection to the first packet; and

if the deep packet inspection of the first packet is not completed within a predetermined maximum amount of time, suspend the deep packet inspection of the first packet; and

a processor to execute the machine readable instructions.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2016
From: TREND MICRO INCORPORATED
To: TREND MICRO INCORPORATED
Reel/Frame 039512/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2016
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: TREND MICRO INCORPORATED
Reel/Frame 039203/0047 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP; HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 036987/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2010
From: TIPPINGPOINT TECHNOLOGIES, INC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 024755/0973 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SEE ATTACHED Recorded Jul 15, 2010
From: 3COM CORPORATION
To: HEWLETT-PACKARD COMPANY
Reel/Frame 025039/0844 →
MERGER Recorded Jul 6, 2010
From: 3COM CORPORATION
To: HEWLETT-PACKARD COMPANY
Reel/Frame 024630/0820 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2009
From: CANION, RODNEY S.; TOMLINSON, ALEXANDER I.
To: TIPPINGPOINT TECHNOLOGIES, INC.
Reel/Frame 022382/0382 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2008
From: YANG, ZHONGPING; GALLAGHER, GENEVIEVE LOUISE EICHENBERG
To: MEDTRONIC, INC.
Reel/Frame 021323/0804 →