Patent №
US 9,398,043
Granted
2016-07-19
Filed 2009
Owner
JUNIPER NETWORKS, INC.
Lab
—
AI components
2
kr · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
12409634
An intrusion detection system inspects encapsulated packet flows and, upon detecting a malicious encapsulated packet flow, may close an encapsulated network session corresponding to the malicious flow or drop sub-packets of the malicious flow without acting against non-malicious sub-packets and/or sessions. In one example, a network device includes a flow analysis module that receives a packet flow packets, each packet comprising a packet header and one or more sub-packets each corresponding to respective network sessions, an attack detection module that identifies at least one of the network sessions as a malicious network session, a policy action module that executes a policy action on the sub-packet corresponding to the malicious network session based on the identification of the malicious network session, and a forwarding component that forms a reconstructed packet comprising the packet header and the sub-packets excluding the sub-packet corresponding to the malicious network session and forwards the reconstructed packet.
AI classification
Ownership
JUNIPER NETWORKS, INC.
assignment · 224380793
Assignors
YANG, SIYING
On an employer assignment, the assignors are typically the inventors.