×

Minimize SYN-flood issues with flow cache while maintaining performance

  • US 9,154,423 B1
  • Filed: 03/13/2013
  • Issued: 10/06/2015
  • Est. Priority Date: 05/01/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method for managing communication over a network with a traffic management device that includes a plurality of components and is operative to perform actions, comprising:

  • employing at least one data flow segment (DFS) component to determine if at least one received network packet is associated with a new connection flow, wherein each DFS component corresponds to a high speed flow cache;

    employing at least one control segment (CS) component to perform actions, including;

    determining if each connection flow is genuine that is evicted from at least one high-speed flow cache;

    if an amount of non-genuine connection flows exceeds a threshold, enabling at least one flood control filter; and

    if a new connection flow is determined to be genuine, generating flow control data that corresponds to the new connection flow; and

    employing the at least one DFS component to store the flow control data for each genuine connection flow in at least one high speed flow cache; and

    employing the at least one DFS component to forward received network packets for each genuine connection flow based on its corresponding flow control data stored in at least one high-speed flow cache.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×