Patent · US9800608B2 · B2 · US
Processing data flows with a data flow processor
- (11) Publication number
- US9800608B2
- (21) Application number
- 12/982,999
- (22) Filing date
- 2010-12-31
- (30) Priority date
- 2000-09-25
- (43) Publication date
- 2017-10-24
- (45) Date of grant
- 2017-10-24
- (51) IPC
- G06F 15/167; G06F 15/16; G06F 21/55; H04L 29/06
- (52) CPC
- (73) Assignee
- Symantec Corp
- (72) Inventors
- Yevgeny Korsunsky; Moisey Akerman
- (54) Title
- Processing data flows with a data flow processor
- (57) Abstract
An apparatus and method to distribute applications and services in and throughout a network and to secure the network includes the functionality of a switch with the ability to apply applications and services to received data according to respective subscriber profiles. Front-end processors, or Network Processor Modules (NPMs), receive and recognize data flows from subscribers, extract profile information for the respective subscribers, utilize flow scheduling techniques to forward the data to applications processors, or Flow Processor Modules (FPMs). The FPMs utilize resident applications to process data received from the NPMs. A Control Processor Module (CPM) facilitates applications processing and maintains connections to the NPMs, FPMs, local and remote storage devices, and a Management Server (MS) module that can monitor the health and maintenance of the various modules.
- Full text
- View on Google Patents
Claims (10)
- A network apparatus for processing data flows, comprising: a chassis; one or more memories within the chassis; and one or more network processors within the chassis, the one or more network processors configured to execute instructions stored in the one or more memories to: receive and forward a stream of data packets in a network; recognize one or more data packets in the stream of data packets that contain data, including subscriber profile information, to be processed by an application executing on the network apparatus by applying a policy to the data; define an application suite by storing a plurality of applications in the one or more memories including at least two of: a virus detection application, an intrusion detection application, a firewall application, a content filtering application, a privacy protection application, and a policy-based browsing application; select an application of the plurality of applications stored in the one or more memories for processing the stream of data packets based on payloads of the data packets and on the subscriber profile information execute the selected application so as to process the stream of data packets by applying the policy to the payloads using machine learning logic to dynamically reconfigure a data flow, resulting in processed data, the machine learning logic configured to: compare a feature vector of the data flow with each of a plurality of artificial neurons that populate an array with each of the plurality of artificial neurons characterized by a weight vector; declare the weight vector positioned at the smallest Euclidean distance from the feature vector to be the winning neuron; map the feature vector to the winning neuron; repeat the comparing, declaring, and mapping with additional feature vectors to create an output map; determine whether the data flow is anomalous by determining whether the output map is atypical due to at least one value in the output map being larger or smaller than a threshold in relation to other values in the output map; and return the processed data for forwarding to a destination in the network.
- The network apparatus of claim 1, wherein the one or more network processors are further configured to execute instructions stored in the one or more memories to perform a step from the group consisting of, downloading applications to the one or more memories, and deleting applications from the one or more memories.
- The network apparatus of claim 1, wherein the one or more network processors are further configured to execute instructions stored in the one or more memories to identify a source of the stream of data packets, to detect a subscriber profile in the stream of data packets, and to identify the source of the stream based on the subscriber profile.
- A method of processing data flows, comprising: receiving a stream of data packets in a network within a chassis of a network apparatus, the network apparatus comprising at least one network processor and at least one memory; recognizing one or more data packets in the stream of data packets that contain data, including subscriber profile information, to be processed by an application executing on the network apparatus by applying a policy to the data; defining an application suite by storing a plurality of applications in the at least one memory, the plurality of applications including at least two of: a virus detection application, an intrusion detection application, a firewall application, a content filtering application, a privacy protection application, and a policy-based browsing application; selecting an application of the plurality of applications stored in the at least one memory for processing the stream of data packets based on payloads of the data packets and on the subscriber profile information; executing the selected application so as to process the data by applying the policy to the data using machine learning logic to dynamically reconfigure a data flow, resulting in processed data, the machine learning logic configured to: compare a feature vector of the data flow with each of a plurality of artificial neurons that populate an array with each of the plurality of artificial neurons characterized by a weight vector; declare the weight vector positioned at the smallest Euclidean distance from the feature vector to be the winning neuron; map the feature vector to the winning neuron; repeat the comparing, declaring, and mapping with additional feature vectors to create an output map; determine whether the data flow is anomalous by determining whether the output map is atypical due to at least one value in the output map being larger or smaller than a threshold in relation to other values in the output map; and returning the processed data for forwarding to a destination in the network.
- The method of claim 4, further comprising managing the plurality of applications for executing on the network apparatus.
- The method of claim 4, wherein the executing of the selected application further comprises selecting the application based on the subscriber profile information.
- The network apparatus of claim 1, wherein the selected application is the privacy protection application or the content filtering application.
- The network apparatus as in claim 7, wherein the payloads of the data packets comprise a social security number or a Health Insurance Portability and Accountability (HIP AA) record.
- The method as in claim 4, wherein the selected application is the privacy protection application or the content filtering application.
- The method as in claim 9, wherein the payloads of the data packets comprise a social security number or a Health Insurance Portability and Accountability (HIP AA) record.
Description
Field
This invention is in the field of computer security and protection. Specifically, it is in the field of protecting computer systems and databases from viruses, attacks from hackers and other unauthorized intrusions, spyware, spam, phishing and other scams, malicious activities and code.
Description of the Related Art
Methods providing security for computer systems have been developed, which address disparate threats to the systems, such threats including computer viruses, attacks by hackers, spyware, phishing, spam, intrusion onto a computer network by unauthorized users, and others. Products have been developed that separately address each of the most prevalent type of threats, and, more recently, those products have been joined together in suites of applications, where each application addresses a different kind of threat. The latter approach, known as unified threat management, offers more comprehensive protection against threats; however, the protection comes at the expense of processing resources, as each application in a unified threat management suite must use such resources.
Systems that provide only intrusion detection may have substantial drawbacks in this environment including false alarms, low manageability, high maintenance, and no prevention of attacks. False alarms may manifest as large quantities of records that require manual filtering, a costly and error prone process. An intrusion detection system that requires substantial time and effort to maintain detection sensors, security policies, and intrusion lists may contribute to poor intrusion detection.
Citations (115)
- US5276899A
- US5134691A
- EP0690376A2
- US6182123B1
- US5062037A
- US5446680A
- US5522070A
- US5790176A
- US6092218A
- US5621889A
- EP0648038A2
- US5557742A
- US5675797A
- US5867716A
- US5872779A
- US6064723A
- US5774668A
- US6442599B1
- US6317775B1
- US5771234A
- US5978843A
- US6279028B1
- US6119236A
- US6167428A
- US6347398B1
- US6393569B1
- US6067546A
- US6014700A
- US6816903B1
- US6185207B1
- US6006264A
- US5975945A
- US6058434A
- US6597684B1
- US6088804A
- US6226700B1
- US6279113B1
- US20010003831A1
- US6314463B1
- US6446109B2
- US7023825B1
- US6405246B1
- US6321338B1
- US6708212B2
- US6411986B1
- US20040215979A1
- US7013333B1
- US6370648B1
- US7934254B2
- US7069293B2
- US20030097398A1
- US6430570B1
- US6466965B1
- US6463474B1
- US6578066B1
- US6516337B1
- US6769066B1
- US7516227B2
- US7062556B1
- US6532446B1
- US6952728B1
- US6735206B1
- US6728808B1
- US6385205B1
- US7624172B1
- EP1187004A2
- US6519703B1
- US7574740B1
- US20030051195A1
- US6611526B1
- US20020032766A1
- US20110219035A1
- US8046465B2
- US20110213869A1
- US20110214157A1
- US20080262990A1
- US20080162390A1
- US20110231564A1
- US7836443B2
- US20110238855A1
- US8010469B2
- US20100042565A1
- US20020165947A1
- US20030051026A1
- US20040215957A1
- US6999952B1
- US20060272013A1
- US20020178268A1
- US7237264B1
- US7458094B2
- US7133365B2
- US7921204B2
- US7260846B2
- US20040025044A1
- US7913303B1
- US20040225895A1
- US20040236866A1
- US7464264B2
- US20050018618A1
- US20050086520A1
- EP1662700A1
- US20050076228A1
- WO2005060203A1
- US7664855B1
- US20060020595A1
- US20080134330A1
- US20070192863A1
- US20080133517A1
- US20080262991A1
- US20080229415A1
- US20080133518A1
- WO2007070838A2
- WO2007070838A3
- US7577623B2
- US8266694B1
Record as JSON
{
"publication_number": "US9800608B2",
"country": "US",
"kind": "B2",
"title": "Processing data flows with a data flow processor",
"abstract": "An apparatus and method to distribute applications and services in and throughout a network and to secure the network includes the functionality of a switch with the ability to apply applications and services to received data according to respective subscriber profiles. Front-end processors, or Network Processor Modules (NPMs), receive and recognize data flows from subscribers, extract profile information for the respective subscribers, utilize flow scheduling techniques to forward the data to applications processors, or Flow Processor Modules (FPMs). The FPMs utilize resident applications to process data received from the NPMs. A Control Processor Module (CPM) facilitates applications processing and maintains connections to the NPMs, FPMs, local and remote storage devices, and a Management Server (MS) module that can monitor the health and maintenance of the various modules.",
"claims": [
"1. A network apparatus for processing data flows, comprising: a chassis; one or more memories within the chassis; and one or more network processors within the chassis, the one or more network processors configured to execute instructions stored in the one or more memories to: receive and forward a stream of data packets in a network; recognize one or more data packets in the stream of data packets that contain data, including subscriber profile information, to be processed by an application executing on the network apparatus by applying a policy to the data; define an application suite by storing a plurality of applications in the one or more memories including at least two of: a virus detection application, an intrusion detection application, a firewall application, a content filtering application, a privacy protection application, and a policy-based browsing application; select an application of the plurality of applications stored in the one or more memories for processing the stream of data packets based on payloads of the data packets and on the subscriber profile information execute the selected application so as to process the stream of data packets by applying the policy to the payloads using machine learning logic to dynamically reconfigure a data flow, resulting in processed data, the machine learning logic configured to: compare a feature vector of the data flow with each of a plurality of artificial neurons that populate an array with each of the plurality of artificial neurons characterized by a weight vector; declare the weight vector positioned at the smallest Euclidean distance from the feature vector to be the winning neuron; map the feature vector to the winning neuron; repeat the comparing, declaring, and mapping with additional feature vectors to create an output map; determine whether the data flow is anomalous by determining whether the output map is atypical due to at least one value in the output map being larger or smaller than a threshold in relation to other values in the output map; and return the processed data for forwarding to a destination in the network.",
"2. The network apparatus of claim 1, wherein the one or more network processors are further configured to execute instructions stored in the one or more memories to perform a step from the group consisting of, downloading applications to the one or more memories, and deleting applications from the one or more memories.",
"3. The network apparatus of claim 1, wherein the one or more network processors are further configured to execute instructions stored in the one or more memories to identify a source of the stream of data packets, to detect a subscriber profile in the stream of data packets, and to identify the source of the stream based on the subscriber profile.",
"4. A method of processing data flows, comprising: receiving a stream of data packets in a network within a chassis of a network apparatus, the network apparatus comprising at least one network processor and at least one memory; recognizing one or more data packets in the stream of data packets that contain data, including subscriber profile information, to be processed by an application executing on the network apparatus by applying a policy to the data; defining an application suite by storing a plurality of applications in the at least one memory, the plurality of applications including at least two of: a virus detection application, an intrusion detection application, a firewall application, a content filtering application, a privacy protection application, and a policy-based browsing application; selecting an application of the plurality of applications stored in the at least one memory for processing the stream of data packets based on payloads of the data packets and on the subscriber profile information; executing the selected application so as to process the data by applying the policy to the data using machine learning logic to dynamically reconfigure a data flow, resulting in processed data, the machine learning logic configured to: compare a feature vector of the data flow with each of a plurality of artificial neurons that populate an array with each of the plurality of artificial neurons characterized by a weight vector; declare the weight vector positioned at the smallest Euclidean distance from the feature vector to be the winning neuron; map the feature vector to the winning neuron; repeat the comparing, declaring, and mapping with additional feature vectors to create an output map; determine whether the data flow is anomalous by determining whether the output map is atypical due to at least one value in the output map being larger or smaller than a threshold in relation to other values in the output map; and returning the processed data for forwarding to a destination in the network.",
"5. The method of claim 4, further comprising managing the plurality of applications for executing on the network apparatus.",
"6. The method of claim 4, wherein the executing of the selected application further comprises selecting the application based on the subscriber profile information.",
"7. The network apparatus of claim 1, wherein the selected application is the privacy protection application or the content filtering application.",
"8. The network apparatus as in claim 7, wherein the payloads of the data packets comprise a social security number or a Health Insurance Portability and Accountability (HIP AA) record.",
"9. The method as in claim 4, wherein the selected application is the privacy protection application or the content filtering application.",
"10. The method as in claim 9, wherein the payloads of the data packets comprise a social security number or a Health Insurance Portability and Accountability (HIP AA) record."
],
"description_excerpt": "Field\n\nThis invention is in the field of computer security and protection. Specifically, it is in the field of protecting computer systems and databases from viruses, attacks from hackers and other unauthorized intrusions, spyware, spam, phishing and other scams, malicious activities and code.\n\nDescription of the Related Art\n\nMethods providing security for computer systems have been developed, which address disparate threats to the systems, such threats including computer viruses, attacks by hackers, spyware, phishing, spam, intrusion onto a computer network by unauthorized users, and others. Products have been developed that separately address each of the most prevalent type of threats, and, more recently, those products have been joined together in suites of applications, where each application addresses a different kind of threat. The latter approach, known as unified threat management, offers more comprehensive protection against threats; however, the protection comes at the expense of processing resources, as each application in a unified threat management suite must use such resources.\n\nSystems that provide only intrusion detection may have substantial drawbacks in this environment including false alarms, low manageability, high maintenance, and no prevention of attacks. False alarms may manifest as large quantities of records that require manual filtering, a costly and error prone process. An intrusion detection system that requires substantial time and effort to maintain detection sensors, security policies, and intrusion lists may contribute to poor intrusion detection.",
"cpc": [
"H04L 63/1441",
"G06F 21/55",
"H04L 2463/141",
"H04L 63/1425",
"H04L 63/1483"
],
"ipc": [
"G06F 15/167",
"G06F 15/16",
"G06F 21/55",
"H04L 29/06"
],
"assignees": [
"Symantec Corp"
],
"inventors": [
"Yevgeny Korsunsky",
"Moisey Akerman"
],
"filing_date": "2010-12-31",
"publication_date": "2017-10-24",
"grant_date": "2017-10-24",
"priority_date": "2000-09-25",
"application_number": "US-98299910-A",
"family_id": "44648095",
"cited_by_count": 156,
"citations": [
"US5276899A",
"US5134691A",
"EP0690376A2",
"US6182123B1",
"US5062037A",
"US5446680A",
"US5522070A",
"US5790176A",
"US6092218A",
"US5621889A",
"EP0648038A2",
"US5557742A",
"US5675797A",
"US5867716A",
"US5872779A",
"US6064723A",
"US5774668A",
"US6442599B1",
"US6317775B1",
"US5771234A",
"US5978843A",
"US6279028B1",
"US6119236A",
"US6167428A",
"US6347398B1",
"US6393569B1",
"US6067546A",
"US6014700A",
"US6816903B1",
"US6185207B1",
"US6006264A",
"US5975945A",
"US6058434A",
"US6597684B1",
"US6088804A",
"US6226700B1",
"US6279113B1",
"US20010003831A1",
"US6314463B1",
"US6446109B2",
"US7023825B1",
"US6405246B1",
"US6321338B1",
"US6708212B2",
"US6411986B1",
"US20040215979A1",
"US7013333B1",
"US6370648B1",
"US7934254B2",
"US7069293B2",
"US20030097398A1",
"US6430570B1",
"US6466965B1",
"US6463474B1",
"US6578066B1",
"US6516337B1",
"US6769066B1",
"US7516227B2",
"US7062556B1",
"US6532446B1",
"US6952728B1",
"US6735206B1",
"US6728808B1",
"US6385205B1",
"US7624172B1",
"EP1187004A2",
"US6519703B1",
"US7574740B1",
"US20030051195A1",
"US6611526B1",
"US20020032766A1",
"US20110219035A1",
"US8046465B2",
"US20110213869A1",
"US20110214157A1",
"US20080262990A1",
"US20080162390A1",
"US20110231564A1",
"US7836443B2",
"US20110238855A1",
"US8010469B2",
"US20100042565A1",
"US20020165947A1",
"US20030051026A1",
"US20040215957A1",
"US6999952B1",
"US20060272013A1",
"US20020178268A1",
"US7237264B1",
"US7458094B2",
"US7133365B2",
"US7921204B2",
"US7260846B2",
"US20040025044A1",
"US7913303B1",
"US20040225895A1",
"US20040236866A1",
"US7464264B2",
"US20050018618A1",
"US20050086520A1",
"EP1662700A1",
"US20050076228A1",
"WO2005060203A1",
"US7664855B1",
"US20060020595A1",
"US20080134330A1",
"US20070192863A1",
"US20080133517A1",
"US20080262991A1",
"US20080229415A1",
"US20080133518A1",
"WO2007070838A2",
"WO2007070838A3",
"US7577623B2",
"US8266694B1"
]
}
Record 3,787 of 8,000 in Patents full text (MLC-0201). Request the full dataset.