IP Library Granted Patent US 8,024,799
Granted Patent B2
US 8,024,799 · App. 11/483,265 · Granted Sep 20, 2011

Apparatus and method for facilitating network security with granular traffic modifications

Assignee: Cpacket Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,024,799
App. No.
11/483,265
Granted
Sep 20, 2011
Kind
B2
Abstract

An apparatus that facilitates network security for input network traffic includes microcode controlled state machines, each of which includes a computation kernel. Rules applied to a network traffic segment are distributed across the computation kernels. At least two of the computation kernels include condition logic configured by microcode stored in an associated control store to evaluate a unique configured rule in microcode to produce modification instructions. A distribution circuit routes the network traffic segment to each of the microcode controlled state machines. A circuit generates a modification command by combining the modification instructions from each of the at least two computation kernels, and performs a modification of the input network traffic based on the modification command to produce modified output network traffic that facilitates network security.

Claims (17)

1. An apparatus to facilitate network security for input network traffic, comprising:

a first plurality of microcode controlled state machines, each of said first plurality of microcode controlled state machines including a computation kernel, wherein a plurality of rules applied to a network traffic segment are distributed across said computation kernels such that each of at least two of said computation kernels includes condition logic configured by microcode stored in an associated control store to evaluate a unique configured rule in microcode to produce modification instructions;

a distribution circuit to route said network traffic segment to each of said first plurality of microcode controlled state machines; and

a first circuit that generates a modification command by combining said modification instructions from said at least two of said computation kernels, a second circuit that performs a modification of said input network traffic based on said modification command to produce modified output network traffic that facilitates network security;

wherein said distribution circuit provides said network traffic segment directly to said second circuit for modification, bypassing said first plurality of microcode controlled state machines, in response to said second circuit receiving said modification command from said first circuit.

2. The apparatus of claim 1 , wherein said second circuit includes an output circuit.

3. The apparatus of claim 2 , wherein said first circuit includes an aggregation circuit positioned between said first plurality of microcode controlled state machines and said output circuit.

4. The apparatus of claim 1 , wherein said modification instructions are based on individual network traffic segments corresponding to a packet.

5. The apparatus of claim 1 , wherein said modification includes at least one of filtering, dropping, duplication, and re-direction of said unit of said input network traffic.

6. The apparatus of claim 5 , wherein said modification includes at least one of encapsulation, marking, insertion of a field in the header, and removal of a field from the header of said unit of said input network traffic.

7. The apparatus of claim 6 positioned inside a firewall perimeter.

8. The apparatus of claim 1 , wherein:

said distribution circuit, said first plurality of microcode controlled state machines, and said circuit process traffic from a first path in a first direction, said apparatus further comprising a second plurality of microcode controlled state machines processing traffic from a second path in a second direction opposite to the first direction; and

said first plurality of microcode controlled state machines and said second plurality of microcode controlled state machines are configured to dynamically alternate between processing traffic from said first path and said second path.

9. The apparatus of claim 1 , wherein:

said condition logic of each of said at least two of said computation kernels includes a corresponding condition analysis circuit configured to compare a first value of an internal state variable stored by said condition logic and updated based on network traffic conditions to a second value stored by said condition logic to evaluate a behavioral rule associated with network traffic conditions to produce a computation kernel output; and

said modification instructions produced by said at least two of said computation kernels are based on said computation kernel output.

Assignments (10)
SECURITY INTEREST Recorded Jan 31, 2024
From: CPACKET NETWORKS INC.
To: TRINITY CAPITAL INC., AS COLLATERAL AGENT
Reel/Frame 066313/0479 →
RELEASE OF SECURITY INTEREST Recorded Jan 30, 2024
From: NH EXPANSION CREDIT FUND HOLDINGS LP
To: CPACKET NETWORKS INC.
Reel/Frame 066296/0675 →
SECURITY INTEREST Recorded Apr 17, 2020
From: CPACKET NETWORKS INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 052424/0412 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2019
From: PARTNERS FOR GROWTH V, L.P.
To: CPACKET NETWORKS INC.
Reel/Frame 050953/0721 →
SECURITY INTEREST Recorded Nov 5, 2019
From: CPACKET NETWORKS, INC.
To: NH EXPANSION CREDIT FUND HOLDINGS LP
Reel/Frame 050924/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 18, 2019
From: SILICON VALLEY BANK
To: CPACKET NETWORKS INC.
Reel/Frame 050764/0597 →
SECURITY INTEREST Recorded Oct 27, 2017
From: CPACKET NETWORKS INC.
To: PARTNERS FOR GROWTH V, L.P.
Reel/Frame 043975/0953 →
SECURITY INTEREST Recorded Aug 3, 2014
From: CPACKET NETWORKS INC.
To: SILICON VALLEY BANK
Reel/Frame 033463/0506 →
SECURITY AGREEMENT Recorded Jun 8, 2012
From: CPACKET NETWORKS INC.
To: SILICON VALLEY BANK
Reel/Frame 028343/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2006
From: KAY, RONY
To: CPACKET NETWORKS, INC.
Reel/Frame 018335/0694 →
Continuity (2)
Continuation In Part 11208022 · Aug 19, 2005
Related Publication 20070056030A1 · Mar 8, 2007