IP Library Granted Patent US 8,782,787
Granted Patent B2
US 8,782,787 · App. 12/911,912 · Granted Jul 15, 2014

Distributed packet flow inspection and processing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,782,787
App. No.
12/911,912
Granted
Jul 15, 2014
Kind
B2
Abstract

Distribution of network processing load among a set of packet processing devices is improved by employing means for eliminating, controlling, or otherwise affecting redundant packet processing operations. In one embodiment, at least two packet processing devices are present, both capable of processing data packets flowing therethrough, such as, inspecting, detecting, and filtering data packets pursuant to one or more filters from a filter set. Redundancy is controlled by providing or enabling either or both of the packet processing devices with capability for detecting during its said inspection of said data packets that, for example, one or more filters had been previously executed on said data packets by the other packet processing device, and then not executing the previously-executed filters on said data packets.

Claims (49)

1. A network comprising:

a first packet processing device to apply a first filtering operation on a data packet; and

a second packet processing device to

receive the data packet from the first packet processing device,

determine filtering operations previously performed on the data packet,

identify the first filtering operation as a filtering operation previously performed on the data packet,

based on the identification of the first filtering operation, apply a second filtering operation, different from the first filtering operation, on the data packet, and

add a tag to the data packet to indicate the second filtering operation applied on the data packet.

2. The network of claim 1 , wherein determine filtering operations previously performed on the data packet includes inspect a field of the data packet, wherein said field contains a value signifying the first filtering operation.

3. The network of claim 2 , wherein said value is encrypted.

4. The network of claim 2 , wherein said value signifies an entry or entries in a data structure, wherein said entry or entries correlate with the first filtering operation.

5. The network of claim 2 , wherein said value identifies the first packet processing device as the device that previously executed the first filtering operation on the data packet.

6. The network of claim 1 , wherein determine filtering operations previously performed on the data packet includes:

inspect an address field of the data packet; and

use network topology information in conjunction with the address in the address field to identify the previous filtering operations.

7. The network of claim 1 , further comprising:

a management agent to assign the first filtering operation to the first packet processing device and assign the second filtering operation to the second packet processing device.

8. The network of claim 7 , wherein the second packet processing device is further to

determine whether the first filtering operation has been performed on the data packet,

if the first filtering operation has been performed on the data packet, apply only the second filtering operation on the data packet, and

if the first filtering operation has not been performed on the data packet, apply both the first and second filtering operations on the data packet.

9. The network of claim 1 , wherein said second packet processing device is to apply the second filtering operation only if said second packet processing device detects that said second filtering operation had not previously been executed on said data packet.

10. A packet processing device suitable for installation in a network to thereby provide therein an intrusion prevention system, the packet processing device comprising:

a port to receive data packets;

a data packet inspector to inspect the data packets; and

a data packet filter to filter the data packets in response to the inspection of the data packets by the data packet inspector,

wherein the data packet inspector is to identify filtering operations previously applied on the data packets by another packet processing device,

based on the identified previous filtering operations, the data packet filter is to apply a filtering operation, different from the identified previous filtering operations, on the data packets, and

wherein the data packet filter is further to add a tag to the data packets to indicate the filtering operation applied to the data packets.

11. The packet processing device of claim 10 , wherein, to identify filtering operations previously applied on the data packets, said data packet inspector is to inspect an address field of the data packets and use network topology information in conjunction with the address in the address field to identify the previous filtering operations.

12. The packet processing device of claim 10 , wherein said data packet inspector is to inspect a field of the data packets, wherein said field contains a value signifying said previous filtering operations.

13. The packet processing device of claim 12 , wherein said value is encrypted.

14. The packet processing device of claim 12 , wherein said value signifies an entry or entries in a data structure, wherein said entry or entries correlate with said previous filtering operations.

15. The packet processing device of claim 12 , wherein said value identifies the another packet processing device as the device that previously executed said filtering operations on the data packets.

16. A method for processing data packets by a packet processing device, the method comprising:

receiving a data packet;

identifying, by the packet processing device, filtering operations previously performed on the data packet by another packet processing device, including inspecting an address field of the data packet and using network topology information in conjunction with the address in the address field to identify the previous filtering operations; and

based on the identified previous filtering operations, applying a filtering operation, different from the identified previous filtering operations, on the data packet.

17. The method of claim 16 , further comprising:

adding a tag to the data packets to indicate the filtering operation applied on the data packet.

18. A packet processing device suitable for installation in a network to thereby provide therein an intrusion prevention system, the packet processing device comprising:

a port to receive data packets;

a data packet inspector to inspect the data packets; and

a data packet filter to filter the data packets in response to the inspection of the data packets by the data packet inspector,

wherein the data packet inspector is to inspect a field of the data packets to identify filtering operations previously applied on the data packets by another packet processing device, wherein the field contains a value signifying the previous filtering operations applied on the data packets, and

based on the identified previous filtering operations, the data packet filter is to apply a filtering operation, different from the identified previous filtering operations, on the data packets.

19. The packet processing device of claim 18 , wherein the value is encrypted.

20. The packet processing device of claim 18 , wherein the value signifies an entry or entries in a data structure, wherein the entry or entries correlate with the previous filtering operations.

21. The packet processing device of claim 18 , wherein the value identifies the another packet processing device as the device that previously executed the filtering operations on the data packets.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2016
From: TREND MICRO INCORPORATED
To: TREND MICRO INCORPORATED
Reel/Frame 039512/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2016
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: TREND MICRO INCORPORATED
Reel/Frame 039203/0047 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP; HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 036987/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2010
From: WILLEBEEK-LEMAIR, MARC; SMITH, BRIAN C.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 025194/0986 →