Invention Grant
- Patent Title: Deploying a security appliance system in a high availability environment without extra network burden
-
Application No.: US14641461Application Date: 2015-03-09
-
Publication No.: US09628504B2Publication Date: 2017-04-18
- Inventor: Ming Da Ho , Ming-Pin Hsueh , Ting-Jui Hu , Ping-Hung Lee , Ming-Hsun Wu
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Michael O'Keefe
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/851 ; H04L12/801

Abstract:
A security appliance system routing strings of data packets in a high availability environment. The security appliance system contains a plurality of intrusion prevention systems connected to a load balancer and a computing device. Each intrusion prevention system contains stored session state information in a local session state data store, the load balancer contains a shared hash algorithm, and the computing device contains a connection state manager containing a network session state data store. The computing device includes a topology manager recording connectivity changes of the intrusion prevention systems and accordingly adjusting the shared hash algorithm for the recorded connectivity changes. Using the shared hash algorithm and routing information, a hash value is assigned to received strings. Strings are forwarded an intrusion prevention system based on assigned hash value and processed using stored session state information within the local session state data store and the network session state data store.
Public/Granted literature
- US20160269439A1 DEPLOYING A SECURITY APPLIANCE SYSTEM IN A HIGH AVAILABILITY ENVIRONMENT WITHOUT EXTRA NETWORK BURDEN Public/Granted day:2016-09-15
Information query