IP Library Granted Patent US 9,525,696
Granted Patent B2
US 9,525,696 · App. 13/416,647 · Granted Dec 20, 2016

Systems and methods for processing data flows

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,525,696
App. No.
13/416,647
Granted
Dec 20, 2016
Kind
B2
Abstract

A flow processing facility, which uses a set of artificial neurons for pattern recognition, such as a self-organizing map, in order to provide security and protection to a computer or computer system supports unified threat management based at least in part on patterns relevant to a variety of types of threats that relate to computer systems, including computer networks. Flow processing for switching, security, and other network applications, including a facility that processes a data flow to address patterns relevant to a variety of conditions are directed at internal network security, virtualization, and web connection security. A flow processing facility for inspecting payloads of network traffic packets detects security threats and intrusions across accessible layers of the IP-stack by applying content matching and behavioral anomaly detection techniques based on regular expression matching and self-organizing maps. Exposing threats and intrusions within packet payload at or near real-time rates enhances network security from both external and internal sources while ensuring security policy is rigorously applied to data and system resources. Intrusion Detection and Protection (IDP) is provided by a flow processing facility that processes a data flow to address patterns relevant to a variety of types of network and data integrity threats that relate to computer systems, including computer networks.

Claims (26)

1. A flow processing facility for implementing a security policy, comprising:

a plurality of application processing hardware modules, each configured with an application for processing data packets;

a subscriber profile for identifying data packets associated with the subscriber profile in a stream of data packets; and

a network processing module for identifying one or more of the plurality of application processing modules for processing the identified data packets based on an association of the application configured on each application processing module with the subscriber profile and for transmitting the identified data packets in at least one of series and parallel to the identified application processing modules based on the security policy.

2. The flow processing facility of claim 1 wherein transmitting the identified packets in parallel to the applications includes parallel transmitting of the identified data packets to each of the identified application processor modules.

3. The flow processing facility of claim 1 wherein transmitting the identified packets in parallel to the applications includes parallel transmitting of the identified data packets to a plurality of applications configured on one of the identified application processing modules.

4. The flow processing facility of claim 3 wherein the plurality of applications includes a monitoring application and a network data processing application.

5. The flow processing facility of claim 4 , wherein the monitoring application includes an intrusion detection application.

6. The flow processing facility of claim 4 , wherein the network data processing application includes at least one of a URL filter, a content filter, a firewall, and an intrusion prevention application.

7. The flow processing facility of claim 4 wherein the plurality of applications includes a plurality of monitoring applications for monitoring data flows at a plurality of protocol layers.

8. The flow processing facility of claim 7 , wherein the plurality of monitoring applications includes at least one intrusion detection application for detecting intrusions at a portion of the plurality of protocol layers.

9. The flow processing facility of claim 1 wherein transmitting the identified packets in series to the applications includes transmitting the identified data packets to be processed by a first application before being processed by a second application.

10. The flow processing facility of claim 9 , wherein the second application is selected from a list consisting of an anti-virus application, a URL filter, a content filter, a firewall, an intrusion prevention service, and a database protection application.

11. The flow processing facility of claim 1 wherein transmitting the identified packets in series to the applications includes transmitting the identified data packets to be processed by a second application after the identified data packets are processed by a first application.

12. The flow processing facility of claim 11 , wherein the second application is selected from a list consisting of an anti-virus application, a URL filter, a content filter, a firewall, an intrusion prevention application, and a database protection application.

13. A flow processing facility for implementing a security policy, comprising:

a plurality of applications configured on one or more application processing hardware modules for processing data packets;

a subscriber profile for identifying data packets associated with the subscriber profile in a stream of data packets;

a security policy for determining a portion of the identified data packets to be processed by each of the applications; and

a network processing module for identifying at least one of the one or more application processing modules for processing the identified data packets based on an association of applications configured on each of the one or more application processing modules with the subscriber profile, and for transmitting the portion of the identified data packets in at least one of series and parallel to the applications configured on the identified application processing modules based on the security policy.

14. The flow processing facility of claim 13 , wherein transmitting the identified packets in parallel to the applications includes parallel transmitting of the identified data packets to each of the identified plurality of application processor modules.

15. The flow processing facility of claim 13 , wherein transmitting the identified packets in parallel to the applications includes parallel transmitting of the identified data packets to a plurality of applications configured on one of the plurality of application processing modules.

16. The flow processing facility of claim 13 , wherein the plurality of applications includes a monitoring application and a network data processing application, wherein the monitoring application includes an intrusion detection application and wherein the network data processing application includes at least one of a URL filter, a content filter, a firewall, and an intrusion prevention application.

17. The flow processing facility of claim 13 , wherein the plurality of applications includes a plurality of monitoring applications for monitoring data flows at a plurality of protocol layers, wherein the plurality of monitoring applications includes at least one intrusion detection application for detecting intrusions at a portion of the plurality of protocol layers.

18. The flow processing facility of claim 13 , wherein transmitting the identified packets in series to the applications includes transmitting the identified data packets to be processed by a first application before being processed by a second application that is selected from a list consisting of an anti-virus application, a URL filter, a content filter, a firewall, an intrusion prevention service, and a database protection application.

19. The flow processing facility of claim 13 , wherein transmitting the identified packets in series to the applications includes transmitting the identified data packets to be processed by a second application after the identified data packets are processed by a first application, wherein the second application is selected from a list consisting of an anti-virus application, a URL filter, a content filter, a firewall, an intrusion prevention application, and a database protection application.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 29877/0668 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC. AS SUCCESSOR BY MERGER TO CROSSBEAM SYSTEMS, INC.
Reel/Frame 035797/0004 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
MERGER Recorded May 28, 2013
From: CROSSBEAM SYSTEMS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 030492/0146 →
SECURITY AGREEMENT Recorded Feb 26, 2013
From: CROSSBEAM SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 029877/0668 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2013
From: SILICON VALLEY BANK
To: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
Reel/Frame 029599/0731 →
SECURITY AGREEMENT Recorded Nov 9, 2012
From: CROSSBEAM SYSTEMS, INC.; CB SYSTEMS HOLDINGS II, INC.; CB SYSTEMS ACQUISITION CO.
To: SILICON VALLEY BANK
Reel/Frame 029275/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2012
From: KAPOOR, HARSH; AKERMAN, MOISEY; JUSTUS, STEPHEN D.; FERGUSON, JOHN C.; KORSUNSKY, YEVGENY; GALLO, PAUL S.; LEE, CHARLES CHING; MARTIN, TIMOTHY M.; FU, CHUNSHENG; XU, WEIDONG
To: CROSSBEAM SYSTEMS, INC.
Reel/Frame 028086/0964 →