×

COOPERATED APPROACH TO NETWORK PACKET FILTERING

  • US 20140331221A1
  • Filed: 10/28/2010
  • Published: 11/06/2014
  • Est. Priority Date: 10/28/2010
  • Status: Active Grant
First Claim
Patent Images

1. A network interface apparatus in a computer system, comprising:

  • a first virtual function of a plurality of virtual functions, the first virtual function owned by a first virtual machine present in the computer system;

    a first simple filtering agent, associated with the first virtual function, to enforce one or more inbound simple filter rules at a first filtering level for a first network packet of a plurality of network packets received from a network, wherein at least one of the one or more inbound simple filter rules blocks the first network packet from reaching the first virtual machine in response to the first network packet failing at least one of the one or more inbound simple filter rules;

    a second virtual function of the plurality of virtual functions, the second virtual function owned by a virtual machine monitor present in the computer system; and

    a side bounce filtering agent to forward the first network packet to the second virtual function in response to first network packet being blocked by the at least one of the one or more inbound simple filter rules.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×