Multi-layered application classification and decoding
US8112800B1 · kind B1 · utility
Assignee
Inventors
Key dates
| Filing date | Nov 8, 2007 |
| Grant date | Feb 7, 2012 |
| Priority date | — |
| Expiry date | May 18, 2030 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L69/22
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
An intrusion detection system is described that is capable of applying a plurality of stacked (layered) application-layer decoders to extract encapsulated application-layer data from a tunneled packet flow produced by multiple applications operating at the application layer, or layer seven (L7), of a network stack. In this was, the IDS is capable of performing application identification and decoding even when one or more software applications utilize other software applications as for data transport to produce packet flow from a network device. The protocol decoders may be dynamically swapped, reused and stacked (layered) when applied to a given packet or packet flow.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.