IP Library Granted Patent US 7,773,507
Granted Patent B1
US 7,773,507 · App. 11/479,177 · Granted Aug 10, 2010

Automatic tiered services based on network conditions

Assignee: Extreme Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,773,507
App. No.
11/479,177
Filed
Jun 30, 2006
Granted
Aug 10, 2010
Kind
B1
Art Unit
2473
USPC
370/230
Abstract

A traffic selector table for a network switch is populated with one or more entries that each identifies a tiered service. A traffic flow that matches an entry in the table is identified by the switch. The matched traffic flow is redirected to an intrusion prevention device to determine whether the traffic presents a threat to the network. The switch detects a condition in network traffic flowing through the switch. The traffic selector table is dynamically modified in response to the detected condition.

Claims (36)

1. In a network switch, a method comprising:

redirecting traffic received at the network switch to an external device to perform packet inspection based on a service type associated with the network traffic and based further on entries in a table stored on a memory of the network switch;

maintaining packet flow statistics for traffic flowing through the network switch;

dynamically modifying the table of entries based on the packet flow statistics;

monitoring the redirected traffic for congestion between the network switch and the external device to perform packet inspection; and

dynamically removing one or more entries from the table when a congestion condition is detected,

wherein dynamically modifying the table of entries based on the packet flow statistics comprises:

comparing the packet flow statistics against a policy threshold; and

dynamically modifying the table of entries when the policy threshold is exceeded.

2. The method of claim 1 , wherein the service type associated with the network traffic is selected from a group including an email service, a web service, a Structured Query Language (SQL) service and a File Transfer Protocol (FTP) service.

3. The method of claim 1 , wherein dynamically modifying the table of entries comprises at least one of adding and entry to the table and deleting an entry from the table.

4. The method of claim 1 , wherein dynamically modifying the table of entries comprises prioritizing entries in the table.

5. A network switch, comprising:

a traffic selector to redirect traffic received at the network switch to an external device to perform packet inspection based on a service type associated with the network traffic and based further on entries in a table stored on a memory of the network switch;

a traffic sensor to maintain packet flow statistics for traffic flowing through the network switch;

a selection manager coupled to the traffic selector and the traffic sensor to dynamically modify the table of entries based on the packet flow statistics;

a congestion sensor to monitor the redirected traffic for congestion between the network switch and the external device to perform packet inspection; and

the selection manager further to remove one or more entries from the table when a congestion condition is detected,

wherein the selection manager further comprises:

means for comparing the packet flow statistics against a policy threshold; and

means for dynamically modifying the table of entries when the policy threshold is exceeded.

6. The network switch of claim 5 , further comprising:

a flow handler to maintain a second table of entries corresponding to one or more tiered services that have been inspected by the external device;

the flow handler to forward packets that match an entry in the second table out of the switch.

7. The network switch of claim 5 , wherein the service type associated with the network traffic is selected from a group including an email service, a web service, a Structured Query Language (SQL) service and a File Transfer Protocol (FTP) service.

8. A machine-accessible non-transitory storage medium having instructions stored thereon that, when executed by a network switch, cause the network switch to perform a method comprising:

redirecting traffic received at the network switch to an external device to perform packet inspection based on a service type associated with the network traffic and based further on entries in a table stored on a memory of the network switch;

maintaining packet flow statistics for traffic flowing through the network switch;

dynamically modifying the table of entries based on the packet flow statistics;

monitoring the redirected traffic for congestion between the network switch and the external device to perform packet inspection; and

dynamically removing one or more entries from the table when a congestion condition is detected,

wherein dynamically modifying the table of entries comprises: comparing the packet flow statistics against a policy threshold; and

dynamically modifying the table of entries when the policy threshold is exceeded.

9. The machine-accessible non-transitory storage medium of claim 8 , wherein the service type associated with the network traffic is selected from a group including an email service, a web service, a Structured Query Language (SQL) service, and a File Transfer Protocol (FTP) service.

10. The machine-accessible non-transitory storage medium of claim 8 , wherein modifying of the table of entries comprises adding or deleting an entry from the table.

11. The machine-accessible non-transitory storage medium of claim 8 , wherein dynamically modifying the table of entries comprises prioritizing entries in the table.

Assignments (10)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
SECURITY AGREEMENT Recorded Jul 27, 2015
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 036189/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2007
From: KASRALIKAR, RAHUL; FOWLER, JEFFREY
To: EXTREME NETWORKS, INC.
Reel/Frame 018884/0154 →