-
公开(公告)号:US12192186B2
公开(公告)日:2025-01-07
申请号:US18389417
申请日:2023-11-14
Applicant: Cisco Technology, Inc.
Inventor: Kyle Andrew Donald Mestery , Vincent E. Parla
Abstract: Techniques for routing service mesh traffic based on whether the traffic is encrypted or unencrypted are described herein. The techniques may include receiving, from a first node of a cloud-based network, traffic that is to be sent to a second node of the cloud-based network and determining whether the traffic is encrypted or unencrypted. If it is determined that the traffic is encrypted, the traffic may be sent to the second node via a service mesh of the cloud-based platform. Alternatively, or additionally, if it is determined that the traffic is unencrypted, the traffic may be sent to the second node via an encrypted tunnel. In some examples, the techniques may be performed at least partially by a program running on the first node of the cloud-based network, such as an extended Berkeley Packet Filter (eBPF) program, and the like.
-
公开(公告)号:US12192179B2
公开(公告)日:2025-01-07
申请号:US17817479
申请日:2022-08-04
Applicant: Cisco Technology Inc.
Inventor: Balaji Sundararajan , Venkatesh Gota B R , Sireesha Yeruva , Chandramouli Balasubramanian , Anand Oswal
Abstract: The present disclosure is directed to systems and methods for dynamic firewall discovery on a service plane. The method includes the steps of identifying a source data packet for transmission from a source machine at a source site to a destination machine at a destination site, wherein the source data packet corresponds to a request for connection between the source machine and the destination machine over a WAN, inspecting the source data packet at a first firewall associated with the source site, marking the source data packet with a marker to indicate inspection by the first firewall, transmitting the marked source data packet to the destination site, determining at the destination site that the source data packet has been inspected based on the marker, and forwarding the source data packet to the destination machine at the destination site, without inspection of the source data packet by a second firewall associated with the destination site.
-
公开(公告)号:US12192104B2
公开(公告)日:2025-01-07
申请号:US18470153
申请日:2023-09-19
Applicant: Cisco Technology, Inc.
Inventor: Dennis Khoa Dang Nguyen , Keerthi Manjunathan Swarnamanjunathan , Laura J. Sharpless , Kelvin Chan , Ganga S. Devadas
IPC: H04L47/12 , H04L5/00 , H04L41/5009 , H04L43/062 , H04L47/11 , H04L49/25 , H04L49/50
Abstract: Techniques for identifying network congestion and adapting network performance to relieve the network congestion are described. As described, a network element such as a switch reports network congestion indicators such as link level control frames to a network controller. The network controller uses the network congestion indicators reported from the network elements to identify congestion points, data traffic, and data flows experiencing congestion at a network level. The network controller then determines optimized control parameters for the network in order to reduce or alleviate the congestion at the congestion points.
-
公开(公告)号:US12192053B2
公开(公告)日:2025-01-07
申请号:US18307777
申请日:2023-04-26
Applicant: Cisco Technology, Inc.
Inventor: Vishal S Desai , Young Il Choi , Abhishek Datta
IPC: H04L41/082 , H04L41/0823 , H04L41/149
Abstract: The disclosed technology relates to determining a period in which a non-urgent RRM update should be deferred. The method may comprise applying a first update to an existing configuration of the plurality of wireless access points in the network based on an analysis of telemetry received from the plurality of wireless access points received over a period spanning at least two busy periods. The method may further comprise applying a second update that modifies the first preferred network configuration based on an analysis of telemetry received during the first busy period. The method may further comprise applying a maintenance update to the tweaked network configuration based on telemetry received during the next busy period.
-
公开(公告)号:US12191915B1
公开(公告)日:2025-01-07
申请号:US17689634
申请日:2022-03-08
Applicant: Cisco Technology, Inc.
Inventor: Kadaba Lakshmikumar , Romesh Kumar Nandwana , Alexander C. Kurylak
Abstract: Techniques for implementing a differential differencing TIA for coherent applications are disclosed. A method includes receiving first and second optical signals from a 90 degree optical hybrid that receives a coherent optical signal, wherein the first and second optical signals each include one pair of sum and difference signals output by the 90 degree optical hybrid, generating, based on the first optical signal and from a first photo diode, a first differential signal, generating, based on the second optical signal and from a second photo diode, a second differential signal, differentially transconducting the first and second differential signals to produce first and second transconducted signals, performing a differencing operation on the first and second differential transconducted signals to produce a combined differential-differencing transconducted signal that is representative of the first optical signal and the second optical signal, and outputting the combined differential transconducted signal as a differential output.
-
公开(公告)号:US20250007951A1
公开(公告)日:2025-01-02
申请号:US18215644
申请日:2023-06-28
Applicant: Cisco Technology, Inc.
Inventor: Prab Radhakrishnan , Balaji Sundararajan , Ram Dular Singh , Vishnuprasad Raghavan
Abstract: Techniques for extending application-aware routing (AAR) policies to enable intelligent routing decisions based on device security posture. The techniques may include receiving, from a client device, traffic that is to be sent over a network to an application and determining a security score associated with the traffic. The security score may be based on a security posture associated with the client device, a security level associated with a connectivity network used by the client device, and the like. The techniques may also include determining, based at least in part on the security score and based at least in part on an application-aware routing policy, a path for sending the traffic to the application.
-
公开(公告)号:US20250007931A1
公开(公告)日:2025-01-02
申请号:US18342588
申请日:2023-06-27
Applicant: Cisco Technology, Inc.
Inventor: Manoj Kumar Shukla , Shankar Gopalkrishnan
IPC: H04L9/40
Abstract: Techniques are described for managing network traffic based on anomaly data. The anomaly data can be collected from network devices. A controller can identify, based on the anomaly data, identifiers, classifications, severities, and other characteristics, can be utilized to generate risk weights associated with the devices. The risk weights can be generated based on numbers of occurrences of the anomalies and the severities. Estimated risk scores associated with the devices can be generated based on the risk weights and anomaly frequencies associated with the classifications of the anomalies. The servers and the controllers can exchange communications with the devices to control the devices, and traffic associated therewith, based on the estimated risk scores.
-
公开(公告)号:US12184694B2
公开(公告)日:2024-12-31
申请号:US17531063
申请日:2021-11-19
Applicant: Cisco Technology, Inc.
Inventor: Blake Harrell Anderson , David McGrew , Keith Richard Schomburg , Michael Scott Dorsey , Constantinos Kleopa
IPC: G06F21/60 , H04L9/40 , H04L65/1066 , H04L69/14 , H04L69/08
Abstract: In one embodiment, a device obtains one or more packets of a traffic session in a network. The device determines, for a particular packet of the one or more packets that match a filter, a fingerprint for the particular packet. The device identifies a plurality of traffic sessions whose packets match the fingerprint, wherein each of the plurality of traffic sessions is associated with at least one process. The device updates a process with the traffic session by applying a classifier to the plurality of traffic sessions.
-
169.
公开(公告)号:US12184648B2
公开(公告)日:2024-12-31
申请号:US18167593
申请日:2023-02-10
Applicant: Cisco Technology, Inc.
Inventor: Srinath Gundavelli , Shree N. Murthy , Pradeep Kumar Kathail , Brian Weis
IPC: H04L9/40 , H04L47/2441 , H04L65/1073 , H04W80/02
Abstract: A method is provided to anonymize the media access control (MAC) address of a client device. The method involves generating a plurality of media access control (MAC) addresses for use by a client device in a network. Policies are defined that determine which one of the plurality of MAC addresses is to be used by the client device. The plurality of MAC addresses allocated for use by the client device are registered with a management entity in the network.
-
170.
公开(公告)号:US20240430012A1
公开(公告)日:2024-12-26
申请号:US18823664
申请日:2024-09-03
Applicant: Cisco Technology, Inc.
Inventor: Daniel KUCHARSKI , Sherif ABDALLA , Brian WELCH
IPC: H04B10/516 , G02B26/06 , G02B26/08 , G02F1/01 , G02F1/21 , G02F1/225 , H04B10/079 , H04B10/50 , H04B10/54
Abstract: Methods and systems for encoding multi-level pulse amplitude modulated signals using integrated optoelectronics are disclosed and may include generating a multi-level, amplitude-modulated optical signal utilizing an optical modulator driven by first and second electrical input signals, where the optical modulator may configure levels in the multi-level amplitude modulated optical signal, drivers are coupled to the optical modulator; and the first and second electrical input signals may be synchronized before being communicated to the drivers. The optical modulator may include optical modulator elements coupled in series and configured into groups. The number of optical modular elements and groups may configure the number of levels in the multi-level amplitude modulated optical signal. Unit drivers may be coupled to each of the groups. The electrical input signals may be synchronized before communicating them to the unit drivers utilizing flip-flops. Phase addition may be synchronized utilizing one or more electrical delay lines.
-
-
-
-
-
-
-
-
-