IP Library Granted Patent US 10,284,522
Granted Patent B2
US 10,284,522 · App. 15/610,995 · Granted May 7, 2019

Rule swapping for network protection

Inventors: David K. Ahn (Winston-Salem, NC); Steven Rogers (Leesburg, VA); Sean Moore (Hollis, NH)
Assignee: Centripetal Networks, Inc.
H04L63/0263G06N5/02H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,522
App. No.
15/610,995
Granted
May 7, 2019
Kind
B2
Abstract

In some variations, first and second rule sets may be received by a network protection device. The first and second rule sets may be preprocessed. The network protection device may be configured to process packets in accordance with the first rule set. Packets may be received by the network protection device. A first portion of the packets may be processed in accordance with the first rule set. The network protection device may be reconfigured to process packets in accordance with the second rule set. A second portion of the packets may be processed in accordance with the second rule set.

Claims (66)

1. A method comprising:

receiving, by a network device, a plurality of packets;

processing, by the network device, a first portion of the plurality of packets in accordance with a first rule set;

receiving, by the network device, a configuration signal to configure the network device to process packets in accordance with a second rule set; and

responsive to receiving the configuration signal:

ceasing processing of one or more packets of the plurality of packets;

caching the one or more packets; and

reconfiguring the network device to process packets in accordance with the second rule set; and

responsive to completing of the reconfiguring, processing the one or more cached packets in accordance with the second rule set.

2. The method of claim 1 , further comprising:

storing, by the network device, configuration information for processing packets in accordance with the first rule set;

configuring, by the network device, the network device to process packets in accordance with the first rule set based on the stored configuration information; and

processing, after the configuring, by the network device, a second portion of the plurality of packets in accordance with the first rule set.

3. The method of claim 1 , further comprising:

storing, by the network device, the first rule set and the second rule set in a memory buffer.

4. The method of claim 1 , wherein the configuration signal is responsive to the network device receiving a message indicating a network attack.

5. The method of claim 1 , wherein each of the rules of both the first rule set and second rule set are associated with at least one action to be applied to a packet being processed.

6. The method of claim 1 , wherein the reconfiguring the network device to process packets in accordance with the second rule set comprises reconfiguring a plurality of processors in the network device with the second rule set.

7. The method of claim 1 , further comprising:

preprocessing the first rule set and the second rule set by merging a first plurality of rules included in at least one of the first rule set or the second rule set into a single rule; or

preprocessing the first rule set and the second rule set by separating a rule included in at least one of the first rule set or the second rule set into a second plurality of rules; or

preprocessing the first rule set and the second rule set by reordering one or more rules included in at least one of the first rule set or the second rule set.

8. A system comprising:

at least one processor; and

memory comprising instructions that, when executed by the at least one processor, cause the system to:

receive a plurality of packets;

process a first portion of the plurality of packets in accordance with a first rule set;

responsive to a configuration signal to process packets in accordance with a second rule set:

cease processing of one or more packets of the received plurality of packets;

cache the one or more packets; and

reconfigure the system to process packets in accordance with the second rule set; and

responsive to completion of reconfiguration, process the one or more cached packets in accordance with the second rule set.

9. The system of claim 8 , wherein the instructions, when executed by the at least one processor, further cause the system to:

store configuration information for processing packets in accordance with the first rule set;

configure the system to process packets in accordance with the first rule set based on the stored configuration information; and

process, after the configuration, a second portion of the plurality of packets in accordance with the first rule set.

10. The system of claim 8 , wherein the instructions, when executed by the at least one processor, further cause the system to:

store the first rule set and the second rule set in a memory buffer.

11. The system of claim 8 , wherein the configuration signal is responsive to the system receiving a message indicating a network attack.

12. The system of claim 8 , wherein each of the rules of both the first rule set and second rule set are associated with at least one action to be applied to a packet being processed.

13. The system of claim 8 , wherein the instructions, when executed by the at least one processor, to cause the system to reconfigure the system to process packets in accordance with the second rule set, further cause the system to:

reconfigure a plurality of processors with the second rule set.

14. The system of claim 8 , wherein the instructions, when executed by the at least one processor, further cause the system to:

preprocess the first rule set and the second rule set by merging a first plurality of rules included in at least one of the first rule set or the second rule set into a single rule; or

preprocess the first rule set and the second rule set by separating a rule included in at least one of the first rule set or the second rule set into a second plurality of rules; or

preprocess the first rule set and the second rule set by reordering one or more rules included in at least one of the first rule set or the second rule set.

15. One or more non-transitory computer-readable media comprising instructions that when executed by a computing system cause the computing system to:

receive a plurality of packets;

process a first portion of the plurality of packets in accordance with a first rule set;

responsive to a configuration signal to process packets in accordance with a second rule set:

cease processing of one or more packets of the plurality of received packets;

cache the one or more packets; and

reconfigure the computing system to process packets in accordance with the second rule set; and

responsive to completion of reconfiguration, process the one or more cached packets in accordance with the second rule set.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the instructions, when executed by the computing system, cause the computing system to:

store the first rule set and the second rule set in a memory buffer.

17. The one or more non-transitory computer-readable media of claim 15 , wherein each of the rules of both the first rule set and second rule set are associated with at least one action to be applied to a packet being processed.

18. The one or more non-transitory computer-readable media of claim 15 , wherein the instructions, when executed by the computing system, cause the computing system to:

store configuration information for processing packets in accordance with the first rule set;

configure the computing system to process packets in accordance with the first rule set based on the stored configuration information; and

process, after the configuration, a second portion of the plurality of packets in accordance with the first rule set.

19. The one or more non-transitory computer-readable media of claim 15 , wherein the configuration signal is responsive to the computing system receiving a message indicating a network attack.

20. The one or more non-transitory computer-readable media of claim 15 , wherein the instructions, when executed by the computing system, cause the computing system to:

preprocess the first rule set and the second rule set by merging a first plurality of rules included in at least one of the first rule set or the second rule set into a single rule; or

preprocess the first rule set and the second rule set by separating a rule included in at least one of the first rule set or the second rule set into a second plurality of rules; or

preprocess the first rule set and the second rule set by reordering one or more rules included in at least one of the first rule set or the second rule set.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2023
From: AHN, DAVID K.; ROGERS, STEVEN; MOORE, SEAN
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 062480/0017 →
CHANGE OF NAME Recorded Jan 25, 2023
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 062493/0549 →
Continuity (3)
Continuation 14921718 · Oct 23, 2015
Continuation 13739178 · Jan 11, 2013
Related Publication 20180115518A1 · Apr 26, 2018