IP Library Granted Patent US 12,556,443
Granted Patent B2
US 12,556,443 · App. 18/442,985 · Granted Feb 17, 2026

Methods and systems for application and policy based network traffic isolation and data transfer

Inventors: Kumar Ramachandran (Fremont, CA); Venkataraman Anand (San Ramon, CA); Navneet Yadav (Saratoga, CA); Arivu Mani Ramasamy (San Jose, CA); Aaron Edwards (Sunnyvale, CA)
Assignee: Palo Alto Networks, Inc.
H04L41/0668G06F16/285G06F16/955G06F17/18H04L12/4633H04L12/4641H04L43/04H04L43/062H04L43/065H04L43/0817H04L43/0864H04L43/0876H04L45/02H04L45/125H04L45/28H04L45/302H04L45/306H04L45/38H04L47/125H04L47/22H04L47/24H04L47/32H04L47/781H04L47/825H04L63/061H04L67/141H04L67/52H04L67/63H04L69/40H04L41/122H04L41/34H04L41/40H04L43/0811H04L43/10H04L45/22H04L61/2503H04L61/4511H04L61/4523H04W84/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,443
App. No.
18/442,985
Granted
Feb 17, 2026
Kind
B2
Abstract

Various techniques for dynamic path selection and data flow forwarding are disclosed. For example, various systems, processes, and computer program products for dynamic path selection and data flow forwarding are disclosed for providing dynamic path selection and data flow forwarding that can facilitate preserving/enforcing symmetry in data flows as disclosed with respect to various embodiments.

Claims (41)

1 . A system, comprising:

a processor of a networked branch device configured to:

detect a data flow of a selected application from an associated originating interface on a network;

determine a first link over which to forward the data flow, wherein the first link includes a first device;

transmit the data flow over the determined first link;

receive a return data flow;

move a forward direction of the return data flow to a new path in the event that the return data flow arrived via a second link that is different from the first link, wherein the second link includes a second device and omits the first device, wherein all packets following an initial packet of the data flow are forwarded and returned on the same new path via the second link as the initial packet; and

store, in a flow table, the first link at a Layer 4 (L4) level; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the processor is further configured to apply time-based application domain classification.

3 . The system of claim 1 , wherein determining the first link and the second link comprises network mapping.

4 . The system of claim 1 , wherein the processor is further configured to model an application session.

5 . The system of claim 1 , wherein the processor is further configured to enforce a hold down period after the moving of the forward direction of the return data flow before another move of the return data flow.

6 . The system of claim 1 , wherein the processor is further configured to move the data flow of the selected application in the event that the new path no longer meets a network requirement for the selected application.

7 . The system of claim 1 , wherein the processor is further configured to:

move the data flow of the selected application in the event that the new path no longer meets a network requirement for the selected application; and

employ a hold down period after moving the data flow of the selected application before another move of the data flow.

8 . The system of claim 1 , wherein a network requirement for the selected application is based on at least one of a bandwidth availability, a latency metric, or a quality of service profile.

9 . A method, comprising:

detecting, by a networked branch device, a data flow of a selected application from an associated originating interface on a network;

determining, by a networked branch device, a first link over which to forward the data flow, wherein the first link includes a first device;

transmitting, by a networked branch device, the data flow over the determined first link;

receiving, by a networked branch device, a return data flow;

moving, by a networked branch device, a forward direction of the return data flow to a new path in the event that the return data flow arrived via a second link that is different from the first link, wherein the second link includes a second device and omits the first device, wherein all packets following an initial packet of the data flow are forwarded and returned on the same new path via the second link as the initial packet; and

storing, in a flow table, the first link at a Layer 4 (L4) level.

10 . The method of claim 9 , wherein determining the first link comprises applying time-based application domain classification.

11 . The method of claim 9 , wherein determining the first link and the second link comprises network mapping.

12 . The method of claim 9 , further comprising modeling an application session.

13 . The method of claim 9 , further comprising enforcing a hold down period after the moving of the forward direction of the return data flow before another moving of the return data flow.

14 . The method of claim 9 , further comprising moving the data flow of the selected application in the event that the new path no longer meets a network requirement for the selected application.

15 . The method of claim 9 , further comprising:

moving the data flow of the selected application in the event that the new path no longer meets a network requirement for the selected application; and

employing a hold down period after moving the data flow of the selected application before another move of the data flow.

16 . The method of claim 9 , wherein a network requirement for the selected application is based on at least one of a bandwidth availability, a latency metric, or a quality of service profile.

17 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

detecting, by a networked branch device, a data flow of a selected application from an associated originating interface on a network;

determining, by a networked branch device, a first link over which to forward the data flow, wherein the first link includes a first device;

transmitting, by a networked branch device, the data flow over the determined first link;

receiving, by a networked branch device, a return data flow;

moving, by a networked branch device, a forward direction of the return data flow to a new path in the event that the return data flow arrived via a second link that is different from the first link, wherein the second link includes a second device and omits the first device, wherein all packets following an initial packet of the data flow are forwarded and returned on the same new path via the second link as the initial packet; and

storing, in a flow table, the first link at a Layer 4 (L4) level.

Continuity (4)
Continuation 17343893 · Jun 10, 2021
Continuation 14856314 · Sep 16, 2015
Provisional Application 62051293 · Sep 16, 2014
Related Publication 20240297818A1 · Sep 5, 2024
References Cited (174)
US 5581702A · McArdle · 1996 [cited by applicant]
US 6173399B1 · Gilbrech · 2001 [cited by applicant]
US 6982969B1 · Carneal · 2006 [cited by applicant]
US 7139928B1 · Bhattacharya · 2006 [cited by applicant]
US 7233569B1 · Swallow · 2007 [cited by applicant]
US 7441267B1 · Elliott · 2008 [cited by applicant]
US 7729353B1 · Podolsky · 2010 [cited by applicant]
US 7861247B1 · Santos · 2010 [cited by applicant]
US 8024478B2 · Patel · 2011 [cited by applicant]
US 8331360B1 · Ashwood-Smith · 2012 [cited by applicant]
US 8385351B1 · Chen · 2013 [cited by applicant]
US 8392575B1 · Marr · 2013 [cited by applicant]
US 8793361B1 · Riddle · 2014 [cited by examiner]
US 9141769B1 · Hitchcock · 2015 [cited by applicant]
US 9686127B2 · Ramachandran · 2017 [cited by applicant]
US 9742626B2 · Ramachandran · 2017 [cited by applicant]
US 9860181B2 · Duffield · 2018 [cited by applicant]
US 9871691B2 · Anand · 2018 [cited by applicant]
US 9906402B2 · Ramachandran · 2018 [cited by applicant]
US 9923808B2 · Kelley, Jr. · 2018 [cited by applicant]
US 9960958B2 · Ramachandran · 2018 [cited by applicant]
US 10097403B2 · Anand · 2018 [cited by applicant]
US 10097404B2 · Yadav · 2018 [cited by applicant]
US 10110422B2 · Yadav · 2018 [cited by applicant]
US 10142164B2 · Ramachandran · 2018 [cited by applicant]
US 10153940B2 · Anand · 2018 [cited by applicant]
US 10374871B2 · Ramachandran · 2019 [cited by applicant]
US 10560314B2 · Ramachandran · 2020 [cited by applicant]
US 20010026550A1 · Kobayashi · 2001 [cited by applicant]
US 20020099756A1 · Catthoor · 2002 [cited by applicant]
US 20020156918A1 · Valdevit · 2002 [cited by applicant]
US 20030005112A1 · Krautkremer · 2003 [cited by applicant]
US 20030035385A1 · Walsh · 2003 [cited by applicant]
US 20030151619A1 · McBride · 2003 [cited by applicant]
US 20030158930A1 · Mc Bride · 2003 [cited by applicant]
US 20040044761A1 · Phillipi · 2004 [cited by applicant]
US 20040111643A1 · Farmer · 2004 [cited by applicant]
US 20040136324A1 · Steinberg · 2004 [cited by applicant]
US 20040223497A1 · Sanderson · 2004 [cited by applicant]
US 20050044443A1 · Magnaghi · 2005 [cited by applicant]
US 20050195741A1 · Doshi · 2005 [cited by applicant]
US 20050216418A1 · Davis · 2005 [cited by applicant]
US 20050265356A1 · Kawarai · 2005 [cited by applicant]
US 20060037072A1 · Rao · 2006 [cited by applicant]
US 20060149845A1 · Malin · 2006 [cited by applicant]
US 20060182033A1 · Chen · 2006 [cited by applicant]
US 20060182034A1 · Klinker · 2006 [cited by examiner]
US 20060182119A1 · Li · 2006 [cited by applicant]
US 20060224428A1 · Schmidt · 2006 [cited by applicant]
US 20060239188A1 · Weiss · 2006 [cited by applicant]
US 20070002804A1 · Xiong · 2007 [cited by applicant]
US 20070058638A1 · Guichard · 2007 [cited by applicant]
US 20070118631A1 · Devarakonda · 2007 [cited by applicant]
US 20070130324A1 · Wang · 2007 [cited by applicant]
US 20080031271A1 · Maeda · 2008 [cited by applicant]
US 20080080473A1 · Thubert · 2008 [cited by applicant]
US 20080082628A1 · Rowstron · 2008 [cited by applicant]
US 20080276317A1 · Chandola · 2008 [cited by applicant]
US 20080305743A1 · Aithal · 2008 [cited by applicant]
US 20090059814A1 · Nixon · 2009 [cited by applicant]
US 20090100431A1 · Doyle · 2009 [cited by applicant]
US 20090116402A1 · Yamasaki · 2009 [cited by applicant]
US 20090163279A1 · Hermansen · 2009 [cited by applicant]
US 20090182874A1 · Morford · 2009 [cited by applicant]
US 20090254589A1 · Nair · 2009 [cited by applicant]
US 20090285120A1 · Swan · 2009 [cited by applicant]
US 20100027427A1 · Kokje · 2010 [cited by applicant]
US 20100094981A1 · Cordray · 2010 [cited by applicant]
US 20100157841A1 · Puthenpura · 2010 [cited by applicant]
US 20100188976A1 · Rahman · 2010 [cited by applicant]
US 20100235880A1 · Chen · 2010 [cited by applicant]
US 20100299433A1 · De Boer · 2010 [cited by applicant]
US 20110019538A1 · Ryoo · 2011 [cited by applicant]
US 20110202641A1 · Kahn · 2011 [cited by applicant]
US 20110255537A1 · Ramasamy · 2011 [cited by applicant]
US 20110267949A1 · Ko · 2011 [cited by applicant]
US 20110296186A1 · Wong · 2011 [cited by applicant]
US 20110317695A1 · Cai · 2011 [cited by applicant]
US 20110320622A1 · Cutler · 2011 [cited by applicant]
US 20120106321A1 · Alon · 2012 [cited by applicant]
US 20120158539A1 · Lawrence · 2012 [cited by applicant]
US 20120182865A1 · Andersen · 2012 [cited by applicant]
US 20120278485A1 · Qian · 2012 [cited by applicant]
US 20120290869A1 · Heitz · 2012 [cited by applicant]
US 20120311138A1 · Inamdar · 2012 [cited by applicant]
US 20120317306A1 · Radinsky · 2012 [cited by applicant]
US 20130003528A1 · Wu · 2013 [cited by applicant]
US 20130003595A1 · Soomro · 2013 [cited by applicant]
US 20130019282A1 · Rice · 2013 [cited by applicant]
US 20130021139A1 · Guo · 2013 [cited by applicant]
US 20130024566A1 · Cremin · 2013 [cited by applicant]
US 20130046887A1 · Malloy · 2013 [cited by applicant]
US 20130074091A1 · Xavier · 2013 [cited by applicant]
US 20130077479A1 · Ryoo · 2013 [cited by applicant]
US 20130086280A1 · James · 2013 [cited by applicant]
US 20130124712A1 · Parker · 2013 [cited by applicant]
US 20130154822A1 · Kumar · 2013 [cited by applicant]
US 20130232261A1 · Wright · 2013 [cited by applicant]
US 20130298182A1 · May · 2013 [cited by applicant]
US 20130298201A1 · Aravindakshan · 2013 [cited by applicant]
US 20130301404A1 · Kano · 2013 [cited by applicant]
US 20130318538A1 · Verma · 2013 [cited by applicant]
US 20130322232A1 · Császár · 2013 [cited by applicant]
US 20140003434A1 · Assarpour · 2014 [cited by applicant]
US 20140010077A1 · Busch · 2014 [cited by applicant]
US 20140016501A1 · Kamath · 2014 [cited by applicant]
US 20140029438A1 · Jain · 2014 [cited by applicant]
US 20140033212A1 · Balasubramaniam · 2014 [cited by applicant]
US 20140040975A1 · Raleigh · 2014 [cited by applicant]
US 20140046882A1 · Wood · 2014 [cited by applicant]
US 20140052877A1 · Mao · 2014 [cited by applicant]
US 20140059095A1 · Adams · 2014 [cited by applicant]
US 20140059216A1 · Jerrim · 2014 [cited by applicant]
US 20140119177A1 · Delregno · 2014 [cited by applicant]
US 20140137182A1 · Elzur · 2014 [cited by applicant]
US 20140169215A1 · Rajendran · 2014 [cited by applicant]
US 20140173018A1 · Westphal · 2014 [cited by applicant]
US 20140222858A1 · Leonard · 2014 [cited by applicant]
US 20140241366A1 · Smith · 2014 [cited by applicant]
US 20140280761A1 · Rothschild · 2014 [cited by applicant]
US 20140303934A1 · Mylarappa · 2014 [cited by applicant]
US 20140310046A1 · Shidfar · 2014 [cited by applicant]
US 20140313881A1 · Limaye · 2014 [cited by applicant]
US 20140334406A1 · Chen · 2014 [cited by applicant]
US 20140337497A1 · Wanser · 2014 [cited by applicant]
US 20150016260A1 · Chow · 2015 [cited by applicant]
US 20150023663A1 · Gerstel · 2015 [cited by examiner]
US 20150036483A1 · Hassan · 2015 [cited by applicant]
US 20150071108A1 · Lumezanu · 2015 [cited by applicant]
US 20150085657A1 · Hoehne · 2015 [cited by applicant]
US 20150103672A1 · Stuart · 2015 [cited by applicant]
US 20150120909A1 · Karthikeyan · 2015 [cited by applicant]
US 20150172331A1 · Raman · 2015 [cited by applicant]
US 20150212909A1 · Sporel · 2015 [cited by applicant]
US 20150222612A1 · Norp · 2015 [cited by applicant]
US 20150365328A1 · Luke · 2015 [cited by examiner]
US 20160057014A1 · Thakkar · 2016 [cited by applicant]
US 20160080195A1 · Ramachandran · 2016 [cited by applicant]
US 20160080211A1 · Anand · 2016 [cited by applicant]
US 20160080212A1 · Ramachandran · 2016 [cited by applicant]
US 20160080221A1 · Ramachandran · 2016 [cited by applicant]
US 20160080225A1 · Yadav · 2016 [cited by applicant]
US 20160080230A1 · Anand · 2016 [cited by applicant]
US 20160080250A1 · Ramachandran · 2016 [cited by applicant]
US 20160080251A1 · Ramachandran · 2016 [cited by applicant]
US 20160080252A1 · Ramachandran · 2016 [cited by applicant]
US 20160080268A1 · Anand · 2016 [cited by applicant]
US 20160080280A1 · Ramachandran · 2016 [cited by applicant]
US 20160080285A1 · Ramachandran · 2016 [cited by applicant]
US 20160080502A1 · Yadav · 2016 [cited by examiner]
US 20160226723A1 · Delattre · 2016 [cited by applicant]
US 20210359936A9 · Dinan · 2021 [cited by applicant]
AU 2015317790 · 2019 [cited by applicant]
CN 101652968 · 2010 [cited by applicant]
CN 101690011 · 2012 [cited by applicant]
CN 101151847 · 2012 [cited by applicant]
CN 103188152 · 2015 [cited by applicant]
CN 103346922 · 2016 [cited by applicant]
CN 107078921 · 2017 [cited by applicant]
TW 201230729 · 2012 [cited by applicant]
TW 201618499 · 2016 [cited by applicant]
TW 1590617 · 2017 [cited by applicant]
WO 0209494 · 2002 [cited by applicant]
WO 03069848 · 2003 [cited by applicant]
WO 2012069486 · 2012 [cited by applicant]
WO 2014037277 · 2014 [cited by applicant]
WO 2016044413 · 2016 [cited by applicant]
“IBM Tivoli Netcool/System Service Monitors”, Reference Guide. IBM. 2013. (Year: 2013), 2013, p. 648. [cited by applicant]
“Query Session / Qwinsta”, Downloaded from <https://web.archive.org/web/20130117095013/https://ss64.com/nt/query-session.html>, Jan. 17, 2013, pp. 1-2. [cited by applicant]
106116652, “Application Serial No. 106116652 , Notice of Publication mailed Aug. 1, 2017”, CloudGenix, Inc., Aug. 1, 2017, 2 Pages. [cited by applicant]
201747001624, “Application Serial No. 201747001624, Notice of Publication mailed May 26, 2017”, CloudGenix, Inc., 1 Page. [cited by applicant]
PCT/US2015/050408, “International Application Serial No. PCT/US2015/050408 International Preliminary Report on Patentability and Written Opinion mailed Mar. 30, 2017”, CloudGenix, Inc., 9 Page. [cited by applicant]
PCT/US2015/050408, “International Application Serial No. PCT/US2015/050408 International Search Report and Written Opinion mailed Feb. 1, 2016”, CloudGenix, Inc., 12 pages. [cited by applicant]
Ramachandran, “Methods and Systems for Business Intent Driven Policy Based Network Traffic Characterization, Monitoring and Control”, Sep. 13, 2017, 1 Page. [cited by applicant]