IP Library › Granted Patent US 12,199,949
Granted Patent B2
US 12,199,949 · App. 18/478,478 · Granted Jan 14, 2025

Packet classification for network routing

Inventors: Nir Zuk (Menlo Park, CA); Marc Joseph Benoit (Santa Clara, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0227H04L45/38H04L45/64H04L47/2441H04L67/63H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,949
App. No.
18/478,478
Granted
Jan 14, 2025
Kind
B2
Abstract

Techniques for packet classification for network routing are disclosed. In some embodiments, packet classification for network routing includes receiving packets associated with a new flow at a security controller from a network device, in which the network device performs packet forwarding; classifying the flow; and determining an action for the flow based on a policy (e.g., a security policy). In some embodiments, the network device is a Software Defined Network (SDN) network device (e.g., a packet forwarding device that supports the OpenFlow protocol or another protocol).

Claims (56)

1. A system for a security controller that performs packet classification for network routing, comprising:

a processor of the security controller configured to:

receive packets associated with a new flow from a network device, wherein the network device performs packet forwarding;

classify the flow;

determine an action for the flow based on a policy;

instruct the network device via an interface to perform the action for the flow;

receive new packets associated with a shunted flow at the security controller from the network device, wherein the shunted flow is a flow that is to be ignored or dropped based on further inspection;

further classify the shunted flow, comprising to:

determine a type of traffic related to the shunted flow, the type of traffic including HTTP traffic, HTTPS traffic, FTP traffic, SSL traffic, SSH traffic, DNS requests, unclassified application traffic, or any combination thereof;

extract username, password, or a combination thereof being submitted to an external site from the new packets to determine a user; and

perform application signature matching based on the type of traffic to determine an application to be associated with the shunted flow; and

determine another action for the shunted flow based on a packet classification of a packet associated with the shunted flow, the user, and another policy; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the security controller is implemented using a cloud security service.

3. The system recited in claim 1 , wherein the network device is a Software Defined Network (SDN) network device.

4. The system recited in claim 1 , wherein the policy is a security policy.

5. The system recited in claim 1 , wherein the instructing of the network device to perform the action for the flow comprises to:

instruct the network device to perform the action for the flow using an application programming interface (API) mechanism.

6. The system recited in claim 1 , wherein the instructing of the network device to perform the action for the flow comprises to:

instruct the network device to perform the action for the flow by tagging a packet associated with the flow.

7. The system recited in claim 1 , wherein the action is to drop the flow.

8. The system recited in claim 1 , wherein the action is to ignore the flow.

9. The system recited in claim 1 , wherein the action is to shunt the flow.

10. A method of a security controller that performs packet classification for network routing, comprising:

receiving packets associated with a new flow from a network device at the security controller, wherein the network device performs packet forwarding;

classifying the flow;

determining an action for the flow based on a policy;

instructing the network device via an interface to perform the action for the flow;

receiving new packets associated with a shunted flow at the security controller from the network device, wherein the shunted flow is a flow that is to be ignored or dropped based on further inspection;

further classifying the shunted flow, comprising:

determining a type of traffic related to the shunted flow, the type of traffic including HTTP traffic, HTTPS traffic, FTP traffic, SSL traffic, SSH traffic, DNS requests, unclassified application traffic, or any combination thereof;

extracting username, password, or a combination thereof being submitted to an external site from the new packets to determine a user; and

performing application signature matching based on the type of traffic to determine an application to be associated with the shunted flow; and

determining another action for the shunted flow based on a packet classification of a packet associated with the shunted flow, the user and another policy.

11. The method of claim 10 , wherein the security controller is implemented using a cloud security service.

12. The method of claim 10 , wherein the network device is a Software Defined Network (SDN) network device.

13. The method of claim 10 , wherein the instructing of the network device to perform the action for the flow comprises:

instructing the network device to perform the action for the flow using an application programming interface (API) mechanism.

14. The method of claim 10 , wherein the instructing of the network device to perform the action for the flow comprises:

instructing the network device to perform the action for the flow by tagging a packet associated with the flow.

15. The method recited in claim 10 , wherein the action is to drop the flow.

16. The method recited in claim 10 , wherein the action is to ignore the flow.

17. The method recited in claim 10 , wherein the action is to shunt the flow.

18. A computer program product for a security controller that performs packet classification for network routing, the computer program product being embodied in a tangible, non-transitory computer readable storage medium and comprising computer instructions for:

receiving packets associated with a new flow from a network device at the security controller, wherein the network device performs packet forwarding;

classifying the flow;

determining an action for the flow based on a policy;

instructing the network device via an interface to perform the action for the flow;

receiving new packets associated with a shunted flow at the security controller from the network device, wherein the shunted flow is a flow that is to be ignored or dropped based on further inspection;

further classifying the shunted flow, comprising:

determining a type of traffic related to the shunted flow, the type of traffic including HTTP traffic, HTTPS traffic, FTP traffic, SSL traffic, SSH traffic, DNS requests, unclassified application traffic, or any combination thereof;

extracting username, password, or a combination thereof being submitted to an external site from the new packets to determine a user; and

performing application signature matching based on the type of traffic to determine an application to be associated with the shunted flow; and

determining another action for the shunted flow based on a packet classification of a packet associated with the shunted flow, the user and another policy.

19. The computer program product recited in claim 18 , wherein the security controller is implemented using a cloud security service.

20. The computer program product recited in claim 18 , wherein the network device is a Software Defined Network (SDN) network device.

Continuity (6)
Continuation 17839614 · Jun 14, 2022
Continuation 16927761 · Jul 13, 2020
Continuation 15250156 · Aug 29, 2016
Continuation 13954668 · Jul 30, 2013
Provisional Application 61847982 · Jul 18, 2013
Related Publication 20240031332A1 · Jan 25, 2024
References Cited (54)
US 6678827B1 · Rothermel · 2004 [cited by examiner]
US 7464407B2 · Nakae · 2008 [cited by applicant]
US 8619799B1 · Thodupunoori · 2013 [cited by examiner]
US 8762501B2 · Kempf · 2014 [cited by applicant]
US 8769664B1 · Zuk · 2014 [cited by applicant]
US 8867361B2 · Kempf · 2014 [cited by applicant]
US 9461968B2 · Chang · 2016 [cited by applicant]
US 10608899B2 · Chennimalai Sankaran · 2020 [cited by applicant]
US 20020083175A1 · Afek · 2002 [cited by examiner]
US 20030097557A1 · Tarquini · 2003 [cited by applicant]
US 20040030927A1 · Zuk · 2004 [cited by applicant]
US 20050129019A1 · Cheriton · 2005 [cited by applicant]
US 20060005231A1 · Zuk · 2006 [cited by applicant]
US 20060146816A1 · Jain · 2006 [cited by applicant]
US 20070006293A1 · Balakrishnan · 2007 [cited by examiner]
US 20070192863A1 · Kapoor · 2007 [cited by applicant]
US 20070297333A1 · Zuk · 2007 [cited by applicant]
US 20080253366A1 · Zuk · 2008 [cited by applicant]
US 20090328219A1 · Narayanaswamy · 2009 [cited by applicant]
US 20100232370A1 · Jing · 2010 [cited by applicant]
US 20110149734A1 · Park · 2011 [cited by applicant]
US 20110314145A1 · Raleigh · 2011 [cited by applicant]
US 20120026881A1 · Zuk · 2012 [cited by applicant]
US 20120084426A1 · Zuk · 2012 [cited by applicant]
US 20120093161A1 · Yeap · 2012 [cited by applicant]
US 20120120964A1 · Koponen · 2012 [cited by applicant]
US 20120304244A1 · Xie · 2012 [cited by examiner]
US 20120304277A1 · Li · 2012 [cited by applicant]
US 20120327767A1 · Ramakrishnan · 2012 [cited by examiner]
US 20130054761A1 · Kempf · 2013 [cited by examiner]
US 20130232251A1 · Pauley · 2013 [cited by applicant]
US 20140033275A1 · Kawamoto · 2014 [cited by applicant]
US 20140098674A1 · Sonoda · 2014 [cited by applicant]
US 20140140213A1 · Iny et al. · 2014 [cited by applicant]
US 20140241247A1 · Kempf · 2014 [cited by applicant]
US 20140289840A1 · Jain · 2014 [cited by applicant]
US 20140331311A1 · Zuk · 2014 [cited by applicant]
US 20140337509A1 · Manghirmalani · 2014 [cited by applicant]
CA 2620349 · 2017 [cited by applicant]
CN 101977146 · 2013 [cited by applicant]
CN 102394885 · 2015 [cited by applicant]
JP 2008011537 · 2008 [cited by applicant]
JP 201398597 · 2013 [cited by applicant]
JP 2013098597 · 2013 [cited by applicant]
WO 2012141086 · 2012 [cited by applicant]
WO 2012169164 · 2012 [cited by applicant]
Author Unknown, Open Networking Foundation, OpenFlow Switch Specification, Version 1.3.0 (Wire Protocol 0x04), Jun. 25, 2012. [cited by applicant]
Author Unknown, Open Networking Foundation, Software-Defined Networking: The New Norm for Networks, ONF White Paper, Apr. 13, 2012. [cited by applicant]
Benton et al., OpenFlow Vulnerability Assessment, 2013, ACM. [cited by applicant]
Casado et al., Ethane: Taking Control of the Enterprise, SIGCOMM Computer Communication Review, ACM, 2007, vol. 37, No. 4. [cited by applicant]
Dely et al., CloudMac, An OpenFlow based Architecture for 802.11 MAC Layering Processing in the Cloud, 2012, IEEE. [cited by applicant]
Jarschel et al., Modeling and Performance Evaluation of an OpenFlow Architecture, 2011, ITC. [cited by applicant]
Mckeown et al., OpenFlow: Enabling Innovation in Campus Networks, Mar. 14, 2008. [cited by applicant]
Peresini et al., Is your OpenFlow Application Correct?, 2011, ACM. [cited by applicant]