Session slicing of mirrored packets
US-12184680-B2 · Dec 31, 2024 · US
US9306959B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9306959-B2 |
| Application number | US-201113034736-A |
| Country | US |
| Kind code | B2 |
| Filing date | Feb 25, 2011 |
| Priority date | Feb 26, 2010 |
| Publication date | Apr 5, 2016 |
| Grant date | Apr 5, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A dual bypass module for managing an integrated secured network environment is provided. The module includes network ports that receive and transmit data traffic flowing through the network. The module also includes a set of monitoring ports that is configured for transmitting the data traffic between the dual bypass module and a set of monitoring systems. The module further includes a set of relays configured for controlling the flow of data through the dual bypass module. The module yet also includes a configurable integrated circuit. The configurable integrated circuit includes at least one of a first logic arrangement for determining conditions of the set of monitoring systems, a second logic arrangement for redirecting the data traffic through a secured alternate path when a monitoring system is unavailable, and a third logic arrangement for redirecting the data traffic through a secured alternate path when a communication path becomes unavailable.
Opening claim text (preview).
What is claimed is: 1. A dual bypass module comprising a device for managing data traffic transmitted in an integrated secured network environment, the device comprising: a set of network ports, said set of network ports including a set of input network ports for receiving data traffic from a network device and a set of output network ports for outputting said data traffic from said network device: a set of monitoring ports, said set of monitoring ports being configured for transmitting said data traffic between said dual bypass module and a set of monitoring systems; a set of relays configured for controlling the flow of data through said dual bypass module: and a configurable integrated circuit, said configurable integrated circuit including: a first logic arrangement for determining conditions of said set of monitoring systems, wherein said first logic arrangement includes a sequential heartbeat diagnostic test for: generating a plurality of sets of sequential heartbeat packets, each set being associated with a respective diagnostic test condition and a respective counter, and inserting said plurality of sets of sequential heartbeat packets into said data traffic flowing between a network tap and a first monitoring system, and receiving said data traffic from said first monitoring system and incrementing the counters for the diagnostic test conditions based on the presence or absence of the sets of sequential heartbeat packets; and a second logic arrangement for redirecting said data traffic through a secured alternate path in response to determining that a failure condition exists for the first monitoring system based on the counters for the diagnostic test conditions. 2. The dual bypass module of claim 1 further including an interface for interacting with said dual bypass module. 3. The dual bypass module of claim 2 wherein said interface being at least one of a command Line interface, a web based device, and a system interface. 4. The dual bypass module of claim 1 wherein said configurable integrated circuit is a field-programmable gate array. 5. The dual bypass module of claim 1 wherein said set of monitoring systems being at least one of an intrusion prevention system, an instruction detection system, and a firewall management system. 6. The dual bypass module of claim 1 wherein said set of relays is configured for creating a secured alternate path for routing said data traffic when power disruption occurs. 7. The dual bypass module of claim 1 wherein said second logic arrangement includes said logic component redirecting said data traffic from said first monitoring system to a second monitoring system when said fail condition exists. 8. A dual bypass module comprising a device for managing data traffic transmitted in an integrated secured network environment, the device comprising: a set of network ports, said set of network ports including a set of input network ports for receiving data traffic from a network device and a set of output network ports for outputting said data traffic from said network device; a set of monitoring ports, said set of monitoring ports being configured for transmitting said data traffic between said dual bypass module and a set of monitoring systems, wherein said data traffic is configured to traverse network ports irrespective of whether power is provided to circuitry of said dual bypass module; a first logic arrangement for identifying conditions of said set of monitoring systems, said first logic arrangement includes a sequential heartbeat diagnostic test for: generating a plurality of sets of sequential heartbeat packets, each set being associated with a respective diagnostic test condition and a respective counter, and inserting said plurality of sets of sequential heartbeat packets into said data traffic flowing between a network tap and a first monitoring system, and receiving said data traffic from said first monitoring system and incrementing the counters for the diagnostic test conditions based on the presence or absence of the sets of sequential heartbeat packets; a second logic arrangement for redirecting said data traffic through a secured alternate path in response to determining that a failure condition exists for the first monitoring system based on the counters for the diagnostic test conditions providing a high availability secure environment; and a third logic arrangement for establishing a redundant path arrangements. 9. The dual bypass module of claim 8 further including a set of relays configured for controlling the flow of data through said dual bypass module, wherein said set of relays is configured for creating a secured alternate path for routing said data traffic when power disruption occurs. 10. The dual bypass module of claim 8 further including an interface for interacting with said dual bypass module, wherein said interface being at least one of a command line interface, a web based device, and a system interface. 11. The dual bypass module of claim 8 wherein said first logic arrangement is a field-programmable gate array. 12. The dual bypass module of claim 8 wherein said second logic arrangement is a field-programmable gate array. 13. The dual bypass module of claim 8 wherein said third logic arrangement is a field-programmable gate array. 14. The dual bypass module of claim 8 wherein said set of monitoring systems being at least one of an intrusion prevention system, an instruction detection system, and a firewall management system. 15. The dual bypass module of claim 8 wherein said third logic arrangement includes redirecting said data traffic through a secured alternate path when a communication path becomes unavailable.
Network monitoring probes · CPC title
Event detection, e.g. attack signature detection · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Active monitoring, e.g. heartbeat, ping or trace-route · CPC title
by dynamic selection of recovery network elements, e.g. replacement by the most appropriate element after failure · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.