×

Method and device for synchronizing network data flow detection status

  • US 9,729,560 B2
  • Filed: 09/10/2014
  • Issued: 08/08/2017
  • Est. Priority Date: 10/12/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method implemented by a status synchronizing server for synchronizing network data flow detection status, wherein the status synchronization server is communicatively coupled to at least two security device nodes, the method comprising:

  • receiving a first request sent by a first security device node, wherein the first request carries a first flow entry, wherein the first flow entry uniquely identifies a first data flow that is currently detected by the first security device node;

    determining first network data flow detection status corresponding to the first flow entry, wherein the first network data flow detection status comprises a first sequence of network events that have previously occurred in the first data flow and that are detected by another security device node, and wherein the other security device node is different than the first security device node; and

    sending a first response to the first security device node, wherein the first response carries the first network data flow detection status, wherein the first network data flow detection status carried in the first response is used by the first security device node to generate second network data flow detection status stored locally, wherein the second network data flow detection status comprises a second sequence of network events, wherein the second sequence of network events is generated by connecting the first sequence of network events with a third sequence of network events that occurred in the first data flow and detected by the first security device node, and wherein the second sequence of network events is used by the first security device to determine whether an attack occurs.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×