LAYER-3 POLICY ENFORCEMENT FOR LAYER-7 DATA FLOWS

    公开(公告)号:US20230328038A1

    公开(公告)日:2023-10-12

    申请号:US17718634

    申请日:2022-04-12

    Abstract: Techniques for using proxies with overprovisioned IP addresses to demultiplex data flows, which may otherwise look the same at L7, into multiple subflows for L3 policy enforcement without having to modify an underlying L3 network. The techniques may include establishing a subflow through a network between a first proxy and a second proxy, the subflow associated with a specific policy. In some examples, the first proxy node may receive an encrypted packet that is to be sent through the network and determine, based at least in part on accessing an encrypted application layer of the packet, a specific application to which the packet is to be sent. The first proxy node may then alter an IP address included in the packet to cause the packet to be sent through the network via the subflow such that the packet is handled according to the specific policy.

    Layer-3 policy enforcement for layer-7 data flows

    公开(公告)号:US12294569B2

    公开(公告)日:2025-05-06

    申请号:US17718634

    申请日:2022-04-12

    Abstract: Techniques for using proxies with overprovisioned IP addresses to demultiplex data flows, which may otherwise look the same at L7, into multiple subflows for L3 policy enforcement without having to modify an underlying L3 network. The techniques may include establishing a subflow through a network between a first proxy and a second proxy, the subflow associated with a specific policy. In some examples, the first proxy node may receive an encrypted packet that is to be sent through the network and determine, based at least in part on accessing an encrypted application layer of the packet, a specific application to which the packet is to be sent. The first proxy node may then alter an IP address included in the packet to cause the packet to be sent through the network via the subflow such that the packet is handled according to the specific policy.

    APPLICATION MONITORING SYSTEM FOR NETWORK ORCHESTRATION

    公开(公告)号:US20240205094A1

    公开(公告)日:2024-06-20

    申请号:US18591960

    申请日:2024-02-29

    CPC classification number: H04L41/12

    Abstract: An application monitoring system for collecting, utilizing, and/or exchanging state information (e.g., application state and network state), configuration information, and/or other information to make network optimizations for applications orchestrated by an application orchestration system. The application monitoring system may include an application orchestrator discovery component that is configured to determine a presence of an application orchestration system for orchestrating applications. The application monitoring system may also include one or more application watch components for monitoring, among other things, application state, application configuration, and/or application replicas. The application monitoring system may further include a network state propagation component configured to provide network state information to the orchestration system.

    Multipath Provisioning of L4-L7 Traffic in a Network
    16.
    发明申请
    Multipath Provisioning of L4-L7 Traffic in a Network 审中-公开
    网络中L4-L7流量的多路径配置

    公开(公告)号:US20160119196A1

    公开(公告)日:2016-04-28

    申请号:US14612691

    申请日:2015-02-03

    Abstract: Techniques are provided for a network mapping server device in a network to receive a connection upgrade message comprising information to establish a first data flow from a first endpoint that does not support multiple subflows for the first data flow according to a multipath protocol, where multiple subflows subdivide the first data flow across two or more network paths. The information in the connection upgrade message is analyzed in order to resolve network connectivity to determine potential network connections for at least two subflows of the first data flow to a second endpoint. A response message is sent comprising information configured to establish at least two subflows for the first data flow between the first endpoint and the second endpoint.

    Abstract translation: 为网络中的网络映射服务器设备提供技术,以接收包括信息的连接升级消息,以便根据多路径协议从不支持第一数据流的多个子流的第一端点建立第一数据流,其中多个子流 第一个数据流跨越两个或多个网络路径细分。 分析连接升级消息中的信息以便解析网络连接以确定到第二端点的至少两个子流的第一数据流的潜在网络连接。 发送响应消息,包括被配置为为第一端点和第二端点之间的第一数据流建立至少两个子流的信息。

Patent Agency Ranking