IP Library Granted Patent US 8,666,985
Granted Patent B2
US 8,666,985 · App. 13/421,757 · Granted Mar 4, 2014

Hardware accelerated application-based pattern matching for real time classification and recording of network traffic

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,666,985
App. No.
13/421,757
Granted
Mar 4, 2014
Kind
B2
Abstract

An indexing database utilizes a non-transitory storage medium. A pattern matching processing unit generates preclassification data for the network data packets utilizing pattern matching analysis. At least one processing unit implements a storage process that receives the network data packets, stores the network data packets in at least one of the slots, and transfers the network data packets to a packet capture repository when slots in a shared memory are full. A preclassification process requests from the pattern matching processing unit the preclassification data. An indexing process determines, based upon the preclassification data, whether to invoke or omit additional analysis of the network data packets, and performs at least one of aggregation, classification, or annotation of the network data packets in the shared memory to maintain one or more indices in the indexing database.

Claims (19)

1. A system, comprising:

a shared memory that includes a plurality of slots to transiently store network data packets;

a packet capture repository utilizing a non-transitory storage medium;

an indexing database utilizing a non-transitory storage medium;

a pattern matching processing unit to generate preclassification data for the network data packets utilizing pattern matching analysis, wherein the pattern matching processing unit includes a graphical processing unit with multiple cores to analyze multiple network data packets in parallel; and

at least one processing unit that implements:

a storage process that receives the network data packets, stores the network data packets in at least one of the slots, and transfers the network data packets to the packet capture repository when the slots in the shared memory are full;

a preclassification process that request from the pattern matching processing unit the preclassification data; and

an indexing process to:

determine, based upon the preclassification data, whether to invoke or omit additional analysis of the network data packets, such that the indexing process resources are dedicated to further analyzing network data packets of greater concern, and

perform at least one of aggregation, classification, or annotation of the network data packets in the shared memory to maintain one or more indices in the indexing database.

2. The system of claim 1 wherein the preclassification process normalizes data within the network data packets.

3. The system of claim 1 wherein the pattern matching analysis is Aho-Corasick string matching.

4. The system of claim 1 wherein the pattern matching analysis is selected from identifying the application to which the network data packets relate, identifying the protocol utilized to transmit the network data packets, identifying file types of payload data in the network data packets, identifying source or destination addresses associated with the network data packets and identifying the lengths of network data packets.

5. The system of claim 1 wherein copyless direct memory access data transfers are used between the plurality of slots.

6. The system of claim 1 wherein the additional analysis determines the names and types of files being shared.

7. The system of claim 1 wherein the additional analysis includes identifying and indexing protocol-specific attributes.

8. The system of claim 1 wherein the additional analysis includes identifying and indexing web-based applications.

9. The system of claim 8 wherein identifying and indexing web-based applications includes identifying and indexing a particular HTTP session.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30747/0452 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC., AS SUCCESSOR BY MERGER TO SOLERA NETWORKS, INC.
Reel/Frame 035797/0332 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30521/0379 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC., AS SUCCESSOR BY MERGER TO SOLERA NETWORKS, INC.
Reel/Frame 035797/0899 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
MERGER Recorded Feb 10, 2014
From: SOLERA NETWORKS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 032188/0063 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: SOLERA NETWORKS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030747/0452 →
PATENT SECURITY AGREEMENT Recorded May 31, 2013
From: SOLERA NETWORKS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030521/0379 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2012
From: WOOD, MATTHEW S.; LEVY, JOSEPH H.; MARSTON, MCKAY
To: SOLERA NETWORKS, INC.
Reel/Frame 028273/0413 →