Obscuring network traffic characteristics

    公开(公告)号:US10826876B1

    公开(公告)日:2020-11-03

    申请号:US15388426

    申请日:2016-12-22

    IPC分类号: H04L29/06

    摘要: The following description is directed to encrypting the characteristics of network traffic. In one example, a method can include receiving an unencrypted link layer packet including a first payload of a first size. The method can include encrypting the first payload of the unencrypted link layer packet. The method can include generating an encrypted link layer packet including a second payload. The second payload can include the encrypted payload and a variable length padding field so that the second payload of the encrypted link layer packet is a different size than the first size of the first payload. The encrypted link layer packet can then be transmitted.

    Managing next hop groups in routers

    公开(公告)号:US10404598B1

    公开(公告)日:2019-09-03

    申请号:US15589537

    申请日:2017-05-08

    摘要: Technologies are provided for organizing network routes using network topology information. A router in a computer network can be configured to group network address prefixes in a routing table based on origin device clusters. The router can be configured to receive a routing protocol message comprising one or more prefixes and associated next hops. The router can identify an origin device cluster based on information contained in the message. The router can create a next hop group and associate it with the origin device cluster. The router can add the prefixes and next hops in the message to the next hop group. When an updated next hop list for a prefix is received at the router, the router can identify an origin device cluster for the prefix, identify a next hop group associated with the origin device cluster, and update the next hop group using the updated next hop list.

    Network base signal distribution system

    公开(公告)号:US10448127B1

    公开(公告)日:2019-10-15

    申请号:US15933179

    申请日:2018-03-22

    IPC分类号: H04J14/00 H04Q11/00

    摘要: Communication systems include network nodes that distribute an electrical or optical base signal to remote nodes for modulation at the remotes nodes. A first waveguide is coupled to transmit data to a corresponding remote node, a second waveguide is coupled to receive remotely modulated data from the remote node, and a third waveguide is coupled to deliver the base signal to the remote node. Typically, the base signal is an optical signal from a laser diode, and optical fibers communicate modulated data signals and the base signal. A portion of the base signal can also be modulated for communication with remote nodes.

    Modular encryption device
    4.
    发明授权

    公开(公告)号:US10075418B1

    公开(公告)日:2018-09-11

    申请号:US15469328

    申请日:2017-03-24

    IPC分类号: H04L29/06

    摘要: A modular encryption device includes a chassis configured to mount in a rack with a networking device and sets of ports mounted on the chassis. Encryption cards are mounted in the chassis of the modular encryption device between ports of the sets of ports such that network traffic flowing through a set of ports flows through one of the encryption cards. The encryption cards of the modular encryption device are configured to encrypt and decrypt network traffic flowing between the networking device and a remote device. In some embodiments, a modular encryption device may encrypt and decrypt network traffic flowing between multiple networking devices and multiple remote devices. Also, in some embodiments, components of a modular encryption device are removable and replaceable such that the modular encryption device can be reconfigured by exchanging the components.

    Virtualization mapping
    5.
    发明授权
    Virtualization mapping 有权
    虚拟化映射

    公开(公告)号:US09385887B2

    公开(公告)日:2016-07-05

    申请号:US14456253

    申请日:2014-08-11

    摘要: Systems and methods for the management of virtual machine instances are provided. The hosted virtual machine networks are configured in a manner such that communications within the hosted virtual machine network are facilitated through a communication protocol. Illustrative embodiments of the systems and methods may be implemented on a virtual network overlaid on one or more intermediate physical networks that are used as a substrate network. Through the utilization of one or more virtual network mapping components in communication with the hosted virtual network components, communications to and from the hosted virtual networks can be processed by mapping relationships between the virtual network communication protocol and the router communication protocol. The mapping information can be provided in advance or as requested to the router components and hosted virtual network components to facilitate bi-lateral communications between the components.

    摘要翻译: 提供了用于管理虚拟机实例的系统和方法。 托管的虚拟机网络被配置为使得通过通信协议促进托管的虚拟机网络内的通信。 可以在覆盖在用作衬底网络的一个或多个中间物理网络上的虚拟网络上实现系统和方法的说明性实施例。 通过利用与托管的虚拟网络组件通信的一个或多个虚拟网络映射组件,可以通过映射虚拟网络通信协议和路由器通信协议之间的关系来处理与托管虚拟网络的通信。 映射信息可以提前或按要求提供给路由器组件和托管的虚拟网络组件,以促进组件之间的双向通信。

    CLIENT TRAFFIC REDIRECTION SERVICE
    7.
    发明申请
    CLIENT TRAFFIC REDIRECTION SERVICE 审中-公开
    客户交通重定向服务

    公开(公告)号:US20150244671A1

    公开(公告)日:2015-08-27

    申请号:US14707644

    申请日:2015-05-08

    IPC分类号: H04L29/12

    摘要: Disclosed are various embodiments for performing network traffic redirection at the client side. Sending of data to a service at a network address is initiated. Whether the network address is in a predetermined network address range is determined. The network address is translated, when the network address is in the predetermined network address range, to one of multiple other network addresses based at least in part on an availability of the service at the other network address. The data is routed to the other network address.

    摘要翻译: 公开了在客户端执行网络业务重定向的各种实施例。 发起数据到网络地址的服务。 确定网络地址是否在预定的网络地址范围内。 至少部分地基于另一网络地址处的服务的可用性,将网络地址处于预定网络地址范围内的网络地址转换为多个其他网络地址之一。 数据被路由到另一个网络地址。

    VIRTUALIZATION MAPPING
    9.
    发明申请
    VIRTUALIZATION MAPPING 审中-公开
    虚拟化映射

    公开(公告)号:US20170034002A1

    公开(公告)日:2017-02-02

    申请号:US15199459

    申请日:2016-06-30

    IPC分类号: H04L12/24 H04L12/751

    摘要: Systems and methods for the management of virtual machine instances are provided. The hosted virtual machine networks are configured in a manner such that communications within the hosted virtual machine network are facilitated through a communication protocol. Illustrative embodiments of the systems and methods may be implemented on a virtual network overlaid on one or more intermediate physical networks that are used as a substrate network. Through the utilization of one or more virtual network mapping components in communication with the hosted virtual network components, communications to and from the hosted virtual networks can be processed by mapping relationships between the virtual network communication protocol and the router communication protocol. The mapping information can be provided in advance or as requested to the router components and hosted virtual network components to facilitate bi-lateral communications between the components.

    摘要翻译: 提供了用于管理虚拟机实例的系统和方法。 托管的虚拟机网络被配置为使得通过通信协议促进托管的虚拟机网络内的通信。 可以在覆盖在用作衬底网络的一个或多个中间物理网络上的虚拟网络上实现系统和方法的说明性实施例。 通过利用与托管的虚拟网络组件通信的一个或多个虚拟网络映射组件,可以通过映射虚拟网络通信协议和路由器通信协议之间的关系来处理与托管的虚拟网络的通信。 映射信息可以提前或按要求提供给路由器组件和托管的虚拟网络组件,以促进组件之间的双向通信。

    DYNAMIC NETWORK DEVICE CONFIGURATION
    10.
    发明申请
    DYNAMIC NETWORK DEVICE CONFIGURATION 审中-公开
    动态网络设备配置

    公开(公告)号:US20160352569A1

    公开(公告)日:2016-12-01

    申请号:US15235589

    申请日:2016-08-12

    IPC分类号: H04L12/24

    摘要: A dynamic configuration system can manage and configure switches or other network devices that come online in a network. When the dynamic configuration system determines that a network device has come online, the dynamic configuration system can identify the network device (e.g., based on its network location, neighbors, fingerprint, identifier, address or the like), select the appropriate configuration data for the network based on the desired network topology, and transmit the configuration data to the network device. The network device can then load the configuration data and function as a component of the desired network topology.

    摘要翻译: 动态配置系统可以管理和配置网络中联机的交换机或其他网络设备。 当动态配置系统确定网络设备已经上线时,动态配置系统可以识别网络设备(例如,基于其网络位置,邻居,指纹,标识符,地址等),选择适当的配置数据 基于所需网络拓扑的网络,并将配置数据发送到网络设备。 网络设备然后可以加载配置数据并且作为所需网络拓扑的组成部分。