Invention Grant
- Patent Title: Cooperated approach to network packet filtering
-
Application No.: US15677829Application Date: 2017-08-15
-
Publication No.: US10375022B2Publication Date: 2019-08-06
- Inventor: Yaozu Dong , Kun Tian
- Applicant: Intel Corporation
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Barnes & Thornburg LLP
- Main IPC: G06F9/46
- IPC: G06F9/46 ; H04L29/06 ; H04L12/931 ; G06F9/455

Abstract:
An apparatus, system, method, and machine-readable medium are disclosed. In one embodiment the apparatus is a network interface controller that includes one virtual function owned by a virtual machine present in the computer system. The controller includes a simple filtering agent that is associated with the first virtual function. The agent enforces simple filter rules for received network packets. The simple filter rules are capable of blocking the network packets from reaching the virtual machine. The apparatus also includes another virtual function that is owned by a virtual machine monitor present in the computer system. The controller also includes a side bounce filtering agent to forward the first network packet to the second virtual function if the first packet is blocked by the at least one of the one or more simple filter rules.
Public/Granted literature
- US20180167364A1 COOPERATED APPROACH TO NETWORK PACKET FILTERING Public/Granted day:2018-06-14
Information query