- 专利标题: Mechanisms for layer 7 context accumulation for enforcing layer 4, layer 7 and verb-based rules
-
申请号: US15868789申请日: 2018-01-11
-
公开(公告)号: US11431677B2公开(公告)日: 2022-08-30
- 发明人: Sushruth Gopal , Jayant Jain , Subrahmanyam Manuguri , Anirban Sengupta , Deepa Kalani , Alok Tiagi , Sushil Singh
- 申请人: NICIRA, INC.
- 申请人地址: US CA Palo Alto
- 专利权人: NICIRA, INC.
- 当前专利权人: NICIRA, INC.
- 当前专利权人地址: US CA Palo Alto
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; G06F9/455 ; H04L69/22 ; H04L69/329
摘要:
The method for implementing mechanisms for Layer 7 context accumulation for enforcing Layers 4, 7, and verb-based rules is presented. The method comprises: receiving stream data, and identifying a packet in the stream. If the packet includes Layer 7 headers: for each Layer 7 header: determining content of the packet identified by a Layer 7 header's identifier; and parsing the content to extract firewall input data. If one or more rules at least partially match the firewall input data, determining that a particular rule also includes additional information that cannot be found in the firewall input data; performing a DPI on the content to determine whether at least a portion of the additional information is found in the content; extracting additional input data from the content and adding it to the firewall input data; and applying the rules to the firewall input data to process the packet.
公开/授权文献
信息查询