APPLYING FINE-GRAIN POLICY ACTION TO ENCAPSULATED NETWORK ATTACKS

Patent №

US 9,398,043

Granted

2016-07-19

Filed 2009

Owner

JUNIPER NETWORKS, INC.

Lab

AI components

2

kr · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

12409634

An intrusion detection system inspects encapsulated packet flows and, upon detecting a malicious encapsulated packet flow, may close an encapsulated network session corresponding to the malicious flow or drop sub-packets of the malicious flow without acting against non-malicious sub-packets and/or sessions. In one example, a network device includes a flow analysis module that receives a packet flow packets, each packet comprising a packet header and one or more sub-packets each corresponding to respective network sessions, an attack detection module that identifies at least one of the network sessions as a malicious network session, a policy action module that executes a policy action on the sub-packet corresponding to the malicious network session based on the identification of the malicious network session, and a forwarding component that forms a reconstructed packet comprising the packet header and the sub-packets excluding the sub-packet corresponding to the malicious network session and forwards the reconstructed packet.

AI classification

AI hardware0.96
Knowledge representation0.75
Vision0.05
Machine learning0.01
Planning0.01
Natural language0.01
Evolutionary computation0.00
Speech0.00

Ownership

JUNIPER NETWORKS, INC.

assignment · 224380793

Assignors

YANG, SIYING

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC