IP Library Patent Application 12982772
Patent Application
App. No. 12/982,772

SECURING A NETWORK WITH DATA FLOW PROCESSING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/982,772
Abstract

An apparatus and method to distribute applications and services in and throughout a network and to secure the network includes the functionality of a switch with the ability to apply applications and services to received data according to respective subscriber profiles. Front-end processors, or Network Processor Modules (NPMs), receive and recognize data flows from subscribers, extract profile information for the respective subscribers, utilize flow scheduling techniques to forward the data to applications processors, or Flow Processor Modules (FPMs). The FPMs utilize resident applications to process data received from the NPMs. A Control Processor Module (CPM) facilitates applications processing and maintains connections to the NPMs, FPMs, local and remote storage devices, and a Management Server (MS) module that can monitor the health and maintenance of the various modules.

Claims (27)

1 . A network apparatus for preventing denial of service attacks, comprising,

at least one network processor module having at least one processor, at least one interface to receive and forward a stream of data packets in a network, and instructions to cause the at least one processor to recognize one or more data packets in the stream of data packets that contain data, including subscriber profile information, for processing by a denial of service security application executing on the network apparatus by applying a denial of service detection and/or prevention policy to the data, and directing the stream of data packets to at least one flow processor module for executing the denial of service security application based on the subscriber profile information and the denial of service detection and/or prevention policy;

the at least one flow processor module having at least one processor and at least one memory for storing denial of service security applications for execution by the at least one flow processor module processor, the at least one flow processor module including instructions to receive the stream of data packets from the at least one network processor module and to apply the denial of service detection and/or prevention policy to the data in the one or more data packets with the denial of service security application; and

at least one control processor module in communication with the at least one flow processor module and the at least one network processor module, and having at least one control processor module processor, and instructions for causing the at least one control processor module processor to manage the denial of service security applications in the flow processor module memories.

2 . The network apparatus of claim 1 , wherein the control processor module instructions for causing the at least one control processor module processor to manage the denial of service security applications in the flow processor module memories further comprise instructions to cause the at least one control processor module to perform a step from the group consisting of, downloading denial of service security applications to the flow processor module memories, and deleting denial of service security applications from the flow processor module memories.

3 . The network apparatus of claim 1 , further comprising a management server module in communication with the at least one control processor module and having at least one management server module processor.

4 . The network apparatus of claim 3 , wherein the management server module further comprises instructions for causing the at least one management server module processor to cause the at least one control processor module to perform a step from the group consisting of, downloading applications from the management server module to the flow processor module memories, and deleting applications from the flow processor module memories.

5 . The network apparatus of claim 1 , further comprising a local memory device coupled to the at least one of control processor module.

6 . The network apparatus of claim 1 , further comprising a remote memory device coupled to the at least one of control processor module.

7 . The network apparatus of claim 1 , wherein the at least one control processor module further comprises instructions to cause the at least one control processor module processor to transfer data between a management server module and the at least one flow processor module.

8 . The network apparatus of claim 1 , further comprising at least one storage device coupled to the at least one of flow processor module.

9 . The network apparatus of claim 1 , further comprising at least one storage device coupled to the at least one of network processor module.

10 . A method for protecting a network with a denial of service security network apparatus, comprising,

receiving a stream of data packets that contain data, including subscriber profile information, from the network at the network apparatus;

identifying at least one denial of service security application for executing on the network apparatus to apply to the stream of data packets;

directing the stream of data packets to at least one processor in the network apparatus for executing the at least one identified denial of service security application based on the subscriber profile information and a denial of service detection/prevention policy; and

processing the stream of data packets according to the at least one identified denial of service security application by applying the denial of service detection/prevention policy to the data.

11 . The method of claim 10 , further including forwarding the processed stream of data packets from the network apparatus.

12 . The method of claim 10 , wherein identifying at least one denial of service security application further comprises selecting the at least one denial of service security application based on the subscriber profile information.

13 . The method of claim 10 , further comprising configuring the at least one processor for the at least one identified denial of service security application.

14 . The method of claim 10 , further comprising selecting at least one processor based on the at least one identified denial of service security application.

15 . The method of claim 10 , further comprising selecting at least one processor based on processor loading.

16 . The method of claim 10 , further comprising selecting at least one processor based on applying the denial of service detection/prevention policy to the data.

17 . The method of claim 10 , wherein identifying at least one denial of service security application further comprises identifying a source of the stream of data packets and retrieving an application subscriber profile based on the data source.

18 . The method of claim 10 , wherein forwarding the processed stream of data packets from the network apparatus further comprises forwarding the processed stream of data packets to the network.

19 . The method of claim 10 , wherein forwarding the processed stream of data packets from the network apparatus comprises forwarding the processed stream of data packets to a storage device.

20 . The method of claim 10 , further comprising determining a destination to forward the processed stream of data packets.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2020
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 052700/0638 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 29877/0668 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC. AS SUCCESSOR BY MERGER TO CROSSBEAM SYSTEMS, INC.
Reel/Frame 035797/0004 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
MERGER Recorded May 28, 2013
From: CROSSBEAM SYSTEMS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 030492/0146 →
SECURITY AGREEMENT Recorded Feb 26, 2013
From: CROSSBEAM SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 029877/0668 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2013
From: SILICON VALLEY BANK
To: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
Reel/Frame 029599/0731 →
SECURITY AGREEMENT Recorded Nov 9, 2012
From: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
To: SILICON VALLEY BANK
Reel/Frame 029275/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2011
From: KORSUNSKY, YEVGENY; AKERMAN, MOISEY
To: CROSSBEAM SYSTEMS, INC.
Reel/Frame 026300/0841 →