IP Library Granted Patent US 9,203,806
Granted Patent B2
US 9,203,806 · App. 13/739,178 · Granted Dec 1, 2015

Rule swapping in a packet network

Inventors: David K. Ahn (Winston-Salem, NC); Steven Rogers (Leesburg, VA); Sean Moore (Hollis, NH)
Assignee: Centripetal Networks, Inc.
H04L63/0263G06N5/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,203,806
App. No.
13/739,178
Granted
Dec 1, 2015
Kind
B2
Abstract

In some variations, first and second rule sets may be received by a network protection device. The first and second rule sets may be preprocessed. The network protection device may be configured to process packets in accordance with the first rule set. Packets may be received by the network protection device. A first portion of the packets may be processed in accordance with the first rule set. The network protection device may be reconfigured to process packets in accordance with the second rule set. A second portion of the packets may be processed in accordance with the second rule set.

Claims (77)

1. A method comprising:

receiving, by a network protection device, a first rule set and a second rule set;

preprocessing, by the network protection device, the first rule set and the second rule set to optimize performance of the network protection device for processing packets in accordance with at least one of the first rule set or the second rule set;

configuring at least two processors of the network protection device to process packets in accordance with the first rule set;

after the preprocessing and the configuring, receiving, by the network protection device, a plurality of packets;

processing, by the network protection device and in accordance with the first rule set, a portion of the plurality of packets;

signaling, each processor of the at least two processors, to process packets in accordance with the second rule set; and

configuring, each processor of the at least two processors, to responsive to the signaling to process packets in accordance with the second rule set:

cease processing of one or more packets;

cache the one or more packets;

reconfigure to process packets in accordance with the second rule set;

signal completion of reconfiguration to process packets in accordance with the second rule set; and

responsive to receiving signaling that each other processor of the at least two processors has completed reconfiguration to process packets in accordance with the second rule set, process, in accordance with the second rule set, the one or more packets.

2. The method of claim 1 , comprising:

storing, by the network protection device, configuration information for processing packets in accordance with the first rule set;

utilizing, by the network protection device, the configuration information to reconfigure to process packets in accordance with the first rule set; and

after the utilizing, processing, by the network protection device and in accordance with the first rule set, an additional portion of the plurality of packets.

3. The method of claim 1 , comprising:

storing, by the network protection device, the first rule set and the second rule set in a memory buffer; and

dynamically adjusting, by the network protection device and based on at least one of a size of the first rule set or a size of the second rule set, a size of the memory buffer.

4. The method of claim 1 , wherein the signaling to process packets in accordance with the second rule set is performed in response to the network protection device receiving a message invoking the second rule set.

5. The method of claim 1 , wherein the signaling to process packets in accordance with the second rule set is performed in response to one or more detected network conditions indicating a network attack.

6. The method of claim 1 , wherein the preprocessing comprises merging two or more rules included in at least one of the first rule set or the second rule set into a single rule.

7. The method of claim 1 , wherein the preprocessing comprises separating a rule included in at least one of the first rule set or the second rule set into two or more rules.

8. The method of claim 1 , wherein the preprocessing comprises reordering one or more rules included in at least one of the first rule set or the second rule set.

9. A system comprising:

a plurality of processors; and

a memory comprising instructions that when executed by at least one processor of the plurality of processors cause the system to:

receive a first rule set and a second rule set;

preprocess the first rule set and the second rule set to optimize performance of the system for processing packets in accordance with at least one of the first rule set or the second rule set;

configure at least two processors of the plurality of processors to process packets in accordance with the first rule set;

after preprocessing the first rule set and the second rule set and configuring the at least two processors to process packets in accordance with the first rule set, receive a plurality of packets;

process, in accordance with the first rule set, a portion of the plurality of packets;

signal, each processor of the at least two processors, to process packets in accordance with the second rule set; and

configure, each processor of the at least two processors to, responsive to being signaled to process packets in accordance with the second rule set:

cease processing of one or more packets;

cache the one or more packets;

reconfigure to process packets in accordance with the second rule set;

signal completion of reconfiguration to process packets in accordance with the second rule set; and

responsive to receiving signaling that each other processor of the at least two processors has completed reconfiguration to process packets in accordance with the second rule set, process, in accordance with the second rule set, the one or more packets.

10. The system of claim 9 , wherein the instructions, when executed by the at least one processor, cause the system to:

store configuration information for processing packets in accordance with the first rule set;

utilize the configuration information to reconfigure to process packets in accordance with the first rule set; and

after utilizing the configuration information to reconfigure to process packets in accordance with the first rule set, process, in accordance with the first rule set, an additional portion of the plurality of packets.

11. The system of claim 9 , wherein the instructions, when executed by the at least one processor, cause the system to:

store the first rule set and the second rule set in a memory buffer; and

dynamically adjust, based on at least one of a size of the first rule set or a size of the second rule set, a size of the memory buffer.

12. The system of claim 9 , wherein the instructions, when executed by the at least one processor, cause the system to signal to process packets in accordance with the second rule set in response to the system receiving a message invoking the second rule set.

13. The system of claim 9 , wherein the instructions, when executed by the at least one processor, cause the system to signal to process packets in accordance with the second rule set in response to one or more detected network conditions indicating a network attack.

14. The system of claim 9 , wherein the instructions, when executed by the at least one processor, cause the system to, prior to configuring the at least two processors to process packets in accordance with the first rule set, merge two or more rules included in at least one of the first rule set or the second rule set into a single rule.

15. The system of claim 9 , wherein the instructions, when executed by the at least one processor, cause the system to, prior to configuring the at least two processors to process packets in accordance with the first rule set, separate a rule included in at least one of the first rule set or the second rule set into two or more rules.

16. The system of claim 9 , wherein the instructions, when executed by the at least one processor, cause the system to, prior to configuring the at least two processors to process packets in accordance with the first rule set, reorder one or more rules included in at least one of the first rule set or the second rule set.

17. One or more non-transitory computer-readable media comprising instructions that when executed by a computing system cause the computing system to:

receive a first rule set and a second rule set;

preprocess the first rule set and the second rule set to optimize performance of the computing system for processing packets in accordance with at least one of the first rule set or the second rule set;

configure at least two processors of the computing system to process packets in accordance with the first rule set;

after preprocessing the first rule set and the second rule set and configuring the at least two processors to process packets in accordance with the first rule set, receive a plurality of packets;

process, in accordance with the first rule set, a portion of the plurality of packets;

signal, each processor of the at least two processors, to process packets in accordance with the second rule set; and

configure, each processor of the at least two processors to, responsive to being signaled to process packets in accordance with the second rule set:

cease processing of one or more packets;

cache the one or more packets;

reconfigure to process packets in accordance with the second rule set;

signal completion of reconfiguration to process packets in accordance with the second rule set; and

responsive to receiving signaling that each other processor of the at least two processors has completed reconfiguration to process packets in accordance with the second rule set, process, in accordance with the second rule set, the one or more packets.

18. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the computing system, cause the computing system to:

store configuration information for processing packets in accordance with the first rule set;

utilize the configuration information to reconfigure to process packets in accordance with the first rule set; and

after utilizing the configuration information to reconfigure to process packets in accordance with the first rule set, process, in accordance with the first rule set, an additional portion of the plurality of packets.

19. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the computing system, cause the computing system to:

store the first rule set and the second rule set in a memory buffer; and

dynamically adjust, based on at least one of a size of the first rule set or a size of the second rule set, a size of the memory buffer.

20. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the computing system, cause the computing system to signal to process packets in accordance with the second rule set in response to the computing system receiving a message invoking the second rule set.

21. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the computing system, cause the computing system to signal to process packets in accordance with the second rule set in response to one or more detected network conditions indicating a network attack.

22. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the computing system, cause the computing system to, prior to configuring the at least two processors to process packets in accordance with the first rule set, merge two or more rules included in at least one of the first rule set or the second rule set into a single rule.

23. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the computing system, cause the computing system to, prior to configuring the at least two processors to process packets in accordance with the first rule set, separate a rule included in at least one of the first rule set or the second rule set into two or more rules.

24. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the computing system, cause the computing system to, prior to configuring the at least two processors to process packets in accordance with the first rule set, reorder one or more rules included in at least one of the first rule set or the second rule set.

Assignments (4)
CHANGE OF NAME Recorded Jan 20, 2023
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 062446/0660 →
SECURITY INTEREST Recorded Mar 4, 2019
From: SMITH, DOUGLAS A
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 048492/0499 →
SECURITY INTEREST Recorded Apr 19, 2017
From: CENTRIPETAL NETWORKS, INC.
To: SMITH, DOUGLAS A.
Reel/Frame 042056/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2013
From: AHN, DAVID K; ROGERS, STEVEN; MOORE, SEAN
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 029613/0121 →
Continuity (1)
Related Publication 20140201123A1 · Jul 17, 2014