Patent · US Active

Applying fine-grain policy action to encapsulated network attacks

US9398043B1 · kind B1 · utility

17Cited by
37References
30Claims
0Family size

Assignee

Inventor

Key dates

Filing dateMar 24, 2009
Grant dateJul 19, 2016
Priority date
Expiry dateJan 23, 2035

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1441
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

An intrusion detection system inspects encapsulated packet flows and, upon detecting a malicious encapsulated packet flow, may close an encapsulated network session corresponding to the malicious flow or drop sub-packets of the malicious flow without acting against non-malicious sub-packets and/or sessions. In one example, a network device includes a flow analysis module that receives a packet flow packets, each packet comprising a packet header and one or more sub-packets each corresponding to respective network sessions, an attack detection module that identifies at least one of the network sessions as a malicious network session, a policy action module that executes a policy action on the sub-packet corresponding to the malicious network session based on the identification of the malicious network session, and a forwarding component that forms a reconstructed packet comprising the packet header and the sub-packets excluding the sub-packet corresponding to the malicious network session and forwards the reconstructed packet.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.