Invention Grant
- Patent Title: Lightweight distributed application security through programmable extraction of dynamic metadata
-
Application No.: US16741794Application Date: 2020-01-14
-
Publication No.: US11412000B2Publication Date: 2022-08-09
- Inventor: Michel Khouderchah , Jayaraman Iyer , Kent K. Leung , Jianxin Wang , Donovan O'Hara , Saman Taghavi Zargar , Subharthi Paul
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: H04L9/40
- IPC: H04L9/40 ; H04L67/02 ; H04L41/22

Abstract:
Presented herein are methodologies for implementing application security. A method includes generating an extraction vector based on a plurality of application security rules to be enforced, transmitting the extraction vector to a first agent operating on a first network device and to a second agent operating on a second network device; receiving, separately, from the first agent and from the second agent, first metadata generated by the first agent and second metadata generated by the second agent by the agents applying the extraction vector to network traffic passing, respectively, through the first network device and the second network device. The first metadata includes a transaction ID assigned by the first agent, and the second metadata includes the same transaction ID. The method further includes correlating the first metadata with the second metadata based on the transaction ID to construct a transactional service graph for the network traffic.
Public/Granted literature
- US20210218771A1 LIGHTWEIGHT DISTRIBUTED APPLICATION SECURITY THROUGH PROGRAMMABLE EXTRACTION OF DYNAMIC METADATA Public/Granted day:2021-07-15
Information query