IP Library Granted Patent US 9,503,425
Granted Patent B2
US 9,503,425 · App. 14/964,502 · Granted Nov 22, 2016

Method to enable deep packet inspection (DPI) in openflow-based software defined network (SDN)

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,503,425
App. No.
14/964,502
Granted
Nov 22, 2016
Kind
B2
Abstract

The present invention relates to a method and system for performing deep packet inspection of messages transmitted through a network switch in a Software Defined Network (SDN). Embodiments of the invention include a network switch, a controller, and a firewall in a software defined networking environment. In the present invention, the network switch is a simple network switch that is physically separate from the controller and the firewall. The invention may include a plurality of physically distinct network switches communicating with one or more controllers and firewalls. In certain instances, communications between the network switch, the controller, and the firewall are performed using the Open Flow standard communication protocol.

Claims (71)

1. A method for performing deep packet inspection on a plurality of data packets belonging to a flow of data packet, the method comprising:

receiving a first packet at a switch; identifying that the first packet belongs to a flow of a plurality of packets; mirroring at least a portion of the first packet to a firewall over a first communication interface at the switch, wherein the portion of the first packet is scanned by a deep packet inspection (DPI) scanner at the firewall;

receiving a message from the firewall indicating that the portion of the first packet does not include a threat;

sending the first packet to a destination identified by information contained in the first packet over a port at the switch in response to receiving the message from the firewall indicating that the first packet does not include a threat;

receiving a second packet at the switch;

identifying that the second packet belongs to the flow of the plurality of packets;

mirroring, by a hardware processor, at least a portion of the second packet to the firewall over the first communication interface at the switch, wherein the firewall scans the portion of the second packet by a DPI scanner and identifies that the second packet includes a threat; prior to receiving the first packet: setting the switch to an observe mode; receiving a plurality of other packets that are associated with the flow;

mirroring, by the hardware processor, at least a portion of each of the plurality of other packets to the firewall;

sending each of the other packets to a destination without waiting for a message from the firewall when the switch is set to the observe mode, wherein the firewall collects information from at least one of the other packets received from the switch; and

setting the switch to an enforce mode.

2. The method of claim 1 , wherein the firewall sends a report to another computer identifying that the second packet includes a threat.

3. The method of claim 1 , further comprising receiving a set configuration command from a controller, wherein the set configuration command identifies that the flow of the plurality of packets is associated with a DPI level.

4. The method of claim 3 , wherein the set configuration command received from the controller includes a count, the count corresponds to the size of the portion of the first and the second data packet sent to the firewall for DPI.

5. The method of claim 1 , further comprising:

receiving a command from a controller identifying a count that corresponds to the size of the portion of the first data packet sent to the firewall before the switch receives the first packet; and

receiving a second command from the controller identifying a count that corresponds to the size of the portion of the second data packet sent to the firewall before the switch receives the second packet.

6. The method of claim 1 , further comprising:

receiving a message from the firewall by the switch indicating that the second packet includes the threat; and

dropping the second packet by the switch.

7. The method of claim 1 , further comprising:

receiving a message from the firewall by the switch indicating that the second packet includes the threat; and

the switch dropping the flow of packets.

8. The method of claim 1 , further comprising:

receiving a third packet at the switch;

identifying that the third packet is not associated with an entry in a flow table at the switch;

sending at least a portion of the third packet to the firewall; and

receiving a message from the firewall regarding the third packet.

9. The method of claim 8 , further comprising the switch dropping the third packet when the message received from the firewall indicates that the third packet should be dropped.

10. The method of claim 8 , further comprising the switch sending the third packet to the destination or another destination when the received message indicates that the third packet can be sent to the destination or the another destination.

11. A non-transitory computer-readable storage medium embodied thereon a program executable by a hardware processor for performing a method, the method comprising:

receiving a first packet at a switch;

identifying that the first packet belongs to a flow of a plurality of packets;

mirroring at least a portion of the first packet to a firewall over a first communication interface at the switch, wherein the portion of the first packet is scanned by a deep packet inspection (DPI) scanner at the firewall;

receiving a message from the firewall indicating that the portion of the first packet does not include a threat;

sending the first packet to a destination identified by information contained in the first packet over a port at the switch in response to receiving the message from the firewall indicating that the first packet does not include a threat;

receiving a second packet at the switch;

identifying that the second packet belongs to the flow of the plurality of packets;

mirroring at least a portion of the second packet to the firewall over the first communication interface at the switch, wherein the firewall scans the portion of the second packet by a DPI scanner and identifies that the second packet includes a threat;

setting the switch to an observe mode;

receiving a plurality of other packets that are associated with the flow;

mirroring by the hardware processor, at least a portion of each of the plurality of other packets to the firewall;

sending each of the other packets to a destination without waiting for a message from the firewall when the switch is set to the observe mode, wherein the firewall collects information from at least one of the other packets received from the switch; and

setting the switch to an enforce mode.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the firewall sends a report to another computer identifying that the second packet includes a threat.

13. The non-transitory computer-readable storage medium of claim 11 , the program further executable to receive a set configuration command from a controller, wherein the set configuration command identifies that the flow of the plurality of packets is associated with a DPI level.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the set configuration command received from the controller includes a count, the count corresponds to the size of the portion of the first and the second data packet sent to the firewall for DPI.

15. The non-transitory computer-readable storage medium of claim 11 , further comprising:

receiving a command from a controller identifying a count that corresponds to the size of the portion of the first data packet sent to the firewall before the switch receives the first packet; and

receiving a second command from the controller identifying a count that corresponds to the size of the portion of the second data packet sent to the firewall before the switch receives the second packet.

16. The non-transitory computer-readable storage medium of claim 11 , the program further executable to:

receive a message from the firewall by the switch indicating that the second packet includes the threat; and

drop the second packet.

17. The non-transitory computer-readable storage medium of claim 11 , further comprising:

receiving a message from the firewall by the switch indicating that the second packet includes the threat; and

the switch dropping the flow of packets.

18. A system for performing deep packet inspection on a plurality of data packets belonging to a flow of data packets, the system comprising:

a hardware processor;

a controller; a firewall; and

a switch, wherein the switch:

receives a set configuration command from the controller;

receives a first packet;

identifies that the first packet belongs to a flow of a plurality of packets;

mirrors at least a portion of the first packet to the firewall over a first communication interface at the switch according to the set configuration command, wherein the portion of the first packet is scanned by a deep packet inspection (DPI) scanner at the firewall;

receives a message from the firewall indicating that the portion of the first packet does not include a threat;

sends the first packet to a destination identified by information contained in the first packet over a port at the switch in response to receiving the message from the firewall indicating that the first packet does not include a threat;

receives second packet at the switch; identifies that the second packet belongs to the flow of the plurality of packets;

mirrors at least a portion of the second packet to the firewall over the first communication interface at the switch, wherein the firewall scans the portion of the second packet by a DPI scanner and identifies that the second packet includes a threat;

set the switch to an observe mode; receive a plurality of other packets that are associated with the flow;

mirror at least a portion of each of the plurality of other packets to the firewall;

send each of the other packets to a destination without waiting for a message from the firewall when the switch is set to the observe mode, wherein the firewall collects information from at least one of the other packets received from the switch; and

set the switch to an enforce mode.

Assignments (32)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046923/0614 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071556/0479 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT R/F 046327/0486 Recorded Sep 4, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 047320/0608 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT R/F 046327/0347 Recorded Sep 4, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 047011/0484 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Aug 24, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046923/0614 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 24, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046923/0672 →
CHANGE OF NAME Recorded Jun 19, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046393/0009 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2018
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 046244/0366 →
CHANGE OF NAME Recorded May 25, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046246/0059 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded May 16, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046169/0718 →
CHANGE OF NAME Recorded May 15, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046163/0137 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF REEL 037848 FRAME 0210 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040031/0725 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 037848 FRAME 0001 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0152 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 037847 FRAME 0843 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0366 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037848/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 037848/0210 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037847/0843 →
MERGER Recorded Dec 9, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037254/0001 →
CONVERSION AND NAME CHANGE Recorded Dec 9, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037256/0277 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2015
From: LING, HUI; CHEN, ZHONG
To: SONICWALL, INC.
Reel/Frame 037256/0282 →