Priority aware MAC flow control
    31.
    发明授权
    Priority aware MAC flow control 有权
    优先级感知MAC流量控制

    公开(公告)号:US08743691B2

    公开(公告)日:2014-06-03

    申请号:US13161439

    申请日:2011-06-15

    摘要: Solutions are provided that allow a network device to apply flow control on the MAC layer while taking into account the priority of the frame of traffic. This may be accomplished by generating a frame indicating that traffic flow should be paused, while utilizing a new opcode value, or alternatively by utilizing a new type/length value (possibly combined with a new opcode value). A receiving device may then examine the fields of the frame to determine whether it should use priority-based pausing, and then examine other fields to determine which priority-levels to pause and for how long. This allows for improved efficiency in flow control on the MAC layer.

    摘要翻译: 提供的解决方案允许网络设备在考虑到流量帧的优先级的情况下对MAC层应用流量控制。 这可以通过生成指示业务流应该被暂停,同时利用新的操作码值,或者通过利用新的类型/长度值(可能与新的操作码值组合)来实现。 然后,接收设备可以检查帧的字段以确定它是否应该使用基于优先级的暂停,然后检查其他字段以确定要暂停的优先级等级以及多长时间。 这样可以提高MAC层的流量控制效率。

    Virtual application delivery chassis system
    33.
    发明授权
    Virtual application delivery chassis system 有权
    虚拟应用交付机箱系统

    公开(公告)号:US08266235B2

    公开(公告)日:2012-09-11

    申请号:US13363055

    申请日:2012-01-31

    摘要: A method for electing a master blade in a virtual application distribution chassis (VADC), includes: sending by each blade a VADC message to each of the other blades; determining by each blade that the VADC message was not received from the master blade within a predetermined period of time; in response, sending a master claim message including a blade priority by each blade to the other blades; determining by each blade whether any of the blade priorities obtained from the received master claim messages is higher than the blade priority of the receiving blade; in response to determining that none of the blade priorities obtained is higher, setting a status of a given receiving blade to a new master blade; and sending by the given receiving blade a second VADC message to the other blades indicating the status of the new master blade of the given receiving blade.

    摘要翻译: 一种用于在虚拟应用分发机架(VADC)中选择主刀片的方法,包括:由每个刀片发送VADC消息给每个其他刀片; 在预定时间段内由每个刀片确定VADC消息未被从主刀片接收; 作为响应,将包括由每个刀片的刀片优先级的主要声明消息发送到其他刀片; 由每个刀片确定从所接收的主机声明消息获得的任何刀片优先级是否高于接收刀片的刀片优先级; 响应于确定没有获得的叶片优先级更高,将给定接收叶片的状态设置为新的主叶片; 并且由给定接收刀片发送第二VADC消息给另一个刀片,指示给定接收刀片的新主刀片的状态。

    Priority aware MAC flow control
    34.
    发明授权
    Priority aware MAC flow control 有权
    优先级感知MAC流量控制

    公开(公告)号:US07990857B2

    公开(公告)日:2011-08-02

    申请号:US12615142

    申请日:2009-11-09

    IPC分类号: H04L12/28 H04L12/56 G06F15/16

    摘要: Solutions are provided that allow a network device to apply flow control on the MAC layer while taking into account the priority of the frame of traffic. This may be accomplished by generating a frame indicating that traffic flow should be paused, while utilizing a new opcode value, or alternatively by utilizing a new type/length value (possibly combined with a new opcode value). A receiving device may then examine the fields of the frame to determine whether it should use priority-based pausing, and then examine other fields to determine which priority-levels to pause and for how long. This allows for improved efficiency in flow control on the MAC layer.

    摘要翻译: 提供的解决方案允许网络设备在考虑到流量帧的优先级的情况下对MAC层应用流量控制。 这可以通过生成指示业务流应该被暂停,同时利用新的操作码值,或者通过利用新的类型/长度值(可能与新的操作码值组合)来实现。 然后,接收设备可以检查帧的字段以确定它是否应该使用基于优先级的暂停,然后检查其他字段以确定要暂停的优先级等级以及多长时间。 这样可以提高MAC层的流量控制效率。

    SECURING AN ACCESSIBLE COMPUTER SYSTEM
    35.
    发明申请
    SECURING AN ACCESSIBLE COMPUTER SYSTEM 有权
    保护可访问的计算机系统

    公开(公告)号:US20100235506A1

    公开(公告)日:2010-09-16

    申请号:US12727499

    申请日:2010-03-19

    IPC分类号: G06F15/16

    摘要: To secure an accessible computer system, the computer system is monitored for connection transactions. An access requestor is denied access to the computer system when the access requestor initiates a number of connection transactions that exceed a configurable threshold number during a first configurable period of time. The monitoring may include detecting connection transactions initiated by the access requestor, counting the number of connection transactions initiated by the access requestor during the first configurable period of time, and comparing the number of connection transactions initiated by the access requestor during the first configurable period of time to the configurable threshold number.

    摘要翻译: 为了确保可访问的计算机系统,监视计算机系统以进行连接事务。 当访问请求者在第一可配置的时间段期间启动超过可配置的阈值数量的多个连接事务时,访问请求者被拒绝访问计算机系统。 所述监视可以包括检测由所述访问请求者发起的连接事务,对由所述访问请求者在所述第一可配置时段期间发起的连接事务的数量进行计数,以及将所述访问请求者发起的连接事务的数量在所述第一可配置周期期间进行比较 时间到可配置的阈值数。

    Securing An Access Provider
    36.
    发明申请
    Securing An Access Provider 有权
    保护访问提供者

    公开(公告)号:US20100217863A1

    公开(公告)日:2010-08-26

    申请号:US12775783

    申请日:2010-05-07

    IPC分类号: G06F15/173

    摘要: To secure an access provider, communications to/from the access provider are monitored for a partially-completed connection transaction. Detected partially-completed connection transactions are terminated when they remain in existence for a period of time that exceeds a threshold period of time. The monitoring may include detecting partially-completed connection transactions initiated by an access requestor, measuring the period of time that a partially-completed connection transaction remains in existence, comparing the period of time with the threshold period of time, and resetting a communication port located on the access provider.

    摘要翻译: 为了保护访问提供商,监视与访问提供商的通信以进行部分完成的连接事务。 检测到的部分完成的连接事务在其存在的时间超过阈值时间段时被终止。 监视可以包括检测由访问请求者发起的部分完成的连接事务,测量部分完成的连接事务保持存在的时间段,将该时间段与阈值时间段进行比较,以及重置位于 在接入提供商。

    Connection rate limiting for server load balancing and transparent cache switching

    公开(公告)号:US07774482B1

    公开(公告)日:2010-08-10

    申请号:US10139076

    申请日:2002-05-03

    IPC分类号: G06F9/46 G06F15/16

    摘要: Each service in a computer network may have a connection rate limit. The number of new connections per time period may be limited by using a series of rules. In a specific embodiment of the present invention, a counter is increased each time a server is selected to handle a connection request. For each service, connections coming in are tracked. Therefore, the source of connection-request packets need not be examined. Only the destination service is important. This saves significant time in the examination of the incoming requests. Each service may have its own set of rules to best handle the new traffic for its particular situation. For server load balancing, a reset may be sent to the source address of the new connection request. For transparent cache switching, the connection request may be forwarded to the Internet.

    Connection rate limiting
    38.
    发明授权
    Connection rate limiting 有权
    连接速率限制

    公开(公告)号:US07707295B1

    公开(公告)日:2010-04-27

    申请号:US10139073

    申请日:2002-05-03

    IPC分类号: G06F15/16

    摘要: Each service in a computer network may have a connection rate limit. The number of new connections per time period may be limited by using a series of rules. In a specific embodiment of the present invention, a counter is increased each time a server is selected to handle a connection request. For each service, connections coming in are tracked. Therefore, the source of connection-request packets need not be examined. Only the destination service is important. This saves significant time in the examination of the incoming requests. Each service may have its own set of rules to best handle the new traffic for its particular situation.

    摘要翻译: 计算机网络中的每个服务可能具有连接速率限制。 每个时间段的新连接数可以通过使用一系列规则来限制。 在本发明的具体实施例中,每当选择服务器来处理连接请求时,增加计数器。 对于每个服务,跟踪进入的连接。 因此,不需要检查连接请求数据包的来源。 只有目的地服务很重要。 这样可以节省大量时间来检查传入的请求。 每个服务可能有自己的一套规则,以便为特定情况最好地处理新的流量。

    Method to process HTTP header with hardware assistance
    39.
    发明授权
    Method to process HTTP header with hardware assistance 有权
    使用硬件帮助来处理HTTP头的方法

    公开(公告)号:US09596286B2

    公开(公告)日:2017-03-14

    申请号:US13480494

    申请日:2012-05-25

    IPC分类号: H04L12/56 H04L29/08 H04L29/06

    摘要: In processing Hypertext Transfer Protocol (HTTP) headers, a packet pre-processor is configured with at least one predetermined header field identifier. The packet pre-processor detects at least one header field identifier in a header field of an HTTP packet received over an HTTP session between a host and a server, matches the predetermined header field identifier to the header field identifier in the HTTP packet, generates a header report block comprising information corresponding to the header field identifier in the HTTP packet, and sends the HTTP packet and the header report block to a processor module for processing the HTTP packet based on the header report block. The processor module receives the HTTP packet and the header report block from the packet pre-processor, retrieves a service policy using the header report block, applies the service policy to the HTTP packet, and sends the HTTP packet to the host or the server.

    摘要翻译: 在处理超文本传输​​协议(HTTP)头部中,分组预处理器配置有至少一个预定的报头字段标识符。 分组预处理器通过主机和服务器之间的HTTP会话接收的HTTP分组的报头字段中的至少一个报头字段标识符进行检测,将该预定报头字段标识符与HTTP分组中的报头字段标识符相匹配,生成 头部报头块,其包括与HTTP分组中的报头字段标识符相对应的信息,并且将HTTP分组和报头报头块发送到处理器模块,用于基于报头报告块处理该HTTP分组。 处理器模块从分组预处理器接收HTTP分组和报头块,使用头报头块检索服务策略,将服务策略应用于HTTP分组,并将HTTP分组发送到主机或服务器。

    Securing an accessible computer system
    40.
    发明授权
    Securing an accessible computer system 有权
    保护可访问的计算机系统

    公开(公告)号:US09288218B2

    公开(公告)日:2016-03-15

    申请号:US12727499

    申请日:2010-03-19

    摘要: To secure an accessible computer system, the computer system is monitored for connection transactions. An access requestor is denied access to the computer system when the access requestor initiates a number of connection transactions that exceed a configurable threshold number during a first configurable period of time. The monitoring may include detecting connection transactions initiated by the access requestor, counting the number of connection transactions initiated by the access requestor during the first configurable period of time, and comparing the number of connection transactions initiated by the access requestor during the first configurable period of time to the configurable threshold number.

    摘要翻译: 为了确保可访问的计算机系统,监视计算机系统以进行连接事务。 当访问请求者在第一可配置的时间段期间启动超过可配置的阈值数量的多个连接事务时,访问请求者被拒绝访问计算机系统。 所述监视可以包括检测由所述访问请求者发起的连接事务,对由所述访问请求者在所述第一可配置时段期间发起的连接事务的数量进行计数,以及将所述访问请求者发起的连接事务的数量在所述第一可配置周期期间进行比较 时间到可配置的阈值数。