Systems and methods for cookie proxy jar management across cores in a multi-core system
    61.
    发明授权
    Systems and methods for cookie proxy jar management across cores in a multi-core system 有权
    在多核系统中跨多核的cookie代理jar管理的系统和方法

    公开(公告)号:US08484287B2

    公开(公告)日:2013-07-09

    申请号:US12851449

    申请日:2010-08-05

    IPC分类号: G06F15/16

    摘要: The present solution is directed towards systems and methods for managing cookies by a multi-core device. The device is intermediary to a client and one or more servers. A first core of a multi-core device receives a response from a server to a request of the client through a user session. The response comprises a cookie. The first core removes the cookie from the response and stores the cookie in a corresponding storage for the session. The first core forwards the response without the cookie to the client. A second core then receives via a session, a second request from the client. The second core determines the identification of the first core as owner of the session from the second request. The second core then communicates to the first core a third request for cookie information for the session.

    摘要翻译: 目前的解决方案涉及用于通过多核设备管理Cookie的系统和方法。 该设备是客户端和一个或多个服务器的中介。 多核设备的第一核心通过用户会话接收从服务器到客户端的请求的响应。 响应包括一个cookie。 第一个核心从响应中删除cookie,并将cookie存储在会话的相应存储中。 第一个核心将没有cookie的响应转发给客户端。 然后,第二核心经由会话接收来自客户端的第二请求。 第二核确定第一个核心作为第二个请求中的会话的所有者的标识。 然后,第二个核心向第一个核心传达第三个会话Cookie信息请求。

    Intelligent network interface controller
    62.
    发明授权
    Intelligent network interface controller 有权
    智能网络接口控制器

    公开(公告)号:US08418252B2

    公开(公告)日:2013-04-09

    申请号:US13359274

    申请日:2012-01-26

    CPC分类号: H04L63/0428 H04L63/14

    摘要: A network interface device includes a security database and a security services engine. The security database is configured to store patterns corresponding to predetermined malware. The security services engine is configured to compare data to be transmitted through a network to the patterns stored in the security database, and the security database is configured to receive updated patterns from the network.

    摘要翻译: 网络接口设备包括安全数据库和安全服务引擎。 安全数据库被配置为存储对应于预定恶意软件的模式。 安全服务引擎被配置为将要通过网络发送的数据与存储在安全数据库中的模式进行比较,并且安全数据库被配置为从网络接收更新的模式。

    Systems and methods for fine grain policy driven cookie proxying
    63.
    发明授权
    Systems and methods for fine grain policy driven cookie proxying 有权
    细粒度政策驱动的Cookie代理的系统和方法

    公开(公告)号:US08090877B2

    公开(公告)日:2012-01-03

    申请号:US12360014

    申请日:2009-01-26

    IPC分类号: G07F15/16

    摘要: The present solution enables a client that is not configured to use cookies to access resources of the server that uses cookies for communications with the clients. An intermediary deployed between a client and a server intercepts and modifies transmissions between the client and the server to compensate for the mismatch in configuration of the cookies between the client and the server. The present disclosure relates to a method for managing cookies by an intermediary for a client. An intermediary receives a response from a server to a request of a client. The response may comprise a uniform resource locator (URL) and a cookie. The intermediary may modify the response by removing the cookie from the response and inserting a unique client identifier into the URL. The intermediary may store the removed cookie in association with the unique client identifier and forward the modified response to the client.

    摘要翻译: 本解决方案使未配置为使用Cookie的客户端访问使用Cookie与客户端通信的服务器的资源。 部署在客户端和服务器之间的中间人拦截并修改客户端和服务器之间的传输,以补偿客户端和服务器之间的Cookie配置不匹配。 本公开涉及一种用于由客户端的中间人管理cookie的方法。 中介从服务器接收到客户端请求的响应。 响应可以包括统一的资源定位符(URL)和cookie。 中间人可以通过从响应中删除cookie并将唯一的客户端标识符插入到URL中来修改响应。 中介可以将删除的cookie与唯一的客户端标识符相关联地存储,并将修改的响应转发给客户端。

    Systems and Methods for Providing Single Sign On Access to Enterprise SAAS and Cloud Hosted Applications
    64.
    发明申请
    Systems and Methods for Providing Single Sign On Access to Enterprise SAAS and Cloud Hosted Applications 有权
    提供单一登录访问企业SAAS和云托管应用程序的系统和方法

    公开(公告)号:US20110277026A1

    公开(公告)日:2011-11-10

    申请号:US13102902

    申请日:2011-05-06

    IPC分类号: H04L9/32 G06F21/00

    摘要: The solution of the present application addresses the problem of authentication across disparately hosted systems by providing a single authentication domain across SaaS and cloud hosted applications as well as traditional enterprise hosted applications. An application delivery controller intermediary to a plurality of clients and the disparately hosted applications providing single sign on management, integration and control. A user may log in via an interface provided, controlled or managed by the ADC, which in turns, authenticates the user to the application in accordance with policy and the host of the application. As such, the user may login once to gain access to a plurality of disparately hosted applications. From the user's perspective, the user seamlessly and transparently gains access to different hosted systems with different passwords and authentication via the remote access provided by the system of the present solution

    摘要翻译: 本应用程序的解决方案通过在SaaS和云托管应用程序以及传统的企业托管应用程序之间提供单个身份验证域来解决跨不同托管系统的身份验证问题。 多个客户端的应用交付控制器中介,以及提供单一登录管理,集成和控制的不同托管的应用。 用户可以通过由ADC提供,控制或管理的接口登录,该接口根据策略和应用的主机向用户认证用户。 因此,用户可以登录一次以访问多个不同的托管的应用。 从用户的角度来看,用户通过本解决方案系统提供的远程访问,无缝透明地访问具有不同密码和身份验证的不同托管系统

    Intelligent fabric congestion detection apparatus and method
    66.
    发明授权
    Intelligent fabric congestion detection apparatus and method 失效
    智能结构拥塞检测装置及方法

    公开(公告)号:US07830801B2

    公开(公告)日:2010-11-09

    申请号:US11259041

    申请日:2005-10-27

    IPC分类号: H04L12/56

    摘要: An intelligent fabric congestion control apparatus and method are provided to receive data packets from source endpoints and output the data packets to destination endpoints. The apparatus and method include a counter, a timer, and a controller. The counter increments from a preset value when a data packet is received at an egress queue and decrements when the data packet is output from the egress queue. The timer starts timing in response to the incrementing of the counter from the preset value. The controller performs one of resetting the timer when the counter is decremented to the preset value prior to the timer reaching a first threshold, and detecting a persistent congestion when the timer reaches the first threshold.

    摘要翻译: 提供了一种智能结构拥塞控制装置和方法,用于从源端点接收数据包,并将数据包输出到目标端点。 该装置和方法包括计数器,定时器和控制器。 当在出口队列处接收到数据分组时,计数器从预置值递增,并且当从出口队列输出数据分组时,计数器递减。 定时器响应于从预设值增加计数器开始定时。 控制器在定时器达到第一阈值之前将计数器减小到预设值,并且当定时器达到第一阈值时检测持续拥塞,来执行重置定时器之一。

    Systems and Methods for For Proxying Cookies for SSL VPN Clientless Sessions
    67.
    发明申请
    Systems and Methods for For Proxying Cookies for SSL VPN Clientless Sessions 有权
    用于代理SSL VPN客户端会话的Cookie的系统和方法

    公开(公告)号:US20090199285A1

    公开(公告)日:2009-08-06

    申请号:US12360019

    申请日:2009-01-26

    IPC分类号: H04L9/32

    摘要: The present application enables the enterprise to configure various policies to address various subsets of the traffic based on various information relating the client, the server, or the details and nature of the interactions between the client and the server. An intermediary deployed between clients and servers may establish an SSL VPN session between a client and a server. The intermediary may receiving a response from a server to a request of a client via the clientless SSL VPN session. The response may comprise one or more cookies. The intermediary may identify an access profile for the clientless SSL VPN session. The access profile may identify one or more policies for proxying cookies. The intermediary may determine, responsive to the one or more policies of the access profile, whether to proxy or bypass proxying for the client the one or more cookies.

    摘要翻译: 本应用使得企业能够基于与客户端,服务器或客户端与服务器之间的交互的细节和性质相关的各种信息来配置各种策略来处理流量的各种子集。 部署在客户端和服务器之间的中介可以在客户端和服务器之间建立SSL VPN会话。 中间人可以通过无客户端SSL VPN会话从服务器接收到客户端的请求的响应。 响应可以包括一个或多个cookie。 中介可以识别无客户端SSL VPN会话的访问配置文件。 访问配置文件可以标识用于代理Cookie的一个或多个策略。 中介可以响应于访问简档的一个或多个策略来确定是否为客户端代理或绕过代理一个或多个cookie。

    SYSTEMS AND METHODS FOR CONFIGURATION DRIVEN REWRITE OF SSL VPN CLIENTLESS SESSIONS
    68.
    发明申请
    SYSTEMS AND METHODS FOR CONFIGURATION DRIVEN REWRITE OF SSL VPN CLIENTLESS SESSIONS 有权
    用于配置驱动SSL VPN客户端会话的系统和方法

    公开(公告)号:US20090193126A1

    公开(公告)日:2009-07-30

    申请号:US12359998

    申请日:2009-01-26

    IPC分类号: G06F15/173

    摘要: The present disclosure provides solutions for an enterprise providing services to a variety of clients to enable the client to use the resources provided by the enterprise by modifying URLs received and the URLs from the responses from the servers to the client's requests before forwarding the requests and the responses to the intended destinations. An intermediary may identify an access profile for a clients' request to access a server via a clientless SSL VPN session. The intermediary may detect one or more URLs in content served by the server in response to the request using one or more regular expressions of the access profile. The intermediary may rewrite or modify, responsive to detecting, the one or more detected URLs in accordance with a URL transformation specified by one or more rewrite policies of the access profile. The response with modified URLs may be forwarded to the client.

    摘要翻译: 本公开提供了向各种客户端提供服务的企业的解决方案,以使得客户端能够在转发请求之前通过修改所接收的URL和从服务器的响应到客户端的请求来使用由企业提供的资源,并且 对预期目的地的回应。 中介可以识别客户端通过无客户端SSL VPN会话访问服务器的请求的访问配置文件。 响应于使用访问简档的一个或多个正则表达式的请求,中介可以检测服务器所服务的内容中的一个或多个URL。 根据由访问简档的一个或多个重写策略指定的URL变换,中介可以响应于检测到一个或多个检测到的URL来重写或修改。 具有修改的URL的响应可以转发给客户端。

    Network for supporting advance features on legacy components
    69.
    发明申请
    Network for supporting advance features on legacy components 失效
    用于支持旧组件的高级功能的网络

    公开(公告)号:US20060114938A1

    公开(公告)日:2006-06-01

    申请号:US11289369

    申请日:2005-11-30

    摘要: A network device that processes packets and includes at least one legacy component for performing basic processing on packets in the network device. The network device further includes at least one advanced component for performing advanced processing, which can not be performed by the legacy component, on packets in the network device. When an incoming packet to the legacy component requires advanced processing, the legacy component performs the basic processing and transmits the packet to a loop-back port on advanced component. Upon receiving the packet, basic processing is disabled on the advanced component and advanced processing is performed on the packet.

    摘要翻译: 一种网络设备,其处理分组并且包括用于对所述网络设备中的分组执行基本处理的至少一个传统组件。 网络设备还包括至少一个高级组件,用于在网络设备中的分组上执行不能由传统组件执行的高级处理。 当到传统组件的传入分组需要高级处理时,传统组件执行基本处理,并将分组发送到高级组件上的环回端口。 接收到报文后,对高级组件进行基本处理,对报文进行高级处理。

    Apparatus and methods for efficient multicasting of data packets
    70.
    发明授权
    Apparatus and methods for efficient multicasting of data packets 有权
    用于有效组播数据包的装置和方法

    公开(公告)号:US06870844B2

    公开(公告)日:2005-03-22

    申请号:US09854234

    申请日:2001-05-10

    摘要: A multicast engine is provided in plurality within a router for replicating and/or modifying packets identified as multicast packets. In preferred embodiments the engine is integrated with one or more ports of a router, particularly with one or more ports of fabric cards. In one implementation the multicast engine is associated with a table having instructions for replicating or modifying multicast packets received, and forwarding the packets accordingly.

    摘要翻译: 在路由器内多个地提供多播引擎,用于复制和/或修改被标识为多播分组的分组。 在优选实施例中,引擎与路由器的一个或多个端口集成,特别是与一个或多个结构卡端口。 在一个实现中,多播引擎与具有用于复制或修改所接收的多播分组的指令的表相关联,并相应地转发分组。