IP Library Granted Patent US 11,595,240
Granted Patent B2
US 11,595,240 · App. 17/142,145 · Granted Feb 28, 2023

Dynamic service chaining and late binding

Inventor: Anil Rao (Santa Clara, CA)
Assignee: Gigamon Inc.
H04L41/046H04L12/4633H04L41/12H04L41/22H04L43/022H04L43/028H04L43/062H04L43/12H04L45/02H04L47/24H04L49/70H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,240
App. No.
17/142,145
Granted
Feb 28, 2023
Kind
B2
Abstract

A visibility platform can be used to monitor traffic traversing private cloud infrastructures and/or public cloud infrastructures. In some instances, the traffic is provided to a set of network services that are accessible to the visibility platform. These network services can be provisioned in a serial or parallel fashion. Network service chaining can be used to ensure that traffic streams skip unnecessary network services and receive only those network services that are needed. For example, an email service chain can include virus, spam, and phishing detection, while a video streaming service chain can include traffic shaping policies to satisfy quality of service (QoS) guarantees. When the visibility platform is represented as a graph that makes use of action sets, network service chains can be readily created or destroyed on demand.

Claims (24)

1. A method comprising:

receiving first input indicative of a selection of a map that includes a rule for filtering data packets from amongst a plurality of maps that were not bound to network objects during construction of the plurality of maps;

receiving second input indicative of a selection of (i) a source network object of a network visibility appliance and (ii) a destination network object of the network visibility appliance; and

binding the map to the network visibility appliance prior to runtime by associating the map with the source network object and the destination network object in a data structure upon deployment of the map within the network visibility appliance.

2. The method of claim 1 , wherein said binding is performed by a controller that is communicatively connected to the network visibility appliance.

3. The method of claim 1 , wherein said binding further comprises editing an action set that is associated with a programmable data structure corresponding to the map.

4. The method of claim 1 , wherein the network visibility appliance is configured to receive traffic from an agent hosted on a virtual machine belonging to one of a plurality of tenants to which a cloud computing platform is accessible.

5. A processing system comprising:

a memory;

a network interface;

a processor coupled to the network interface and the memory, and configured to control the processing system to:

receive first input indicative of a selection of a map that includes a rule for filtering data packets from amongst a plurality of maps that were not bound to network objects during construction of the plurality of maps;

receive second input indicative of a selection of (i) a source network object of a network visibility appliance and (ii) a destination network object of the network visibility appliance; and

bind the map to the network visibility appliance prior to runtime by associating the map with the source network object and the destination network object in a data structure upon deployment of the map within the network visibility appliance.

6. The processing system of claim 5 , wherein saki binding the map to the network visibility appliance is to be performed by a controller that is communicatively connected to the network visibility appliance.

7. The processing system of claim 5 , wherein said binding the map to the network visibility appliance comprises editing an action set that is associated with a programmable data structure corresponding to the map.

8. The processing system of claim 5 , wherein the network visibility appliance is configured to receive traffic from an agent hosted on a virtual machine belonging to one of a plurality of tenants to which a cloud computing platform is accessible.

9. A non-transitory machine-readable storage medium having stored therein instructions, execution of which in a processing system causes the processing system to perform operations comprising:

receiving first input indicative of a selection of a map that includes a rule for filtering data packets from amongst a plurality of maps that were not bound to network objects during construction of the plurality of maps;

receiving second input indicative of a selection of (i) a source network object of a network visibility appliance and (ii) a destination network object of the network visibility appliance; and

binding the map to the network visibility appliance prior to runtime by associating the map with the source network object and the destination network object in a data structure upon deployment of the map within the network visibility appliance.

10. The non-transitory machine-readable storage medium of claim 9 , wherein said binding is performed by a controller that is communicatively connected to the network visibility appliance.

11. The non-transitory machine-readable storage medium of claim 9 , wherein said binding further comprises editing an action set that is associated with a programmable data structure corresponding to the map.

12. The non-transitory machine-readable storage medium of claim 9 , wherein the network visibility appliance is configured to receive traffic from an agent hosted on a virtual machine belonging to one of a plurality of tenants to which a cloud computing platform is accessible.

Assignments (2)
SECURITY INTEREST Recorded Mar 11, 2022
From: GIGAMON INC.; ICEBRG LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 059362/0717 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2021
From: RAO, ANIL
To: GIGAMON INC.
Reel/Frame 054819/0622 →
Continuity (3)
Continuation 15805487 · Nov 7, 2017
Provisional Application 62425577 · Nov 22, 2016
Related Publication 20210168016A1 · Jun 3, 2021