IP Library Granted Patent US 9,800,608
Granted Patent B2
US 9,800,608 · App. 12/982,999 · Granted Oct 24, 2017

Processing data flows with a data flow processor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,800,608
App. No.
12/982,999
Granted
Oct 24, 2017
Kind
B2
Abstract

An apparatus and method to distribute applications and services in and throughout a network and to secure the network includes the functionality of a switch with the ability to apply applications and services to received data according to respective subscriber profiles. Front-end processors, or Network Processor Modules (NPMs), receive and recognize data flows from subscribers, extract profile information for the respective subscribers, utilize flow scheduling techniques to forward the data to applications processors, or Flow Processor Modules (FPMs). The FPMs utilize resident applications to process data received from the NPMs. A Control Processor Module (CPM) facilitates applications processing and maintains connections to the NPMs, FPMs, local and remote storage devices, and a Management Server (MS) module that can monitor the health and maintenance of the various modules.

Claims (35)

1. A network apparatus for processing data flows, comprising:

a chassis;

one or more memories within the chassis; and

one or more network processors within the chassis, the one or more network processors configured to execute instructions stored in the one or more memories to:

receive and forward a stream of data packets in a network;

recognize one or more data packets in the stream of data packets that contain data, including subscriber profile information, to be processed by an application executing on the network apparatus by applying a policy to the data;

define an application suite by storing a plurality of applications in the one or more memories including at least two of: a virus detection application, an intrusion detection application, a firewall application, a content filtering application, a privacy protection application, and a policy-based browsing application;

select an application of the plurality of applications stored in the one or more memories for processing the stream of data packets based on payloads of the data packets and on the subscriber profile information

execute the selected application so as to process the stream of data packets by applying the policy to the payloads using machine learning logic to dynamically reconfigure a data flow, resulting in processed data, the machine learning logic configured to:

compare a feature vector of the data flow with each of a plurality of artificial neurons that populate an array with each of the plurality of artificial neurons characterized by a weight vector;

declare the weight vector positioned at the smallest Euclidean distance from the feature vector to be the winning neuron;

map the feature vector to the winning neuron;

repeat the comparing, declaring, and mapping with additional feature vectors to create an output map;

determine whether the data flow is anomalous by determining whether the output map is atypical due to at least one value in the output map being larger or smaller than a threshold in relation to other values in the output map; and

return the processed data for forwarding to a destination in the network.

2. The network apparatus of claim 1 , wherein the one or more network processors are further configured to execute instructions stored in the one or more memories to perform a step from the group consisting of, downloading applications to the one or more memories, and deleting applications from the one or more memories.

3. The network apparatus of claim 1 , wherein the one or more network processors are further configured to execute instructions stored in the one or more memories to identify a source of the stream of data packets, to detect a subscriber profile in the stream of data packets, and to identify the source of the stream based on the subscriber profile.

4. A method of processing data flows, comprising:

receiving a stream of data packets in a network within a chassis of a network apparatus, the network apparatus comprising at least one network processor and at least one memory;

recognizing one or more data packets in the stream of data packets that contain data, including subscriber profile information, to be processed by an application executing on the network apparatus by applying a policy to the data;

defining an application suite by storing a plurality of applications in the at least one memory, the plurality of applications including at least two of: a virus detection application, an intrusion detection application, a firewall application, a content filtering application, a privacy protection application, and a policy-based browsing application;

selecting an application of the plurality of applications stored in the at least one memory for processing the stream of data packets based on payloads of the data packets and on the subscriber profile information;

executing the selected application so as to process the data by applying the policy to the data using machine learning logic to dynamically reconfigure a data flow, resulting in processed data, the machine learning logic configured to:

compare a feature vector of the data flow with each of a plurality of artificial neurons that populate an array with each of the plurality of artificial neurons characterized by a weight vector;

declare the weight vector positioned at the smallest Euclidean distance from the feature vector to be the winning neuron;

map the feature vector to the winning neuron;

repeat the comparing, declaring, and mapping with additional feature vectors to create an output map;

determine whether the data flow is anomalous by determining whether the output map is atypical due to at least one value in the output map being larger or smaller than a threshold in relation to other values in the output map; and

returning the processed data for forwarding to a destination in the network.

5. The method of claim 4 , further comprising managing the plurality of applications for executing on the network apparatus.

6. The method of claim 4 , wherein the executing of the selected application further comprises selecting the application based on the subscriber profile information.

7. The network apparatus of claim 1 , wherein the selected application is the privacy protection application or the content filtering application.

8. The network apparatus as in claim 7 , wherein the payloads of the data packets comprise a social security number or a Health Insurance Portability and Accountability (HIP AA) record.

9. The method as in claim 4 , wherein the selected application is the privacy protection application or the content filtering application.

10. The method as in claim 9 , wherein the payloads of the data packets comprise a social security number or a Health Insurance Portability and Accountability (HIP AA) record.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 29877/0668 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC. AS SUCCESSOR BY MERGER TO CROSSBEAM SYSTEMS, INC.
Reel/Frame 035797/0004 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
MERGER Recorded May 28, 2013
From: CROSSBEAM SYSTEMS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 030492/0146 →
SECURITY AGREEMENT Recorded Feb 26, 2013
From: CROSSBEAM SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 029877/0668 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2013
From: SILICON VALLEY BANK
To: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
Reel/Frame 029599/0731 →
SECURITY AGREEMENT Recorded Nov 9, 2012
From: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
To: SILICON VALLEY BANK
Reel/Frame 029275/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2011
From: KORSUNSKY, YEVGENY; AKERMAN, MOISEY
To: CROSSBEAM SYSTEMS, INC.
Reel/Frame 026300/0841 →