Systems and methods for processing data flows
First Claim
1. A method in a flow processing facility for securing a computer resource, comprising:
- providing a data flow processing facility comprising a plurality of network addressable data processing modules;
receiving a data flow;
identifying data packets associated with a subscriber profile in the data flow;
employing a policy to make a determination, the determination indicating a first plurality of network addresses of a portion of the plurality of network addressable data processing modules for processing the identified data packets based on at least one of the subscriber profile in the data flow and the policy;
accessing a configuration, the configuration associating one or more processing actions with the policy;
delivering the identified data packets in parallel to each of the first plurality of network addresses that the determination indicates; and
processing the identified data packets with the one or more processing actions in each of the network addressable data processing modules identified by the first plurality of network addresses to secure a computer resource.
12 Assignments
0 Petitions
Accused Products
Abstract
A flow processing facility, which uses a set of artificial neurons for pattern recognition, such as a self-organizing map, in order to provide security and protection to a computer or computer system supports unified threat management based at least in part on patterns relevant to a variety of types of threats that relate to computer systems, including computer networks. Flow processing for switching, security, and other network applications, including a facility that processes a data flow to address patterns relevant to a variety of conditions are directed at internal network security, virtualization, and web connection security. A flow processing facility for inspecting payloads of network traffic packets detects security threats and intrusions across accessible layers of the IP-stack by applying content matching and behavioral anomaly detection techniques based on regular expression matching and self-organizing maps. Exposing threats and intrusions within packet payload at or near real-time rates enhances network security from both external and internal sources while ensuring security policy is rigorously applied to data and system resources. Intrusion Detection and Protection (IDP) is provided by a flow processing facility that processes a data flow to address patterns relevant to a variety of types of network and data integrity threats that relate to computer systems, including computer networks.
67 Citations
18 Claims
-
1. A method in a flow processing facility for securing a computer resource, comprising:
-
providing a data flow processing facility comprising a plurality of network addressable data processing modules; receiving a data flow; identifying data packets associated with a subscriber profile in the data flow; employing a policy to make a determination, the determination indicating a first plurality of network addresses of a portion of the plurality of network addressable data processing modules for processing the identified data packets based on at least one of the subscriber profile in the data flow and the policy; accessing a configuration, the configuration associating one or more processing actions with the policy; delivering the identified data packets in parallel to each of the first plurality of network addresses that the determination indicates; and processing the identified data packets with the one or more processing actions in each of the network addressable data processing modules identified by the first plurality of network addresses to secure a computer resource. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A parallel data flow processing facility to secure a computer resource, comprising:
-
a plurality of network addressable data processing modules; a policy for applying to data packets; a network processor module for identifying data packets associated with a subscriber profile in a stream of data packets, determining a first plurality of network addresses of a portion of the plurality of network addressable data processing modules for processing the identified data packets based on at least one of the subscriber profile and the policy, and delivering the identified data packets in parallel to each of the first plurality of determined network addresses; and the network addressable data processing modules identified by the first plurality of network addresses for processing the delivered data packets to secure a computer resource. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18)
-
Specification