×

Security mediation for dynamically programmable network

  • US 10,333,988 B2
  • Filed: 06/13/2017
  • Issued: 06/25/2019
  • Est. Priority Date: 05/22/2012
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method, comprising:

  • receiving, by a computing system on a network, a candidate flow rule, wherein the candidate flow rule is received during a live operation of the network, wherein a flow rule can be implemented to reprogram a switch on the network;

    creating, according to a priority, an ordered set of currently active flow rules that control a flow of communications across the network during the live operation of the network;

    testing the candidate flow rule against one or more currently active flow rules of the ordered set, in a priority order;

    stopping the testing when a conflict between the candidate flow rule and a currently active flow rule of the ordered set is determined;

    in response to stopping the testing, replacing the currently active flow rule of the ordered set with the candidate flow rule when a priority associated with the candidate flow rule is greater than a priority associated with the currently active flow rule of the ordered set; and

    transmitting the candidate flow rule to the switch.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×