Early policy evaluation of multiphase attributes in high-performance firewalls
First Claim
Patent Images
1. A method comprising:
- establishing a policy at a proxy device, the policy comprising a multiphase condition having a multiphase attribute of a multiphase transaction, wherein the multiphase attribute comprises an attribute that becomes known at one or more of a plurality of phases of the multiphase transaction, and the multiphase condition comprises a condition that is met at one or more of the plurality of phases;
establishing phase specific policies for each phase of the plurality of phases in which the multiphase attribute becomes known;
evaluating the multiphase transaction at the proxy device according to the phase specific policies at each phase of the plurality of phases until a policy decision of the policy is determined;
wherein establishing phase specific policies comprises establishing phase specific conditions each evaluating a phase of the transaction in which the multiphase attribute becomes known, andwherein establishing the policy comprises establishing the policy including a condition having a single phase attribute, and wherein establishing the phase specific policies comprises including the single-phase condition in each phase specific policy and ordering the phase specific conditions, the multiphase condition, and the single-phase condition according to an order of the phases in which the single phase attribute and the multiphase attribute become known.
1 Assignment
0 Petitions
Accused Products
Abstract
A policy is established comprising a condition having a multiphase attribute of a multiphase transaction. Phase specific policies are established for each phase in which the multiphase attribute may become known. The multiphase transaction is evaluated according to the phase specific policies at each phase of the multiphase transaction in which the multiphase attribute may become known until a policy decision of the policy is determined.
-
Citations
14 Claims
-
1. A method comprising:
-
establishing a policy at a proxy device, the policy comprising a multiphase condition having a multiphase attribute of a multiphase transaction, wherein the multiphase attribute comprises an attribute that becomes known at one or more of a plurality of phases of the multiphase transaction, and the multiphase condition comprises a condition that is met at one or more of the plurality of phases; establishing phase specific policies for each phase of the plurality of phases in which the multiphase attribute becomes known; evaluating the multiphase transaction at the proxy device according to the phase specific policies at each phase of the plurality of phases until a policy decision of the policy is determined; wherein establishing phase specific policies comprises establishing phase specific conditions each evaluating a phase of the transaction in which the multiphase attribute becomes known, and wherein establishing the policy comprises establishing the policy including a condition having a single phase attribute, and wherein establishing the phase specific policies comprises including the single-phase condition in each phase specific policy and ordering the phase specific conditions, the multiphase condition, and the single-phase condition according to an order of the phases in which the single phase attribute and the multiphase attribute become known. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. An apparatus comprising:
-
a memory; a network interface; and a processor coupled to the memory and the network interface, wherein the processor is configured to; establish a policy, the policy comprising a multiphase condition having a multiphase attribute of a multiphase transaction, wherein the multiphase attribute comprises an attribute that becomes known at one or more of a plurality of phases of the multiphase transaction, and the multiphase condition comprises a condition that is met at one or more of the plurality of phases; establish phase specific policies for each phase of the plurality of phases in which the multiphase attribute becomes known; evaluate the multiphase transaction according to the phase specific policies at each phase of the plurality of phases until a policy decision of the policy is determined; and establish phase specific conditions each evaluating a phase of the transaction in which the multiphase attribute becomes known; wherein the processor is configured to establish the policy by establishing the policy including a condition having a single phase attribute, and wherein establishing the phase specific policies comprises including the single-phase condition in each phase specific policy and ordering the phase specific conditions, the multiphase condition, and the single-phase condition according to an order of the phases in which the single phase attribute and the multiphase attribute become known. - View Dependent Claims (9, 10, 11)
-
-
12. A non-transitory computer readable tangible storage media encoded with instructions that, when executed by a processor, cause the processor to:
-
establish a policy, the policy comprising a condition having a multiphase attribute of a multiphase transaction, wherein the multiphase attribute comprises an attribute that becomes known at one or more of a plurality of phases of the multiphase transaction, and the multiphase condition comprises a condition that is met at one or more of the plurality of phases; establish phase specific policies for each phase in which the multiphase attribute becomes known; evaluate the multiphase transaction according to the phase specific policies at each phase of the plurality of phases own until a policy decision of the policy is determined; and establish phase specific conditions each evaluating a phase of the transaction in which the multiphase attribute becomes known, wherein the instructions that cause the processor to establish the policy comprise instructions that cause the processor to establish the policy including a condition having a single phase attribute, and wherein establish the phase specific policies comprises including the single-phase condition in each phase specific policy and order the phase specific conditions, the multiphase condition, and the single-phase condition according to an order of the phases in which the single phase attribute and the multiphase attribute become known. - View Dependent Claims (13, 14)
-
Specification