-
公开(公告)号:US10728142B2
公开(公告)日:2020-07-28
申请号:US16204464
申请日:2018-11-29
Applicant: Cisco Technology, Inc.
Inventor: Craig Thomas Hill , James Guichard , Darrin Joseph Miller , Carlos M. Pignataro
IPC: H04L12/723 , H04L12/725 , H04L12/721 , H04L12/715 , H04L29/08 , H04L12/911 , H04L29/06
Abstract: In a first enclave of a label switching network (LSN), a protocol data unit (PDU) of the LSN is formatted to include a network service field specifying a service to be applied to the PDU. The service field can be positioned between PDU data link layer and network layer fields. The PDU specifies PDU routing/forwarding information for a path in the LSN ending in an LSN second enclave, and routing/forwarding for a destination between path segments in a non-LSN. The PDU is communicated from the first enclave, via the non-LSN, to the second enclave in accordance with the routing/forwarding information for the destination between path segments in the non-LSN. In the second enclave, each network service specified for the PDU is determined and then applied to the PDU. The second enclave transmits the network serviced PDU from the second enclave in accordance with the routing/forwarding information of the PDU in the label switching network.
-
公开(公告)号:US20240022945A1
公开(公告)日:2024-01-18
申请号:US18476737
申请日:2023-09-28
Applicant: Cisco Technology, Inc.
Inventor: Jerome Henry , Nancy Cam-Winget , Simone Arena , Darrin Joseph Miller , Sudhir Kumar Jain , Einar Nilsen-Nygaard
IPC: H04W28/02 , H04W8/24 , H04W28/086
CPC classification number: H04W28/0205 , H04W28/0215 , H04W8/245 , H04W28/086
Abstract: Embodiments identify a station that rotates an over the air station address. As address rotation was not originally designed into wireless networks, the rotation can introduce communication challenges for the station. The embodiments derive that traffic referencing two different over the air station addresses are associated with a single common station. This is accomplished by determining a similarity between properties of two sets of traffic. A first set of traffic references the first over the air station address and a second set of traffic references the second over the air station address. If the properties common across the two sets of traffic indicate sufficient similarity, the embodiments determine that both sets of traffic are associated with a single device. Network configuration of the device is then adjusted based on the determination.
-
公开(公告)号:US20230014351A1
公开(公告)日:2023-01-19
申请号:US17932092
申请日:2022-09-14
Applicant: Cisco Technology, Inc.
Inventor: Saravanan Radhakrishnan , Anand Oswal , Ashwin Kumar , Paul Wayne Bigbee , Darrin Joseph Miller
IPC: H04L9/40
Abstract: Systems and methods are provided for receiving, at a network device, a first set of rules from a security controller of an enterprise network, the first set of rules being different from a second set of rules provided to a firewall by the security controller, implementing, at the network device, the first set of rules received from the security controller, generating, at the network device, a first log including metadata based on the first set of rules, the first log being generated on a per flow basis, notifying, at the network device, a NetFlow of the first log including the metadata of the first set of rules, and providing, from the network device, the first log to a cloud-log store by the NetFlow of the network device, the cloud-log store receiving the first log from the network device and a second log from the firewall.
-
公开(公告)号:US20210075799A1
公开(公告)日:2021-03-11
申请号:US16562017
申请日:2019-09-05
Applicant: Cisco Technology, Inc.
Inventor: Gangadharan Byju Pularikkal , Santosh Ramrao Patil , Paul Wayne Bigbee , Darrin Joseph Miller , Madhusudan Nanjanagud
IPC: H04L29/06 , H04L12/721 , G06K9/62 , G06N20/00
Abstract: The present technology pertains to a system that routes application flows. The system can receive an application flow from a device by an active threat detection agent; analyze the application flow for user context, device context, and application context; classify the application flow based on the analysis of the application flow; and direct the application flow according to the classification of the application flow and an application access policy.
-
25.
公开(公告)号:US20200296033A1
公开(公告)日:2020-09-17
申请号:US16889589
申请日:2020-06-01
Applicant: Cisco Technology, Inc.
Inventor: Craig Thomas Hill , James Guichard , Darrin Joseph Miller , Carlos M. Pignataro
IPC: H04L12/723 , H04L12/725 , H04L12/721 , H04L12/715 , H04L29/08 , H04L12/911
Abstract: In a first enclave of a label switching network (LSN), a protocol data unit (PDU) of the LSN is formatted to include a network service field specifying a service to be applied to the PDU. The service field can be positioned between PDU data link layer and network layer fields. The PDU specifies PDU routing/forwarding information for a path in the LSN ending in an LSN second enclave, and routing/forwarding for a destination between path segments in a non-LSN. The PDU is communicated from the first enclave, via the non-LSN, to the second enclave in accordance with the routing/forwarding information for the destination between path segments in the non-LSN. In the second enclave, each network service specified for the PDU is determined and then applied to the PDU. The second enclave transmits the network serviced PDU from the second enclave in accordance with the routing/forwarding information of the PDU in the label switching network.
-
公开(公告)号:US10462007B2
公开(公告)日:2019-10-29
申请号:US15193482
申请日:2016-06-27
Applicant: Cisco Technology, Inc.
Inventor: Sanjay Kumar Hooda , Darrin Joseph Miller , Victor Moreno , Mark Montanez , Sridhar Subramanian
Abstract: Changes are made to a virtual network for an endpoint based on the authenticated user identity of the endpoint. The system includes a server and a controller associated with a network fabric to which the endpoint is connected. The network fabric includes network elements to carry network traffic for the endpoint. The server authenticates the endpoint associated with a network address and determines a user identity of the endpoint based on the authentication. The server determines a first virtual network associated with the user identity. The controller receives a notification from the server that the network traffic for the endpoint associated with the network address is to be routed over the first virtual network. The controller updates routing information to associate the network address with the first virtual network and sends the updated routing information to the network elements of the network fabric.
-
27.
公开(公告)号:US20190097924A1
公开(公告)日:2019-03-28
申请号:US16204464
申请日:2018-11-29
Applicant: Cisco Technology, Inc.
Inventor: Craig Thomas Hill , James Guichard , Darrin Joseph Miller , Carlos M. Pignataro
IPC: H04L12/723 , H04L12/911 , H04L29/08 , H04L12/725 , H04L12/721 , H04L12/715 , H04L29/06
Abstract: In a first enclave of a label switching network (LSN), a protocol data unit (PDU) of the LSN is formatted to include a network service field specifying a service to be applied to the PDU. The service field can be positioned between PDU data link layer and network layer fields. The PDU specifies PDU routing/forwarding information for a path in the LSN ending in an LSN second enclave, and routing/forwarding for a destination between path segments in a non-LSN. The PDU is communicated from the first enclave, via the non-LSN, to the second enclave in accordance with the routing/forwarding information for the destination between path segments in the non-LSN. In the second enclave, each network service specified for the PDU is determined and then applied to the PDU. The second enclave transmits the network serviced PDU from the second enclave in accordance with the routing/forwarding information of the PDU in the label switching network.
-
28.
公开(公告)号:US20180062984A1
公开(公告)日:2018-03-01
申请号:US15249260
申请日:2016-08-26
Applicant: Cisco Technology, Inc.
Inventor: Craig Thomas Hill , James Guichard , Darrin Joseph Miller , Carlos M. Pignataro
IPC: H04L12/723 , H04L12/911 , H04L29/08
CPC classification number: H04L45/50 , H04L45/306 , H04L45/34 , H04L45/38 , H04L45/566 , H04L45/64 , H04L47/825 , H04L67/327 , H04L69/22 , H04L69/321
Abstract: In a first enclave of a label switching network (LSN), a protocol data unit (PDU) of the LSN is formatted to include a network service field specifying a service to be applied to the PDU. The service field can be positioned between PDU data link layer and network layer fields. The PDU specifies PDU routing/forwarding information for a path in the LSN ending in an LSN second enclave, and routing/forwarding for a destination between path segments in a non-LSN. The PDU is communicated from the first enclave, via the non-LSN, to the second enclave in accordance with the routing/forwarding information for the destination between path segments in the non-LSN. In the second enclave, each network service specified for the PDU is determined and then applied to the PDU. The second enclave transmits the network serviced PDU from the second enclave in accordance with the routing/forwarding information of the PDU in the label switching network.
-
-
-
-
-
-
-