IP Library Granted Patent US 9,119,109
Granted Patent B1
US 9,119,109 · App. 13/316,134 · Granted Aug 25, 2015

Method and an apparatus to perform multi-connection traffic analysis and management

Inventors: Aleksandr Dubrovsky (San Mateo, CA); Boris Yanovsky (Saratoga, CA); Shunhui Zhu (Mountain View, CA)
Assignee: Dell Software Inc.
H04W28/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,119,109
App. No.
13/316,134
Granted
Aug 25, 2015
Kind
B1
Abstract

A method and an apparatus to perform multi-connection traffic analysis and management are described. In one embodiment, the method includes analyzing data packets in the first data flow of a client application for a pattern of interest, where the client application communicates data using first and second data flows. In response to the method detecting a pattern of interest in the first data flow, the method identifies the second data flow and identifies a traffic policy for that second data flow. The method applies the identified traffic policy to the second data flow. Other embodiments have been claimed and described.

Claims (64)

1. A computerized method of applying a dynamically identified traffic policy on a second data flow based on an analysis of a first data flow, the method comprising:

receiving a plurality of packets of the first data flow;

determining that a packet of the plurality of packets is received out of order;

storing a copy of the out of order packet, wherein the out of order packet is stored until a packet with a lower sequence number is received;

allowing the received out of order packet to pass to a destination without re-ordering the plurality of packets whereby the traffic flow of the plurality of packets is not interrupted;

receiving the packet with the lower sequence number;

re-ordering the out of order packet stored and the packet with the lower sequence number;

analyzing the plurality of data packets in the re-ordered first data flow for a pattern of interest, wherein a client application communicates data using the first and second data flows;

identifying the second data flow of the client application;

dynamically identifying a traffic policy for the second data flow; and

applying the traffic policy to the second data flow responsive to detection of a pattern of interest in the first data flow.

2. The method of claim 1 , wherein the dynamically identified traffic policy is to apply quality of service to the second data flow.

3. The method of claim 2 , wherein the dynamically identified traffic policy is to drop data packets of the second data flow.

4. The method of claim 2 , wherein the dynamically identified traffic policy is to restrict the bandwidth for the second data flow.

5. The method of claim 1 , wherein the first data flow is a control channel and the second data flow is a data channel for the client application.

6. The method of claim 5 , further comprising:

passing the corresponding data packet when the one or more data packets compared so far do not contain the pattern of interest; and

blocking the corresponding data packet when the one or more data packets compared so far contain the pattern of interest.

7. The method of claim 1 , wherein the analyzing the plurality of data packets is performed in a plurality of states, each of the plurality of states corresponds to one of a plurality of segments of the pattern of interest.

8. The method of claim 7 , wherein the analyzing the plurality of data packets comprises storing a current state of the pattern matching after performing the pattern matching on a data packet.

9. The method of claim 7 , further comprising:

looking up a stored state when a next data packet is received; and

performing pattern matching on the next data packet from the stored state.

10. An apparatus comprising:

an interface to receive data packets;

a memory; and

a processor executing instructions out of the memory to analyze a plurality of data packets in a first data flow of a client application for a pattern of interest, wherein:

a client application communicates data in a first and second data flow in response to detecting a pattern of interest in the first data flow of the client application, and

the processor executes instructions out of the memory to:

determine that a packet of the plurality of packets is an out or order packet;

store a copy of the out of order packet in the memory, wherein the out of order packet is stored until a packet with a lower sequence number is received;

allow the out of order packet to pass to a destination without re-ordering the plurality of packets whereby the traffic flow of the plurality of packets is not interrupted;

receive the packet with the lower sequence number;

re-order the out of order packet stored and the packet with the lower sequence number;

analyze the plurality of packets in the re-ordered first data flow for a pattern of interest;

identify the second data flow of the client application,

dynamically identify a traffic policy for the second data flow, and

apply the traffic policy to the second data flow responsive to detecting the pattern of interest in the first data flow.

11. The apparatus of claim 10 , wherein the dynamically identified traffic policy is to apply quality of service to the second data flow.

12. The apparatus of claim 10 , wherein the dynamically identified traffic policy is to drop data packets of the second data flow.

13. The apparatus of claim 10 , wherein the dynamically identified traffic policy is to restrict the bandwidth for the second data flow.

14. The apparatus of claim 10 , wherein the first data flow is a control channel and the second data flow is a data channel for the client application.

15. A system comprising:

at least one client application;

a network interface; and

a traffic policy system communicably coupled between the at least one client application and the network interface, wherein the network interface receives data packets, the traffic policy comprising:

a memory; and

a processor executing instructions out of the memory to analyze a plurality of data packets in a first data flow of a client application for a pattern of interest, wherein:

a client application communicates data in a first and second data flow,

the processor further executing instructions out of the memory to:

determine that a packet of the plurality of packets in an out or order packet;

store a copy of the out of order packet in the memory, wherein the out of order packet is stored until a packet with a lower sequence number is received;

allow the out of order packet to pass to a destination without re-ordering the plurality of packets whereby the traffic flow of the plurality of packets is not interrupted;

receive the packet with the lower sequence number;

re-ordering the out of order packet stored and the packet with the lower sequence number;

analyze the re-ordered plurality of packets in the first data flow for the pattern of interest;

identify the second data flow of the client application,

dynamically identify a traffic policy for the second data flow, and

apply the traffic policy to the second data flow responsive to detecting a pattern of interest in the first data flow.

16. The system of claim 15 , further comprising a client machine, wherein the traffic policy system is operable to run on the client machine.

17. The system of claim 15 , further comprising a router, wherein the traffic policy system is operable to run on the router.

18. The system of claim 15 , further comprising a server, wherein the traffic policy system is operable to run on the server.

19. The system of claim 15 , wherein the dynamically identified traffic policy is to apply quality of service to the second data flow.

20. The system of claim 19 , wherein the dynamically identified traffic policy is to drop data packets of the second data flow.

Assignments (24)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Apr 30, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046040/0277 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
CONVERSION AND NAME CHANGE Recorded Jul 15, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 036109/0158 →
MERGER Recorded Jul 15, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 036103/0612 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2011
From: DUBROVSKY, ALEKSANDR; YANOVSKY, BORIS; ZHU, SHUNHUI
To: SONICWALL, INC.
Reel/Frame 027382/0203 →
Continuity (1)
Provisional Application 61428772 · Dec 30, 2010