×

Dynamic policy provisioning within network security devices

  • US 8,856,926 B2
  • Filed: 05/20/2009
  • Issued: 10/07/2014
  • Est. Priority Date: 06/27/2008
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method comprising:

  • receiving, with a network security device of a network, network traffic;

    while processing the network traffic, monitoring, with the network security device, a level of utilization of one or more internal hardware resources of the network security device;

    when the level of utilization of the one or more internal hardware resources is less than a threshold, applying, with the network security device, a first policy to the network traffic to detect a first set of network attacks, wherein the first policy identifies a first set of attack patterns that correspond to the first set of network attacks;

    when the level of utilization of the one or more internal hardware resources equals or exceeds the threshold, applying, with the network security device, the second policy to at least a portion of the network traffic to detect a second set of network attacks, wherein the second policy identifies a second set of attack patterns that correspond to the second set of network attacks, and wherein the first set of attack patterns and the second set of attack patterns identify at least one different attack pattern; and

    forwarding, with the network security device, at least the portion of the network traffic based on the application of the first policy or the second policy.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×