US2014366089A1PendingUtilityA1

Method, apparatus, signals, and medium for managing transfer of data in a data network

Assignee: FORTINET INCPriority: Sep 6, 2005Filed: Aug 26, 2014Published: Dec 11, 2014
Est. expirySep 6, 2025(expired)· nominal 20-yr term from priority
H04L 47/43H04L 41/0894H04L 67/563H04L 47/20H04L 63/20H04L 67/10H04L 63/1425H04L 12/66H04L 67/146H04L 63/0281H04L 63/1416
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and apparatus for managing a transfer of data in a data network identifies data associated with a communication session between a first node and a second node in the data network. Further processing of the communication session occurs when a portion of the communication session meets a criterion and the communication session is permitted to continue when the portion of the communication session does not meet the criterion.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A method for managing a transfer of data between a first node and a second node in a data network, the method comprising:
 identifying data associated with a communication session between the first node and the second node;   identifying, through execution of instructions on a processor, a signature associated with said data associated with said communication session;   further processing, through execution of instructions on the processor, said first communication session when a portion of said first communication session meets a criterion, the criterion including the identified signature associated with said first communication session, the further processing defined by a policy associated with the identified signature and including at least one action to be performed by the further processing, the at least one action including dividing the first communication session between the first node and the third node and a second communication session between the third node and the second node, the third node to act as a proxy node; and   permitting said communication session to continue when said portion of said communication session does not meet said criterion or upon completion of the further processing.   
     
     
         3 . The method of  claim 2 , wherein identifying said signature comprises identifying a pattern in said data associated with said communication session. 
     
     
         4 . The method of  claim 2 , wherein identifying said signature comprises performing signature analysis on said data associated with said communication session. 
     
     
         5 . The method of  claim 2 , wherein identifying said signature comprises determining whether said data associated with said communication session complies with a data transfer protocol. 
     
     
         6 . The method of  claim 2 , wherein identifying said signature comprises determining whether said data associated with said communication session is addressed to a particular destination. 
     
     
         7 . An apparatus for managing a transfer of data in a data network, the apparatus comprising:
 means for identifying data associated with a communication session between the first node and the second node;   means for identifying, through execution of instructions on a processor, a signature associated with said data associated with said communication session;   means for further processing, through execution of instructions on the processor, said first communication session when a portion of said first communication session meets a criterion, the criterion including the identified signature associated with said first communication session, the further processing defined by a policy associated with the identified signature and including at least one action to be performed by the further processing, the at least one action including dividing the first communication session between the first node and the third node and a second communication session between the third node and the second node, the third node to act as a proxy node; and   means for permitting said communication session to continue when said portion of said communication session does not meet said criterion or upon completion of the further processing.   
     
     
         8 . The apparatus of  claim 7 , wherein said means for identifying said signature comprises means for identifying a pattern in said data associated with said communication session. 
     
     
         9 . The apparatus of  claim 7 , wherein said means for identifying said signature comprises means for performing signature analysis on said data associated with said communication session. 
     
     
         10 . The apparatus of  claim 7 , wherein said means for identifying said signature comprises means for determining whether said data associated with said communication session complies with a specific data transfer protocol. 
     
     
         11 . The apparatus of  claim 7 , wherein said means for identifying said signature comprises means for determining whether said data associated with said communication session is addressed to a specific destination. 
     
     
         12 . An apparatus for managing a transfer of data in a data network, the apparatus comprising:
 a session identifier operably configured to identifying data associated with a first communication session between the first node and the second node communicatively connected to the data network;   a session controller having an input for receiving a control signal indicating whether said first communication session meets a criterion, said session controller responsive to said control signal to produce a signal to indicate whether or not said first communication session should be permitted to continue or should be subjected to further processing before being allowed to continue; and   a signature analyzer operably configured to produce said control signal in response to identifying a signature associated with said data associated with said first communication session, the signature associated with a policy defining at last one action to be performed with regard to data packets of said first communication session, the at least one action including dividing the first communication session between the first node and the third node and a second communication session between the third node and the second node, the third node to act as a proxy node.   
     
     
         13 . The apparatus of  claim 12 , further comprising:
 a signature analyzer operably configured to produce said control signal in response to identifying a signature associated with said data associated with said communication session.   
     
     
         14 . The apparatus of  claim 13 , wherein said signature comprises a pattern characteristic of a particular type of data transfer. 
     
     
         15 . The apparatus of  claim 13 , wherein said signature comprises a data protocol identifier. 
     
     
         16 . The apparatus of  claim 13 , wherein said signature comprises an address field. 
     
     
         17 . The apparatus of  claim 13 , wherein said signature analyzer comprises a hardware circuit comprising discrete logic components. 
     
     
         18 . The apparatus of  claim 13 , wherein said signature analyzer comprises an application specific integrated circuit (ASIC).

Join the waitlist — get patent alerts

Track US2014366089A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.