APPARATUS AND METHOD FOR BALANCING LOAD ACROSS MULTIPLE PACKET PROCESSING ENGINES
    1.
    发明申请
    APPARATUS AND METHOD FOR BALANCING LOAD ACROSS MULTIPLE PACKET PROCESSING ENGINES 有权
    用于通过多个分组处理引擎平衡负载的装置和方法

    公开(公告)号:US20120147891A1

    公开(公告)日:2012-06-14

    申请号:US13323178

    申请日:2011-12-12

    IPC分类号: H04L12/56

    CPC分类号: H04L47/125

    摘要: A distributed packet processing apparatus capable of distributing packet load across a plurality of packet processing engines is provided. The distributed packet processing apparatus includes a plurality of processing engines each configured to process allocated packets, a first tag generating unit configured to allocate an input packet to a processing engine, which has a processing engine index corresponding to a tag index for the input packet, among the plurality of processing engines, a second tag generating unit configured to calculate a tag index for an output packet, and an index conversion unit configure to convert the tag index for the output packet to one processing engine index among a plurality of processing indexes for the plurality of the processing engines and allocates the output packet to a processing engine having the one processing engine such that loads are distributed among the plurality of processing engines.

    摘要翻译: 提供能够跨多个分组处理引擎分发分组负载的分布式分组处理装置。 分布式分组处理装置包括:处理分配的分组的多个处理引擎,第一标签生成单元,被配置为向处理引擎分配输入分组,处理引擎具有与输入分组的标签索引对应的处理引擎索引, 在所述多个处理引擎中,第二标签生成单元,被配置为计算输出分组的标签索引,以及索引变换单元,其将所述输出分组的标签索引转换为多个处理索引中的多个处理索引, 所述多个处理引擎并将所述输出分组分配给具有所述一个处理引擎的处理引擎,使得在所述多个处理引擎之间分配负载。

    HIGH-SPEED CONTENT INSPECTION APPARATUS FOR MINIMIZING SYSTEM OVERHEAD
    2.
    发明申请
    HIGH-SPEED CONTENT INSPECTION APPARATUS FOR MINIMIZING SYSTEM OVERHEAD 审中-公开
    用于最小化系统的高速内容检查装置

    公开(公告)号:US20120147754A1

    公开(公告)日:2012-06-14

    申请号:US13324416

    申请日:2011-12-13

    IPC分类号: H04J3/14

    CPC分类号: H04L43/028

    摘要: A high-speed content inspection apparatus for minimizing system overhead is provided. The high-speed content inspection apparatus extracts content in unit of sub-pattern by inspecting a payload of a packet in units of sub-pattern, and extract target content by inspecting a correlation between the extracted sub-patterns. If a sub-pattern present at the end of a payload is smaller than a predetermined unit of a sub-pattern, position information of the sub-pattern at the end of the payload is rolled back and the correlation is inspected. Accordingly, without having to add another hardware or high-performance hardware, target content can be efficiently detected in real time.

    摘要翻译: 提供了一种用于最小化系统开销的高速内容检查装置。 高速内容检查装置以子图案为单位检查分组的有效载荷,以子图案为单位提取内容,并通过检查提取的子模式之间的相关性来提取目标内容。 如果存在于有效负载结束处的子模式小于子模式的预定单元,则在有效负载结束时的子模式的位置信息被回滚并且检查相关性。 因此,无需添加另一硬件或高性能硬件,可以实时有效地检测目标内容。

    APPARATUS AND METHOD FOR CYBER-ATTACK PREVENTION
    6.
    发明申请
    APPARATUS AND METHOD FOR CYBER-ATTACK PREVENTION 审中-公开
    装置和方法,用于防止病毒感染

    公开(公告)号:US20130167219A1

    公开(公告)日:2013-06-27

    申请号:US13616670

    申请日:2012-09-14

    IPC分类号: G06F21/20

    CPC分类号: H04L63/1425 H04L63/1458

    摘要: Provided are a method of preventing cyber-attack based on a terminal and a terminal apparatus therefor. The terminal apparatus includes: a packet processor configured to determine whether excessive traffic is generated by a transmission packet; an anomalous traffic detecting unit configured to determine whether anomalous traffic is generated, using a first condition of the excessive traffic being maintained for a first time period and a second condition of a generation count of the same kind of transmission packets exceeding a predetermined threshold value for a second time period; and a traffic block request unit configured to generate a traffic block request signal for requesting blockage of the transmission packet according to the result of determining whether anomalous traffic is generated.

    摘要翻译: 提供一种基于终端及其终端装置来防止网络攻击的方法。 终端装置包括:分组处理器,被配置为确定是否由传输分组产生过量业务; 异常业务检测单元,被配置为使用在第一时间段内保持过多业务的第一条件和超过预定阈值的相同类型的发送分组的生成计数的第二条件来确定是否产生异常业务, 第二个时期; 以及业务块请求单元,被配置为根据确定是否产生异常业务的结果来生成用于请求阻塞所述传输分组的业务块请求信号。

    Apparatus and method for balancing load across multiple packet processing engines
    7.
    发明授权
    Apparatus and method for balancing load across multiple packet processing engines 有权
    用于平衡多个分组处理引擎的负载的装置和方法

    公开(公告)号:US08885646B2

    公开(公告)日:2014-11-11

    申请号:US13323178

    申请日:2011-12-12

    IPC分类号: H04L12/28 H04L12/803

    CPC分类号: H04L47/125

    摘要: A distributed packet processing apparatus capable of distributing packet load across a plurality of packet processing engines is provided. The distributed packet processing apparatus includes a plurality of processing engines each configured to process allocated packets, a first tag generating unit configured to allocate an input packet to a processing engine, which has a processing engine index corresponding to a tag index for the input packet, among the plurality of processing engines, a second tag generating unit configured to calculate a tag index for an output packet, and an index conversion unit configure to convert the tag index for the output packet to one processing engine index among a plurality of processing indexes for the plurality of the processing engines and allocates the output packet to a processing engine having the one processing engine index such that loads are distributed among the plurality of processing engines.

    摘要翻译: 提供能够跨多个分组处理引擎分发分组负载的分布式分组处理装置。 分布式分组处理装置包括:处理分配的分组的多个处理引擎,第一标签生成单元,被配置为向处理引擎分配输入分组,处理引擎具有与输入分组的标签索引对应的处理引擎索引, 在所述多个处理引擎中,第二标签生成单元,被配置为计算输出分组的标签索引,以及索引变换单元,其将所述输出分组的标签索引转换为多个处理索引中的多个处理索引, 多个处理引擎,并且将输出分组分配给具有一个处理引擎索引的处理引擎,使得负载分布在多个处理引擎之间。

    PACKET SCHEDULING METHOD AND APPARATUS BASED ON FAIR BANDWIDTH ALLOCATION
    9.
    发明申请
    PACKET SCHEDULING METHOD AND APPARATUS BASED ON FAIR BANDWIDTH ALLOCATION 有权
    基于公平带宽分配的分组调度方法和设备

    公开(公告)号:US20120127859A1

    公开(公告)日:2012-05-24

    申请号:US13301350

    申请日:2011-11-21

    IPC分类号: H04L12/26

    摘要: A packet scheduling method and apparatus which allows multiple flows that require data transmission to the same output port of a network device such as a router to fairly share bandwidth. The packet scheduling method includes calculating an expected time of arrival of a (k+1)-th packet subsequent to a currently input k-th packet of individual flows by use of bandwidth allocated fairly to each of the flows and a length of the k-th packet; in response to the arrival of the (k+1)-th packet, comparing the expected time of arrival of the (k+1)-th packet to an actual time of arrival of the (k+1)-th packet; and scheduling the (k+1)-th packet of each flow according to the comparison result.

    摘要翻译: 一种分组调度方法和装置,其允许需要数据传输到诸如路由器的网络设备的相同输出端口的多个流以公平地共享带宽。 分组调度方法包括通过使用公平分配给每个流的带宽和k的长度来计算当前输入的各个流的第k个分组之后的第(k + 1)个分组的到达时间 第 响应于第(k + 1)个分组的到达,将第(k + 1)个分组的预期到达时间与第(k + 1)个分组的实际到达时间进行比较; 并根据比较结果调度每个流的第(k + 1)个分组。