Method of configuring a policy of a network device, and appliance and method of applying object-oriented expressions in a policy
237 claims: 19 independent, 218 dependent
- 1REIVINDICAÇÕES 1. Método para configurar uma política de um dispositivo de rede com expressão orientada de objeto para especificar estrutura em uma carga útil de um fluxo de pacote recebido por um dispositivo de rede, o método compreendendo:(a) proporcionar uma interface de configuração para configurar uma política para um dispositivo de rede;(b) receber por via da interface de configuração, uma expressão para a política, a expressão identificando (i) uma classe de objeto para aplicar em uma parte da carga útil de um fluxo de pacote, e (ii) um membro da classe de objeto;e (c) receber, por via da interface de configuração, informação identificando uma ação para a política, a ação a ser adotada com base em uma avaliação da expressão.
- 2Método, de acordo com a reivindicação 1, em que a etapa (a) compreende proporcionar para um usuário, uma interface de configuração de linha de comando.
- 3Método, de acordo com a reivindicação 1, em que a etapa (a) compreende proporcionar para um usuário, uma interface de configuração compreendendo uma ou mais interfaces de arrastar e soltar, uma interface de seleção de lista, ou uma interface de realce de sintaxe.
- 4Método, de acordo com a reivindicação 1, em que a etapa (a) compreende a execução da interface de configuração em um dispositivo conectado ao dispositivo de rede.
- 5Método, de acordo com a reivindicação 1, em que a etapa (a) compreende executar a interface de configuração em um dispositivo de rede.
- 6Método, de acordo com a reivindicação 1, compreendendo adicionalmente receber, de um usuário, informação identificando um protocolo.
- 7Método, de acordo com a reivindicação 6, em que a etapa (b) compreende receber uma classe de objeto para aplicar em uma parte de uma carga útil de um fluxo de pacote, a classe de objeto correspondente ao protocolo identificado.
- 8Método, de acordo com a reivindicação 1, compreendendo adicionalmente receber, do usuário, informação identificando um protocolo a ser usado na interpretação de carga útil de um fluxo de pacote.
- 9Método, de acordo com a reivindicação 1, em que o membro da classe de objeto compreende um campo.
- 10Método, de acordo com a reivindicação 1, em que o membro da classe de objeto compreende um campo correspondente a uma segunda classe de objeto.
- 11Método, de acordo com a reivindicação 1, em que o membro da classe de objeto compreende um método.
- 12Método, de acordo com a reivindicação 1, em que o membro da classe de objeto é herdado de uma classe principal da classe de objeto.
- 13Método, de acordo com a reivindicação 1, em que a classe de objeto corresponde a uma solicitação HTTP.
- 14Método, de acordo com a reivindicação 1, em que a classe de objeto corresponde a uma solicitação HTTP, e o membro da classe de objeto compreende uma URL.
- 15Método, de acordo com a reivindicação 1, em que a classe de objeto corresponde a uma solicitação HTTP, e o membro da classe de objeto compreende um Cookie.
- 16Método, de acordo com a reivindicação 1, em que a classe de objeto corresponde a uma resposta HTTP.
- 17Método, de acordo com a reivindicação 1, em que a classe de objeto corresponde a um corpo de resposta HTTP, e o membro da classe de objeto corresponde a uma URL.
- 18Método, de acordo com a reivindicação 1, em que a etapa (b) compreende receber por via da interface de configuração, uma expressão para a política, a expressão identificando (i) uma classe de objeto para aplicar em uma parte da carga útil de um fluxo de pacote, (ii) um campo da classe de objeto, o campo correspondendo a uma segunda classe de objeto e (ii) um typecasting explícito do campo.
- 19Método, de acordo com a reivindicação 1, em que a etapa (b) compreende receber por via da interface de configuração, uma expressão para a política, a expressão identificando (i) uma classe de objeto para aplicar em uma parte de carga útil do fluxo de pacote, (ii) um método da classe de objeto, o método retornando um objeto correspondente a uma segunda classe de objeto, e (iii) um typecasting explícito do objeto retornado.
- 20Método, de acordo com a reivindicação 1, em que a etapa (c) compreende informação identificando uma ação para a política, a ação a ser adotada baseada em uma avaliação de uma regra contendo a expressão.
- 21Método, de acordo com a reivindicação 1, em que a ação especifica uma função direcionada para pelo menos um de:equilíbrio de carga, comutação de conteúdo, segurança de aplicação, distribuição de aplicação, aceleração de rede, e aceleração de aplicação.
- 22Método, de acordo com a reivindicação 1, em que a ação compreende uma URL no corpo da resposta HTTP.
- 23Método, de acordo com a reivindicação 1, em que a ação compreende uma expressão orientada de objeto.
- 24Método de aplicação em um computador de expressões orientadas de objeto em uma política para especificar estrutura em uma carga útil de um fluxo de pacote recebido pelo computador, o método compreendendo:(a) identificar, por um computador, uma política para avaliar com relação a uma carga útil de um fluxo de pacote recebido, a política especificando (i) uma classe de objeto para aplicar em uma parte da carga útil de um fluxo de pacote, (ii) um membro da classe de objeto e (ii) uma ação;(b) selecionar, pelo computador, uma parte da carga útil identificada pela classe de objeto;(c) determinar pelo computador, um valor para o membro da classe de objeto;e (d) adotar a ação em resposta ao valor determinado.
- 25Método, de acordo com a reivindicação 24, em que a política identifica um protocolo.
- 26Método, de acordo com a reivindicação 25, compreendendo adicionalmente analisar uma parte da carga útil de acordo com o protocolo identificado.
- 27Método, de acordo com a reivindicação 25, em que o protocolo é HTTP.
- 28Método, de acordo com a reivindicação 24, em que o membro da classe de objeto compreende um campo.
- 29Método, de acordo com a reivindicação 24, em que o membro da classe de objeto compreende um campo correspondente a uma segunda classe de objeto.
- 30Método, de acordo com a reivindicação 24, em que o membro da classe de objeto compreende um método.
- 31Método, de acordo com a reivindicação 24, em que o membro da classe de objeto é herdado de uma classe principal da classe de objeto.
- 32Método, de acordo com a reivindicação 24, em que a classe de objeto corresponde a uma solicitação HTTP.
- 33Método, de acordo com a reivindicação 24, em que a classe de objeto corresponde a uma solicitação HTTP e o membro da classe de objeto compreende uma URL.
- 34Método, de acordo com a reivindicação 24, em que a classe de objeto corresponde a uma solicitação HTTP, e o membro da classe de objeto compreende um cookie.
- 35Método, de acordo com a reivindicação 24, em que a classe de objeto corresponde a uma resposta HTTP.
- 36Método, de acordo com a reivindicação 24, em que a classe de objeto corresponde a um corpo de resposta HTTP, e o membro da classe de objeto corresponde a uma URL.
- 37Método, de acordo com a reivindicação 24, em que a etapa (c) compreende determinar, pelo computador, um valor para o membro da classe de objeto;e executar um typecasting explícito do valor determinado.
- 38Método, de acordo com a reivindicação 24, em que a etapa (d) compreende:avaliar a expressão com base no valor determinado: executar uma operação no valor determinado para produzir um resultado, e adotar a ação em resposta ao resultado produzido.
- 39Método, de acordo com a reivindicação 38, em que a operação compreende um de:E, OU, MAIOR DO QUE, MENOR DO QUE, IGUAIS, e NÃO IGUAIS.
- 40Método, de acordo com a reivindicação 24, em que a etapa (d) compreende executar uma ação direcionada para pelo menos um de:equilíbrio de carga, comutação de conteúdo, segurança de aplicação, distribuição de aplicação, aceleração de rede e aceleração de aplicação.
- 41Método, de acordo com a reivindicação 24, em que a etapa (d) compreende uma URL no corpo da resposta HTTP contida no fluxo de pacote.
- 42Computador para aplicar expressões orientadas de objeto em uma política para especificar estrutura de carga útil de um fluxo de pacote recebido pelo computador, o computador compreendendo:um processador de pacote que recebe um fluxo de pacote;e um mecanismo de política que identifica uma política para avaliar com relação a uma carga útil de um fluxo de pacote recebido, a política especificando (i) uma classe de objeto para aplicar em uma parte da carga útil do fluxo de pacote, (ii) um membro da classe de objeto e (iii) uma ação;selecionar uma parte da carga útil identificada pela classe de objeto;determinar um valor para um membro da classe de objeto;e adotar a ação em resposta ao valor determinado.
- 43Sistema, de acordo com a reivindicação 42, em que a política identifica um protocolo.
- 44Sistema, de acordo com a reivindicação 43, em que o mecanismo de política analisa uma parte da carga útil de acordo com o protocolo identificado.
- 45Sistema, de acordo com a reivindicação 43, em que o protocolo é HTTP.
- 46Sistema, de acordo com a reivindicação 42, em que o mem6 bro da classe de objeto compreende um campo.
- 47Sistema, de acordo com a reivindicação 42, em que o membro da classe de objeto compreende um campo correspondente a uma segunda classe de objeto.
- 48Sistema, de acordo com a reivindicação 42, em que o membro da classe de objeto compreende um método.
- 49Sistema, de acordo com a reivindicação 42, em que o membro da classe de objeto é herdado de uma classe principal da classe de objeto.
- 50Sistema, de acordo com a reivindicação 42, em que a classe de objeto corresponde a uma solicitação HTTP.
- 51Sistema, de acordo com a reivindicação 42, em que a classe de objeto corresponde a uma solicitação HTTP, e o membro da classe de objeto compreende uma URL.
- 52Sistema, de acordo com a reivindicação 42, em que a classe de objeto corresponde a uma solicitação HTTP, e o membro da classe de objeto corresponde a um cookie.
- 53Sistema, de acordo com a reivindicação 42, em que a classe de objeto corresponde a uma resposta HTTP.
- 54Sistema, de acordo com a reivindicação 42, em que a classe de objeto corresponde a um corpo de resposta, e o membro da classe de objeto corresponde a uma URL.
- 55Sistema, de acordo com a reivindicação 42, em que o mecanismo de política determina um valor para o membro da classe de objeto;e executa um typecasting explícito do valor determinado.
- 56Sistema, de acordo com a reivindicação 42, em que o mecanismo de política avalia a expressão com base no valor determinado;executa uma operação no valor determinado para produzir um resultado, e adota a ação em resposta ao resultado produzido.
- 57Sistema, de acordo com a reivindicação 38, em que a operação compreende uma de E, OU, MAIOR DO QUE, MENOR DO QUE, IGUAIS, e NÃO IGUAIS.
- 58Sistema, de acordo com a reivindicação 42, em que o mecanismo de política executa uma ação direcionada para pelo menos um de:equilíbrio de carga, comutação de conteúdo, segurança de aplicação, distribuição de aplicação, aceleração de rede, e aceleração de aplicação.
- 59Sistema, de acordo com a reivindicação 42, em que a ação de política re-escreve uma URL no corpo de uma resposta HTTP contida no fluxo de pacote.
- 60Método de aplicação em um computador de expressões orientadas de objeto em uma política para especificar estrutura em uma carga útil de um fluxo de pacote recebido pelo computador, o método compreendendo:(a) identificar pelo computador, uma política compreendendo uma expressão orientada de objeto para avaliar com relação a uma carga útil de um fluxo de pacote recebido;(b) atribuir, pela pluralidade, valores para uma estrutura de dados especificada pela expressão orientada de objeto com base em uma parte da carga útil;(c) executar pelo computador, uma avaliação da expressão com base nos valores atribuídos;e (d) adotar, em resposta à avaliação, uma ação especificada pela política.
- 61Método, de acordo com a reivindicação 60, em que a etapa (b) compreende aplicar, pelo computador, uma estrutura de dados especificada pela expressão orientada de objeto para um fluxo de byte da carga útil.
- 62Computador para aplicar expressões orientadas de objeto em uma política para especificar estrutura em uma carga útil de um fluxo de pacote recebido pelo computador, o computador compreendendo:um processador de pacote que recebe um fluxo de pacote;e;um mecanismo de política que identifica uma política compreendendo uma expressão orientada de objeto para avaliar com relação a uma carga útil do fluxo de pacote;atribuir valores para uma estrutura de dados especificada pela expressão orientada de objeto com base em uma parte da carga útil, executar uma avaliação da expressão com base nos valores atribuídos, e adotar, em resposta à avaliação, uma ação especificada pela política.
- 63Computador, de acordo com a reivindicação 62, em que o mecanismo de política aplica uma estrutura de dados especificada pela expressão orientada de objeto em um fluxo de byte da carga útil.
- 64Método de aplicação em um computador de expressões em uma política para especificar estrutura em uma carga útil de um floco recebido pelo computador, o método compreendendo:(a) identificar, pelo computador, uma política compreendendo uma expressão orientada de objeto para avaliar com relação a uma carga útil de um fluxo de pacote recebido;(b) atribuir, pelo computador, valores para uma estrutura de dados especificada pela expressão orientada de objeto com base em uma parte da carga útil;(c) executar, pelo computador, uma avaliação da expressão com base nos valores atribuídos;(d) alterar, em resposta à avaliação, uma parte do fluxo de pacote recebido;e (e) transmitir pelo computador, o fluxo de pacote alterado.
- 65Método, de acordo com a reivindicação 64, em que a política identifica um protocolo.
- 66Método, de acordo com a reivindicação 65, compreendendo adicionalmente analisar uma parte da carga útil de acordo com o protocolo identificado.
- 67Método, de acordo com a reivindicação 65, em que o protocolo é HTTP.
- 68Método, de acordo com a reivindicação 64, em que a expressão especifica uma classe de objeto correspondente a uma solicitação HTTP.
- 69Método, de acordo com a reivindicação 64, em que a expressão especifica uma classe de objeto correspondente a uma solicitação HTTP, e uma classe de objeto correspondente a uma URL.
- 70Método, de acordo com a reivindicação 64, em que a expressão especifica uma classe de objeto correspondente a um corpo de resposta HTTP, e uma classe de objeto correspondente a uma URL.
- 71Método, de acordo com a reivindicação 64, em que a etapa (d) compreende alterar uma parte do fluxo de pacote especificado pela estrutura de dados.
- 72Método, de acordo com a reivindicação 64, em que a etapa (d) compreende alterar uma parte do fluxo de pacote especificado em uma segunda expressão orientada de objeto.
- 73Método, de acordo com a reivindicação 64, em que a etapa (d) compreende re-escrever uma URL no corpo da resposta HTTP contida no fluxo de pacote.
- 74Método, de acordo com a reivindicação 64, em que a etapa (d) compreende ocultar um número de cartão de crédito contido no fluxo de pacote.
- 75Método, de acordo com a reivindicação 64, em que a etapa (d) compreende re-escrever uma URL em uma solicitação HTTP.
- 76Método, de acordo com a reivindicação 64, em que a etapa (d) compreende re-escrever um valor de campo de forma de uma resposta HTTP.
- 77Computador para aplicar expressões orientadas de objeto em uma política para especificar estrutura em uma carga útil de um fluxo de pacote recebido pelo computador, o computador compreendendo:um processador de pacote que recebe um fluxo de pacote;e um mecanismo de política que identifica uma política compreendendo uma expressão orientada de objeto para avaliar com relação a uma carga útil do fluxo de pacote recebido, atribui valores para uma estrutura de dados especificada pela expressão orientada de objeto com base em uma parte da carga útil;executa, pela pluralidade, uma avaliação da expressão com base nos valores atribuídos;altera, em resposta à avaliação, uma parte do fluxo de pacote recebido;e transmite o fluxo de pacote alterado.
- 78Computador, de acordo com a reivindicação 77, em que a política identifica um protocolo.
- 79Computador, de acordo com a reivindicação 78, compreendendo adicionalmente analisar uma parte da carga útil de acordo com o protocolo identificado.
- 80Computador, de acordo com a reivindicação 78, em que o protocolo é HTTP.
- 81Computador, de acordo com a reivindicação 77, em que a expressão especifica uma classe de objeto correspondente a uma solicitação HTTP.
- 82Computador, de acordo com a reivindicação 77, em que a expressão especifica uma classe de objeto correspondente a uma solicitação HTTP, e uma classe de objeto correspondente a uma URL.
- 83Computador, de acordo com a reivindicação 77, em que a expressão especifica uma classe de objeto correspondente a um corpo de solicitação HTTP, e uma classe de objeto correspondente a uma URL.
- 84Computador, de acordo com a reivindicação 77, em que o mecanismo de política altera uma parte do fluxo de pacote especificado pela estrutura de dados.
- 85Computador, de acordo com a reivindicação 77, em que o mecanismo de política altera uma parte do fluxo de pacote especificado por uma segunda expressão orientada de objeto.
- 86Computador, de acordo com a reivindicação 77, em que o mecanismo de política re-escreve uma URL no corpo de uma resposta HTTP contida no fluxo de pacote.
- 87Computador, de acordo com a reivindicação 77, em que o mecanismo de política oculta um número de cartão de crédito contido no fluxo de pacote.
- 88Computador, de acordo com a reivindicação 77, em que o mecanismo de política re-escreve uma URL em uma solicitação HTTP.
- 89Computador, de acordo com a reivindicação 77, em que o mecanismo de política re-escreve um valor de campo de forma de uma res11 posta HTTP.
- 90Método de configuração de um dispositivo de rede para especificar controle de fluxo dentre as políticas usadas no processamento de um fluxo de pacote, o método compreendendo:(a) proporcionar uma interface de configuração para configurar uma pluralidade de políticas de um dispositivo de rede, pelo menos uma política da pluralidade de políticas compreendendo um identificador de política;e (b) receber, por via da interface de configuração, informação identificando uma primeira política da pluralidade de políticas, a primeira política identificando (i) uma regra compreendendo uma primeira expressão e (ii) uma primeira ação a ser adotada com base em uma avaliação da regra;e (c) receber, por via da interface de configuração, informação identificando uma segunda política da pluralidade de políticas para aplicar subsequente à primeira política se a regra avaliar para verdadeiro.
- 91Método, de acordo com a reivindicação 90, em que a etapa (a) compreende proporcionar uma interface de configuração de linha de comando.
- 92Método, de acordo com a reivindicação 90, em que a etapa (a) compreende proporcionar uma interface de configuração compreendendo uma ou mais interfaces de arrastar e soltar, uma interface de seleção de lista, ou uma interface de realce de sintaxe.
- 93Método, de acordo com a reivindicação 90, em que a etapa (a) compreende executar a interface de configuração em um dispositivo em comunicação com o dispositivo de rede.
- 94Método, de acordo com a reivindicação 90, em que a etapa (a) compreende executar a interface de configuração no dispositivo de rede.
- 95Método, de acordo com a reivindicação 90, em que a primeira expressão é uma expressão orientada de objeto.
- 96Método, de acordo com a reivindicação 90, em que a primeira ação compreende nenhuma ação.
- 97Método, de acordo com a reivindicação 90, em que a primei12 ra ação especifica uma função executando uma de:equilíbrio de carga, comutação de conteúdo, segurança de aplicação, distribuição de aplicação, aceleração de rede, ou aceleração de aplicação.
- 98Método, de acordo com a reivindicação 90, em que a etapa (c) compreende receber um inteiro especificando um número de linha de uma segunda política.
- 99Método, de acordo com a reivindicação 90, em que a etapa (c) compreende receber um identificador de política especificando uma segunda política.
- 100Método, de acordo com a reivindicação 90, em que a etapa (c) compreende receber uma expressão orientada de objeto para avaliar em execução para especificar um número de linha de uma segunda política.
- 101Método, de acordo com a reivindicação 90, em que a etapa (c) compreende receber uma expressão orientada de objeto para ser avaliada em tempo real para especificar um número de linha de uma segunda política.
- 102Método, de acordo com a reivindicação 90, em que a pluralidade de políticas compreende um banco de política.
- 103Método, de acordo com a reivindicação 90, em que cada política da pluralidade de políticas compreende uma classificação de uma ordem de valor básico na qual as políticas serão processadas por um dispositivo de rede.
- 104Método de controle de fluxo dentre as políticas usadas em um dispositivo de rede processando um fluxo de pacote, o método compreendendo:(a) identificar, por um computador, uma pluralidade de políticas para aplicar em um fluxo de pacote recebido, pelo menos uma política da pluralidade de políticas compreendendo um identificador de política;(b) processar, pelo computador, uma primeira política da pluralidade de políticas, a primeira política identificando (i) uma regra compreendendo uma primeira expressão e (ii) uma primeira ação para ser adotada com base em uma avaliação da regra, e (iii) uma segunda política da plurali13 dade de políticas;(c) determinar, pelo computador, com base em uma avaliação a expressão, os cálculos da rede para verdadeiro;e (d) processar, pelo computador em resposta à determinação, a segunda política identificada.
- 105Método, de acordo com a reivindicação 104, em que a etapa (c) compreende avaliar uma expressão orientada de objeto.
- 106Método, de acordo com a reivindicação 104, compreendendo adicionalmente a etapa de executar, em resposta à determinação uma ação identificada pela primeira política.
- 107Método, de acordo com a reivindicação 104, compreendendo adicionalmente a etapa de executar, em resposta à determinação uma ação identificada pela primeira política; a ação compreendendo executar uma de:equilíbrio de carga, comutação de conteúdo, segurança de aplicação, distribuição de aplicação, aceleração de rede, ou aceleração de aplicação.
- 108Método, de acordo com a reivindicação 104, em que a primeira política compreende um inteiro especificando uma classificação de uma segunda política da pluralidade de políticas a ser processada a seguir se a primeira ação se aplicar.
- 109Método, de acordo com a reivindicação 104, em que a etapa (d) compreende avaliar, pelo computador, uma expressão para determinar uma classificação da segunda política da pluralidade de políticas a ser processada a seguir.
- 110Método, de acordo com a reivindicação 104, em que a etapa (d) compreende avaliar, pelo computador, uma expressão orientada de objeto para determinar uma classificação de uma segunda política da pluralidade de políticas a ser processada a seguir.
- 111Método, de acordo com a reivindicação 104, em que computador de políticas compreende um banco de política.
- 112Método, de acordo com a reivindicação 104, em que cada política compreende uma classificação para indicar uma ordem de valor bá14 sico na qual as políticas devem ser processadas.
- 113Método, de acordo com a reivindicação 104, compreendendo adicionalmente armazenar na lista, em resposta à determinação, uma ação identificada pela primeira política.
- 114Método, de acordo com a reivindicação 113, compreendendo adicionalmente armazenar, na lista, pelo menos outra ação identificada em pelo menos outra política sendo dotada de uma regra avaliada para verdadeira.
- 115Método, de acordo com a reivindicação 114, compreendendo adicionalmente executar cada ação armazenada na lista de ações.
- 116Computador para proporcionar controle de fluxo dentre políticas usadas em um dispositivo de rede processando um fluxo de pacote, o computador compreendendo:um processador de pacote que recebe um fluxo de pacote;e um mecanismo de política que identifica uma pluralidade de políticas para aplicar em um fluxo de pacote recebido, pelo menos uma política da pluralidade de políticas compreendendo um identificador de política, processa uma primeira política da pluralidade de políticas, a primeira política identificando (i) uma regra compreendendo uma primeira expressão e (ii) uma primeira ação a ser adotada com base em uma avaliação da regra, e (iii) uma segunda pluralidade de políticas;determinar, com base em uma avaliação da expressão, se a regra avalia para verdadeiro;e processar, por um computador em resposta à determinação, a segunda política identificada.
- 117Computador, de acordo com a reivindicação 116, em que o mecanismo de política avalia uma expressão orientada de objeto.
- 118Computador, de acordo com a reivindicação 116, em que o mecanismo de política executa, em resposta à determinação, uma ação identificada pela primeira política.
- 119Computador, de acordo com a reivindicação 116, em que o mecanismo de política executa, em resposta à determinação, uma ação identificada pela primeira política; a ação compreendendo executar uma de:equilíbrio de carga, comutação de conteúdo, segurança de aplicação, distribuição de aplicação, aceleração de rede, ou aceleração de aplicação.
- 120Computador, de acordo com a reivindicação 116, em que a primeira política compreende um inteiro especificando uma classificação de uma segunda política da pluralidade de políticas a ser processada a seguir se a primeira ação aplicar.
- 121Computador, de acordo com a reivindicação 116, em que o mecanismo de política avalia uma expressão para determinar uma classificação de uma segunda política da pluralidade de políticas a ser processada a seguir.
- 122Computador, de acordo com a reivindicação 116, em que o mecanismo de política avalia uma expressão orientada de objeto para determinar uma classificação de uma segunda política da pluralidade de políticas a ser processada a seguir.
- 123Computador, de acordo com a reivindicação 116, em que a pluralidade de políticas compreende um banco de política.
- 124Computador, de acordo com a reivindicação 116, em que cada política da pluralidade de políticas compreende uma classificação indicando uma ordem de valor básico na qual as políticas devem ser processadas.
- 125Computador, de acordo com a reivindicação 116, em que o mecanismo de política armazena em uma lista, em resposta à determinação, uma ação identificada pela primeira política.
- 126Computador, de acordo com a reivindicação 125, em que o mecanismo de política armazena, na lista, pelo menos outra ação, a pelo menos outra ação identificada em pelo menos outra política sendo dotada de uma regra avaliada para verdadeiro.
- 127Computador, de acordo com a reivindicação 126, em que o mecanismo de política executa cada ação armazenada na lista de ações.
- 128Método para configurar controle de fluxo dentre grupos de política usados em um dispositivo de rede processando um fluxo de pacote, o método compreendendo:(a) proporcionar uma interface de configuração para configurar uma pluralidade de grupos de política para um dispositivo de rede;(b) identificar, pela interface de configuração, uma primeira política de um grupo de política, a primeira política especificando uma regra compreendendo uma primeira expressão;e (c) receber, por via da interface, informação identificando um segundo grupo de política a ser processado com base em uma avaliação da regra.
- 129Método, de acordo com a reivindicação 128, em que a etapa (a) compreende proporcionar uma interface de configuração de linha de comando.
- 130Método, de acordo com a reivindicação 128, em que a etapa (a) compreende proporcionar uma interface de configuração compreendendo uma ou mais interface de arrastar e soltar, uma interface de seleção de lista, ou interface de realce de sintaxe.
- 131Método, de acordo com a reivindicação 128, em que a etapa (a) compreende executar a interface de configuração em um dispositivo de comunicação com o dispositivo de rede.
- 132Método, de acordo com a reivindicação 128, em que a etapa (a) compreende executar a interface de configuração no dispositivo de rede.
- 133Método, de acordo com a reivindicação 128, em que a etapa (a) compreende proporcionar para um usuário uma interface de configuração para criar uma pluralidade de grupos de política.
- 134Método, de acordo com a reivindicação 128, em que a primeira política especifica uma regra sendo dotada de uma expressão orientada de objeto.
- 135Método, de acordo com a reivindicação 128, em que a primeira política especifica uma ação a ser adotada em uma avaliação da regra.
- 136Método, de acordo com a reivindicação 128, em que a primeira política especifica uma ação adotada se a regra avaliar para verdadei17 ro; a ação compreendendo executar um de:equilíbrio de carga, segurança de aplicação, distribuição de aplicação, aceleração de rede, ou aceleração de aplicação.
- 137Método, de acordo com a reivindicação 128, em que a primeira política especifica uma segunda política do primeiro grupo de política a ser processado após o segundo grupo de política ser processado.
- 138Método, de acordo com a reivindicação 128, em que a etapa (c) compreende receber, por via da interface, informação identificando um segundo grupo de política a ser processado se a regra avaliar para verdadeiro.
- 139Método, de acordo com a reivindicação 128, em que a etapa (c) compreende receber, por via da interface, um rótulo a ser processado com base em uma avaliação da regra.
- 140Método de controle de fluxo dentre grupos de política usados em um dispositivo de rede processando um fluxo de pacote, o método compreendendo:(a) identificar, pela aplicação, um primeiro grupo de política para aplicar um fluxo de pacote recebido;(b) processar, pelo computador, uma primeira política do primeiro grupo de política, a primeira política identificando (i) uma regra compreendendo uma primeira expressão, e (ii) informação identificando um segundo grupo de política;(c) processar, pelo computador em resposta à avaliação da regra, o segundo grupo de política identificado.
- 141Método, de acordo com a reivindicação 140, em que a etapa (c) compreende avaliar uma expressão orientada de objeto.
- 142Método, de acordo com a reivindicação 140, em que a primeira política especifica uma ação a ser adotada em uma avaliação da regra.
- 143Método, de acordo com a reivindicação 140, compreendendo adicionalmente a etapa de executar, em resposta à determinação, a ação identificada pela primeira política.
- 144Método, de acordo com a reivindicação 140, em que a ação compreende executar uma de:equilíbrio de carga, comutação de conteúdo, segurança de aplicação, distribuição de aplicação, aceleração de rede, ou aceleração de aplicação.
- 145Método, de acordo com a reivindicação 140, compreendendo adicionalmente armazenar em uma lista, em resposta à determinação, a ação identificada pela primeira política.
- 146Método, de acordo com a reivindicação 145, compreendendo adicionalmente armazenar, na lista pelo menos outra ação, a pelo menos outra ação identificada em uma segunda política do segundo grupo de política.
- 147Método, de acordo com a reivindicação 145, compreendendo adicionalmente executar cada ação armazenada na lista de ações.
- 148Método, de acordo com a reivindicação 140, compreendendo adicionalmente, processar, pelo computador após o processamento do segundo grupo de política, uma segunda política do primeiro grupo de política.
- 149Método, de acordo com a reivindicação 140, compreendendo adicionalmente, processar, pelo computador, um terceiro grupo de política, o terceiro grupo de política identificado pela segunda política do segundo grupo de política.
- 150Método, de acordo com a reivindicação 140, compreendendo adicionaimente, processar, pelo computador, um terceiro grupo de política, o terceiro grupo de política identificado pela segunda política do primeiro grupo de política.
- 151Método, de acordo com a reivindicação 140, em que a primeira política especifica uma segunda política do primeiro grupo de política a ser processado após o segundo grupo de política ser processado.
- 152Método, de acordo com a reivindicação 151, compreendendo adicionaimente, processar pelo computador após o processamento do segundo grupo de política a segunda política.
- 153Computador proporcionando controle de fluxo dentre gru19 pos de política usados no processamento de um fluxo de pacote, o computador compreendendo:um processador de pacote que recebe um fluxo de pacote;e um mecanismo de política que identifica um primeiro grupo de política para aplicar em um fluxo de pacote recebido;processa uma primeira política do primeiro grupo de política, a primeira política identificando (i) uma regra compreendendo uma primeira expressão e ii) informação identificando um segundo grupo de política;avalia a regra;e processa, em resposta à avaliação da regra, o segundo grupo de política identificado.
- 154Computador, de acordo com a reivindicação 153, em que o mecanismo de política avalia uma expressão orientada de objeto.
- 155Computador, de acordo com a reivindicação 153, em que o mecanismo de política executa, em resposta à determinação, uma ação identificada pela primeira política.
- 156Computador, de acordo com a reivindicação 153, em que o mecanismo de política executa uma de:equilíbrio de carga, segurança de aplicação, distribuição de aplicação, aceleração de rede, ou aceleração de aplicação.
- 157Computador, de acordo com a reivindicação 153, em que o mecanismo de política armazena em uma lista, em resposta à determinação, uma ação identificada pela primeira política.
- 158Computador, de acordo com a reivindicação 153, em que o mecanismo de política armazena em uma lista peio menos outra ação, a pelo menos outra ação identificada em uma segunda política do segundo grupo de política.
- 159Computador, de acordo com a reivindicação 158, em que o mecanismo de política executa cada ação armazenada na lista de ações.
- 160Computador, de acordo com a reivindicação 153, em que o mecanismo de política processa, após o processamento do segundo grupo de política, uma segunda política do primeiro grupo de política.
- 161Computador, de acordo com a reivindicação 153, em que o mecanismo de política processa um terceiro grupo de política, o terceiro gru20 po de política identificado por uma política do segundo grupo de política.
- 162Computador, de acordo com a reivindicação 153, em que o mecanismo de política, após o processamento do segundo grupo de política, retoma o processamento do primeiro grupo de política.
- 163Computador, de acordo com a reivindicação 153, em que o mecanismo de política processa um terceiro grupo de política identificado pela segunda política do primeiro grupo de política.
- 164Computador, de acordo com a reivindicação 153, em que a primeira política especifica uma segunda política do primeiro grupo de política a ser processado após o segundo grupo de política ser processado.
- 165Computador, de acordo com a reivindicação 164, em que o mecanismo de política processa, após o processamento do segundo grupo de política, a segunda política.
- 166Método de configuração de uma política usada por um dispositivo de rede pela especificação de uma ação a ser adotada na eventualidade de um elemento da política estar indefinido, o método compreendendo:(a) proporcionar uma interface de configuração para configurar uma política de um dispositivo de rede: (b) identificar, pela interface de configuração, uma política compreendendo uma primeira ação a ser adotada com base em uma avaliação de uma expressão;(c) receber, por via da interface de configuração, informação identificando uma segunda ação para a política, a segunda ação a ser adotada se um elemento da política estiver indefinido.
- 167Método, de acordo com a reivindicação 166, em que a etapa (a) compreende proporcionar uma interface de configuração de linha de comando para configurar uma política de um dispositivo de rede.
- 168Método, de acordo com a reivindicação 166, em que a etapa (a) compreende proporcionar uma interface de configuração compreendendo uma ou mais interfaces de arrastar e soltar, uma interface de seleção, ou uma interface de realce de sintaxe.
- 169Método, de acordo com a reivindicação 166, em que a eta21 pa (a) compreende executar a interface de configuração em um dispositivo em comunicação com o dispositivo de rede.
- 170Método, de acordo com a reivindicação 166, em que a etapa (a) compreende executar a interface de configuração em um dispositivo em comunicação com o dispositivo de rede.
- 171Método, de acordo com a reivindicação 166, em que a etapa (a) compreende configurar, pelo usuário por via da interface de configuração, uma expressão orientada de objeto para a política.
- 172Método, de acordo com a reivindicação 166, em que a etapa (b) compreende receber, do usuário por via da interface de configuração, uma expressão para a política, a expressão sendo dotada de uma classe de objeto e de uma série de classe de objeto.
- 173Método, de acordo com a reivindicação 166, em que a segunda ação compreende nenhuma ação.
- 174Método, de acordo com a reivindicação 166, em que a segunda ação compreende bloquear a transmissão de uma parte do fluxo de pacote do dispositivo de rede.
- 175Método, de acordo com a reivindicação 166, em que pelo menos uma da primeira ação ou da segunda ação especifica uma função executando uma de:equilíbrio de carga, comutação de conteúdo, segurança de aplicação, distribuição de aplicação, aceleração de rede, ou aceleração de aplicação.
- 176Método, de acordo com a reivindicação 166, em que pelo menos uma da primeira ação e da segunda ação especifica re-escrever uma parte da carga útil do fluxo de pacote.
- 177Método, de acordo com a reivindicação 166, em que pelo menos uma da primeira ação e da segunda ação especifica re-escrever uma URL contida em uma resposta HTTP.
- 178Método, de acordo com a reivindicação 166, em que pelo menos uma da primeira ação e da segunda ação compreende uma expressão orientada de objeto.
- 179Método, de acordo com a reivindicação 166, em que a eta22 pa (c) compreende receber, por via da interface de configuração, informação identificando uma segunda ação para a política, a segunda ação a ser adotada se uma expressão da política estiver indefinida.
- 180Método, de acordo com a reivindicação 166, em que a etapa (c) compreende receber, por via da interface de configuração, informação identificando uma segunda ação para a política, a segunda ação a ser adotada se uma regra da política estiver indefinida.
- 181Método, de acordo com a reivindicação 166, em que a etapa (c) compreende receber, por via da interface de configuração, informação identificando uma segunda ação para a política, a segunda ação a ser adotada se a primeira ação da política estiver indefinida.
- 182Método de aplicação em um computador de uma política especificando uma ação a ser adotada na eventualidade de um elemento da política estiver indefinido, o método compreendendo:(a) identificar, por um computador, uma política para avaliar com relação a uma carga útil de um fluxo de pacote recebido, a política especificando (i) uma expressão, (ii) uma primeira ação a ser adotada com base em uma avaliação da expressão e (iii) uma segunda ação a ser adotada se um elemento da política estiver indefinido;(b) determinar, pelo computador, se um elemento da política está indefinido com relação à carga útil;e (c) adotar, pelo computador em resposta à determinação, a segunda ação.
- 183Método, de acordo com a reivindicação 182, em que a etapa (b) compreende avaliar uma expressão orientada de objeto.
- 184Método, de acordo com a reivindicação 182, em que a etapa (b) compreende avaliar uma expressão sendo dotada de uma classe de objeto e um membro da classes de objeto.
- 185Método, de acordo com a reivindicação 182, em que a etapa (b) compreende determinar, pelo computador, se a expressão está indefinida com relação ao fluxo de pacote.
- 186Método, de acordo com a reivindicação 182, em que a eta23 pa (b) compreende determinar, pelo computador, uma regra da política está indefinida.
- 187Método, de acordo com a reivindicação 182, em que a etapa (b) compreende determinar, pelo computador, a primeira ação da política está indefinida.
- 188Método, de acordo com a reivindicação 182, em que a etapa (c) compreende adotar nenhuma ação.
- 189Método, de acordo com a reivindicação 182, em que a etapa (c) compreende bloquear transmissão do fluxo de pacote do computador.
- 190Método, de acordo com a reivindicação 182, em que a etapa (c) compreende executar uma de;equilíbrio de carga, comutação de controle, segurança de aplicação, distribuição de aplicação, aceleração de rede, ou aceleração de aplicação.
- 191Método, de acordo com a reivindicação 182, em que a etapa (c) compreende re-escrever uma parte da carga útil do fluxo de pacote.
- 192Método, de acordo com a reivindicação 182, em que a etapa (c) compreende re-escrever uma URL contida em uma resposta HTTP.
- 193Computador que possibilita que os usuários especifiquem uma ação a ser adotada na eventualidade de uma expressão contida em uma política não puder ser avaliada pelo computador, o computador compreendendo:um processador de pacote que recebe um fluxo de pacote;e um mecanismo de política que identifica uma política para avaliar com relação à carga útil do fluxo de pacote recebido, a política especificando (i) uma expressão, ii) uma primeira ação a ser adotada com base na avaliação da expressão e (iii) uma segunda ação a ser adotada se a expressão não for avaliada com sucesso;determinar que a expressão não possa ser avaliada com sucesso com relação ao fluxo de pacote;e adotar a segunda ação.
- 194Computador, de acordo com a reivindicação 193, em que o mecanismo de política avalia uma expressão orientada de objeto.
- 195Computador, de acordo com a reivindicação 193, em que o mecanismo de política avalia uma expressão sendo dotada de uma classe de objeto e de um membro da classe de objeto.
- 196Computador, de acordo com a reivindicação 193, em que a segunda ação compreende nenhuma ação.
- 197Computador, de acordo com a reivindicação 193, em que a segunda ação compreende bloquear uma parte de um fluxo de pacote.
- 198Computador, de acordo com a reivindicação 193, em que pelo menos uma da primeira ação e da segunda ação especifica uma função direcionada a pelo menos uma de:equilíbrio de carga, comutação de conteúdo, distribuição de aplicação, aceleração de rede, e aceleração de aplicação.
- 199Computador, de acordo com a reivindicação 193, em que pelo menos uma da primeira ação ou da segunda ação especifica a reescrita de uma parte da carga útil do fluxo de pacote.
- 200Computador, de acordo com a reivindicação 193, em que pelo menos uma da primeira ação ou da segunda ação especifica a reescrita de uma URL contida na resposta HTTP.
- 201Computador, de acordo com a reivindicação 193, em que o mecanismo de política determina que a expressão está indefinida com relação ao fluxo de pacote.
- 202Computador, de acordo com a reivindicação 193, em que o mecanismo de política determina que uma regra da política está indefinida com relação ao fluxo de pacote.
- 203Computador, de acordo com a reivindicação 193, em que o mecanismo de política determina que a primeira seção está indefinida com relação ao fluxo de pacote.
- 204Método para configurar um ou mais perfis de segurança de aplicação para um dispositivo, cada perfil de segurança de aplicação especificando um número de funções de segurança executando verificações relacionadas a uma aplicação, o método compreendendo:(a) proporcionar uma interface de configuração para configurar um perfil de segurança de aplicação;(b) receber, por via da interface de configuração, um primeiro ajuste, o ajuste especificando correspondência para uma primeira verificação do perfil de segurança de aplicação;(c) receber, por via da interface de configuração, um segundo ajuste, o segundo ajuste especificando correspondência para uma segunda verificação do perfil de segurança de aplicação;(d) identificar, pela interface de configuração, uma política, a política especificando uma regra compreendendo uma primeira expressão;e (e) receber, por via da interface, informação identificando o perfil de segurança de aplicação a ser processado com base em uma avaliação da regra.
- 205Método, de acordo com a reivindicação 204, em que a etapa (a) compreende proporcionar uma interface de configuração de linha de comando.
- 206Método, de acordo com a reivindicação 204, em que a etapa (a) compreende proporcionar uma interface de configuração compreendendo uma ou mais interfaces de arrastar e soltar, uma interface de seleção de lista, ou interface de realce de sintaxe.
- 207Método, de acordo com a reivindicação 204, em que a etapa (a) compreende executar a interface de configuração em um dispositivo em comunicação com o dispositivo de rede.
- 208Método, de acordo com a reivindicação 204, em que a etapa (a) compreende executar a interface de configuração no dispositivo de rede.
- 209Método, de acordo com a reivindicação 204, em que a etapa (a) compreende proporcionar, para um usuário, uma interface de configuração para criar uma pluralidade de perfis de aplicação.
- 210Método, de acordo com a reivindicação 204, em que a etapa (b) compreende receber, por via da interface de configuração, uma URL para ser usada pela primeira verificação.
- 211Método, de acordo com a reivindicação 204, em que a etapa (b) compreende receber, por via da interface de configuração, uma ex26 pressão especificando uma ou mais URLs a serem usadas pela primeira verificação.
- 212Método, de acordo com a reivindicação 204, em que a etapa (b) compreende receber, por via da interface de configuração, uma expressão orientada de objeto especificando uma ou mais URLs para ser usada pela primeira verificação.
- 213Método, de acordo com a reivindicação 204, em que a etapa (d) compreende identificar, por via da interface de configuração, política sendo dotada de uma expressão orientada de objeto.
- 214Método, de acordo com a reivindicação 204, em que pelo menos uma da primeira verificação e segunda verificação realizam uma de:detecção de injeção SQL, detecção de URL de início inválida, detecção de adulteração de cookie, detecção de consistência de campo de forma, detecção de estouro de isolador, detecção de roteiro de lugar cruzado, detecção de número de cartão de credito, e detecção de URL inválida.
- 215Método, de acordo com a reivindicação 204, em que pelo menos uma da primeira verificação e segunda verificação realizam uma de:bloqueio de injeção SQL, bloqueio de URL de início inválida, bloqueio de adulteração de cookie, bloqueio de campo de forma inconsistente, bloqueio de estouro de isolador, bloqueio de roteiro de lugar transversal, bloqueio de número de cartão de crédito, e bloqueio de URL inválida.
- 216Método, de acordo com a reivindicação 204, compreendendo adicionalmente armazenar o perfil de segurança de aplicação.
- 217Método, de acordo com a reivindicação 204, compreendendo adicionalmente transmitir o perfil de segurança de aplicação para um dispositivo de rede.
- 218Método para executar em um computador um ou mais perfis de segurança de aplicação, cada perfil de segurança de aplicação especificando um número de grupos de política executando funções de segurança relacionados a uma aplicação, o método compreendendo:(a) identificar, por um computador, uma primeira política para aplicar em um fluxo de pacote;a primeira política especificando uma regra compreendendo uma primeira expressão e identificando um perfil de segurança de aplicação;(b) avaliar a regra pelo computador;(c) processar, pelo computador em resposta a uma avaliação da regra, uma primeira verificação especificada pelo perfil de segurança de aplicação;e (d) processar, pelo computador em resposta à avaliação da regra, uma segunda verificação especificada pelo perfil de segurança de aplicação.
- 219Método, de acordo com a reivindicação 218, em que o computador compreende um dispositivo Proxy VPN.
- 220Método, de acordo com a reivindicação 218, em que a etapa (a) compreende identificação, por um computador, uma primeira política para aplicar em um fluxo de pacote TCP recebido.
- 221Método, de acordo com a reivindicação 218, em que a etapa (b) compreende avaliação, pelo computador, uma expressão orientada de objeto da regra.
- 222Método, de acordo com a reivindicação 218, em que a etapa (c) compreende avaliar pelo menos um ajuste da primeira verificação para determinar se aplica ou não a primeira verificação.
- 223Método, de acordo com a reivindicação 218, em que a etapa (c) compreende determinar que uma URL contida no fluxo de pacote combina pelo menos um ajuste da primeira verificação, e aplicar a primeira verificação em resposta a uma determinação.
- 224Método, de acordo com a reivindicação 218, em que a etapa (c) compreende determinar que uma URL contida no fluxo de pacote combina uma expressão de um ajuste da primeira verificação, e aplicar a primeira verificação em resposta à determinação.
- 225Método, de acordo com a reivindicação 218, em que a etapa (c) compreende determinar que uma URL contida no fluxo de pacote combina uma expressão orientada de objeto de um ajuste da primeira verificação, e aplicar a primeira verificação em resposta à determinação.
- 226Método, de acordo com a reivindicação 218, em que pelo menos uma da primeira verificação e segunda verificação executa uma de:detecção de injeção SQL, detecção de URL de início inválida,detecção de adulteração de cookie, detecção de consistência de campo da forma, detecção de estouro de isolador, detecção de roteiro de lugar transversal, detecção de número de cartão de crédito, e detecção de URL inválida.
- 227Método, de acordo com a reivindicação 218, em que pelo menos uma da primeira verificação e segunda verificação executa uma de:bloqueio de injeção de SQL, bloqueio de URL de início inválido, bloqueio de adulteração de cookie, bloqueio de campo de forma inconsistente, bloqueio de estouro de isolador, bloqueio de roteiro de lugar transversal, bloqueio de cartão de crédito, e bloqueio de URL inválida.
- 228Computador para executar um ou mais perfis de segurança de aplicação para um dispositivo, cada perfil de segurança de aplicação especificando um numero de grupos de política executando funções de segurança relacionadas a uma aplicação, o computador compreendo:um processador de pacote que recebe um fluxo de pacote;e um mecanismo de política em comunicação com o processador de pacote que identifica uma primeira política para aplicar no fluxo de pacote recebido;a primeira política especificando uma regra compreendendo uma primeira expressão e identificando um perfil de segurança de aplicação;calcular a regra;processar, em resposta a uma avaliação da regra, uma primeira verificação especificada pelo perfil de segurança de aplicação;e processar, em resposta à avaliação da regra, uma segunda verificação especificada pelo perfil de segurança de aplicação.
- 229Computador, de acordo com a reivindicação 228, em que o computador compreende um dispositivo Proxy VPN.
- 230Computador, de acordo com a reivindicação 228, em que o mecanismo de política identifica uma primeira política para aplicar em um fluxo de pacote TCP recebido.
- 231Computador, de acordo com a reivindicação 228, em que o mecanismo de política avalia uma expressão orientada de objeto da regra.
- 232Computador, de acordo com a reivindicação 228, em que o mecanismo de política avalia pelo menos um ajuste de uma primeira verificação para determinar se aplica a primeira verificação.
- 233Computador, de acordo com a reivindicação 228, em que o mecanismo de política determina que uma URL contida no fluxo de pacote combine pelo menos um ajuste da primeira verificação, e aplica a primeira verificação em resposta à determinação.
- 234Computador, de acordo com a reivindicação 228, em que o mecanismo de política determina que uma URL contida no fluxo de pacote combine uma expressão de um ajuste da primeira verificação, e aplica a primeira verificação na determinação.
- 235Computador, de acordo com a reivindicação 228, em que o mecanismo de política determina que uma URL contida no fluxo de pacote combine uma expressão orientada de objeto de um ajuste da primeira verificação, e aplica a primeira verificação em resposta à determinação.
- 236Computador, de acordo com a reivindicação 228, em que pelo menos uma da primeira verificação e segunda verificação execute uma de:detecção de injeção SQL, detecção de URL de início inválida, detecção de adulteração de cookie, detecção de consistência de campo de forma, detecção de estouro de isolador, detecção de roteiro de lugar cruzado, detecção de número de cartão de crédito, e detecção de URL inválida.
- 237Computador, de acordo com a reivindicação 228, em que pelo menos uma da primeira verificação e segunda verificação execute uma de:bloqueio de injeção SQL, bloqueio de URL de início inválida, bloqueio de adulteração de cookie, bloqueio de campo de forma inconsistente, bloqueio de estouro de isolador, bloqueio de roteiro de lugar cruzado, bloqueio de número de cartão de crédito, e bloqueio de URL inválida. 1/27 cliente 102η FIG. 1A servidor ιοβη 2/27 cliente 102η FIG. 1B servidor 106η 3/27 ©ΟΙ rol cliente 102η FIG. 1C servidor ιθθη 4/27 servidor 106A 5/27 CM co CM CO O O «CD O CD ω CD o CL /) 4—· ω _c Ό Cl) “O to CO O , . , dispositivo teclado apontador LU O 6/27 7/27 programas de Q/27 aplicação 200 cliente 102 modo de usuário 303 App 1 $/27 App 2 1st program 322 App N 310a interceptor 350 cliente de fluxo contínuo network stack 267 -------♦> estrutura de dados 325 agente coletor 304 SSL VPN aaent 308 mecanismo de otimização de rede 250 agente de aceleração 302 310b modo kernel 302
Independent claims237
318 paragraphs in 2 sections, as filed
(54) Title: SYSTEMS AND METHODS FOR (57) Summary:
CONFIGURE, APPLY AND MANAGE SECURITY POLICIES (30) Unionist Priority: 12/03/2007 us 11 / 685,147,
12/03/2007 US 11 / 685,167, 03/12/2007 US 11 / 685,171, 03/12/2007
US 11 / 685,175, 3/12/2007 US 11 / 685,177, 3/12/2007 US
11 / 685,180 (73) Owner (s): Citrix Systems, INC.
(72) Inventor (s): Abhushek Chauhan, Anoop Reddy, Namit Sikka, Prakash Khemani, Rajiv Mirani, Vamsimohan Korrapati (74) Attorney (s): Dannemann, Siemsen, Bigler & Ipanema Moreira (86) International application: pct US2008056671 de 12/03/2008 (87) International Publication: wo 2008 / 112769of 18/09/2008
<img file="BRPI0808859A2_D0001.tif" />
Invention Patent Descriptive Report for SYSTEMS AND METHODS FOR CONFIGURING, APPLYING AND MANAGING SECURITY POLICIES.
Related Order
The present order is related to and claims the priority of the following pending US Orders, the descriptions of which are fully incorporated into the present by way of reference: Systems and Methods for Providing Structured Policy Expressions to Represent Unstructured Data in a NetWork Appliance, US Order N<sup>2</sup> 11 / 685,147, filed on March 12, 2007; Systems and Methods for Using Object Oriented Expressions to Configure Application Security Policies Order US N<sup>2 </sup>11 / 685,167, filed on March 12, 2007; Systems and Methods for Configuring Flow Control of Policy Expressions; US Application No. 11 / 685,171, filed March 12, 2007; Systems and Methods for Configuring Policy bank Invocations Order US N<sup>2</sup> 11 / 685,180, filed on March 12, 2007; Systems and Methods for Configuring Handling of Undefined Policy Events US Application No. 11 / 685,175, filed March 12, 2007; and Systems and Methods for Managing Application Security Profiles US Application No. 11 / 685,177, filed March 12, 2007.
Field of the Invention
The present invention relates to computer network technologies. Specifically, the present invention relates to systems and methods for configuring and enforcing policies and adjustments on network devices. Background of the Invention
Network devices and clients can provide a number of complex functions with respect to network traffic. Among other functions, network devices can provide load balancing, application security, content switching, SSL downloading, acceleration and cache. However, as the number and complexity of functions provided by network devices grows, so can the complexity and amount of configuration required for a network device. In addition, improper or suboptimal configuration of a network device can result in decreased performance, network errors, application incompatibility, and weakened security.
Many network devices can use a policy framework to control the functions of the network device. In these structures, a policy can specify a rule and an action that dictate behavior under certain conditions. For example, with HTTP traffic, a policy framework can allow a user to configure device behavior based on content within the HTTP stream. These policies can become complex depending on the content to be analyzed and the behaviors sought. Thus, a policy framework may be required that allows a user to apply the framework for network traffic in order to record policies to target device behavior. Similarly, a network device is needed that can then implement such structured policy expressions in an efficient manner.
In addition, as the number of network device functions increases, you can also increase the number of policies required for your configurations. With an increase in the number of policies, it is also necessary to specify and implement processing orders within policies and policy groups.
In addition, some desired policies used on network devices are not always endowed with definite results. For example, a policy can specify behavior in response to a given field in an HTTP request, but it can be undefined in cases where the field is not present or the field has an unexpected value. While it may be possible in some cases to record policies that are always defined, this may require additional policies or more complex policies and may add extra administrative code. Therefore, configuration systems are needed that allow a user to specify one or more actions in the event that a policy is undefined.
Brief Summary of the Invention
The present invention relates to systems and methods for configuring and evaluating policies that control the processing of one or more data streams. A configuration interface is described to allow users to specify object-oriented policies. These object-oriented policies can allow any data structures to be applied with respect to a payload of a received packet flow, including any parts of HTTP traffic. A configuration interface can also allow the user to control the order in which policies and policy groups are executed, in addition to specifying actions to be taken if one or more policies are undefined. Systems and methods for processing policies can enable efficient processing of object-oriented policies by applying potentially complex data structures to unstructured data flows. A device can also interpret and process a series of flow control commands and policy group invocation statements to determine an order among a series of policies and policy groups. These policy settings and processing can allow a user to efficiently configure complex network behaviors related to load balancing, VPNs, SSL offloading, content switching, application security, acceleration and caching.
In one aspect, the present invention relates to systems and methods of configuring a network device policy with an object-oriented expression to specify structure in a payload of a packet flow received by a network device. In one embodiment, the method comprises providing a configuration interface for configuring a policy for a network device; receive, via the configuration interface, an expression for the policy, the expression identifying (i) an object class to apply a portion of the payload of a packet flow, and (ii) a member of the object class; and receive, via the configuration interface, information identifying an action for the policy, the action to be taken based on an evaluation of the expression.
In a second aspect, the present invention relates to the systems and methods for applying object-oriented expression in a policy to specify structure in a payload of a packet flow received by the computer. In one embodiment, a method comprises: identifying, by a computer, a policy to evaluate with respect to a payload of the received packet flow, the policy specifying (i) an object class to apply a part of the payload of a flow package, (ii) a member of the object class and (iii) an action; select, by the computer, a part of the payload identified by the object class; determine, by the computer, a value for the member of the object class; and act in response to the determined value. In another modality, a method comprises: identifying, through the computer, a policy comprising an object-oriented expression to evaluate with respect to a payload of a received packet flow; assign, by computer, values to a data structure specified by the object-oriented expression based on a part of the payload; perform, by the computer, an expression evaluation based on the assigned values; and, in response to the assessment, act as specified by the policy. Corresponding systems may include a packet processor for receiving packet streams and a policy mechanism for evaluating one or more object-oriented policies and acting in concert.
In a third aspect, the present invention relates to systems and methods for applying object-oriented expressions in a policy to specify structure in a payload of a packet flow received by the computer. In one embodiment, a method comprises, identifying, by a computer, a policy comprising an object-oriented expression to evaluate with respect to a payload of a received packet flow, assigning, by the computer, values to a data structure specified by object-oriented expression based on a portion of the payload; perform, by the computer, an expression evaluation based on the assigned values, change, in response to the evaluation, a part of the received packet flow; and transmit the changed packet flow through the computer. Corresponding systems may include a packet processor for receiving and transferring the packet flow and a policy mechanism for evaluating one or more object-oriented policies and acting in an associated manner.
In a fourth aspect, the present invention relates to systems and methods for configuring and / or processing a policy used by a network device specifying an action to be taken in the event that an element of the policy is undefined. In one embodiment, the method comprises: providing a configuration interface to configure a policy for a network device, identifying, through the configuration interface, a policy comprising a first action to be taken based on an evaluation of an expression; receive, via the configuration interface, information identifying a second action for the policy, the second action to be taken if an element of the policy is undefined. In another modality, a method of applying a policy identifying an action to be taken in the event that an element of the policy is undefined comprises: identifying, by a computer, a policy to assess with respect to a payload of a received packet flow , the policy specifying (i) an expression, (ii) a first action to be taken based on an evaluation of the expression and (iii) a second action to be taken if an element of the policy is undefined; determine, by a computer, that an element of the policy is undefined with respect to the payload; and, through the computer in response to the determination, begin to act on the second action. Corresponding systems can include a packet processor to receive a packet flow, and a policy mechanism to evaluate one or more policies and begin to act in an associated manner.
In a fifth aspect, the present invention relates to systems and methods for configuring and / or processing flow control among the policies used in the processing of a packet flow. In one embodiment, a method comprises: providing a configuration interface for configuring a plurality of policies from a network device, at least one policy from a plurality of policies comprising a policy identifier; and receive, via the configuration interface, information identifying a first policy of the plurality of policies, the first policy identifying (i) a rule comprising a first expression and (ii) a first action to be taken based on an evaluation of the rule; and receiving, via the configuration interface, information identifying a second policy from the plurality of policies to apply subsequent to the first policy if the rule evaluates to rectify. In another embodiment, a method includes: to identify, by a computer, a plurality of policies to apply in a received packet flow, at least one policy of the plurality of policies comprising a policy identifier, to process, by the computer, a first policy of the plurality of policies, the first policy identifying ( i) a rule comprising a first expression and (ii) a first action to be taken based on an assessment of the rule, and (iii) a second policy of the plurality of policies; determine, by the computer based on an expression evaluation, the rule evaluates to rectify; and process, by computer in response to the determination, the second policy identified. Corresponding systems can include a packet processor to receive a packet flow, and a policy mechanism to evaluate one or more policies and begin to act in an associated manner.
In a sixth aspect, the present invention relates to systems and methods for configuring and / or processing flow control among the policy groups used on a network device processing a packet flow. In one embodiment, a method comprises: providing a configuration interface for configuring a plurality of policy groups for a network device; identify, through the configuration interface, a first policy from a first policy group, the first policy specifying a rule comprising a first expression; and receive, via the interface, information identifying a second policy group to be processed based on an evaluation of the rule. In another embodiment, a method comprises: identifying, by a computer, a first policy group to apply to a received packet flow; computer processing a first policy from the first policy group, the first policy identifying (i) a rule comprising a first expression, and (ii) information identifying a second policy group; evaluate, through the computer, the rule; and processing, via the computer in response to the rule's assessment, the second identified policy group. Corresponding systems may include: a packet processor to receive a packet flow and a policy mechanism to evaluate one or more policies and start to act in an associated manner.
In a seventh aspect, the present invention relates to systems and methods for configuring and / or processing one or more application security profiles for a device, each application security profile specifying a series of checks on the performance of security functions related to the application. In one embodiment, a method comprises: providing a configuration interface to configure an application security profile; receive, via the configuration interface, a first adjustment, the adjustment specification corresponding to a first verification of the application security profile; receive, via the configuration interface, a second adjustment, the second adjustment specification corresponding to a second verification of the application security profile; identify, through the configuration interface, a policy, the policy specifying a rule comprising a first expression; and receive, via the interface, information identifying the application security profile to be processed based on an evaluation of the rule. In another embodiment, a method may comprise identifying, by a computer, a first policy to apply to a received packet flow; the first policy specifying a rule comprising a first expression and identifying a computer's security profile; evaluate, through the computer, the rule; process, via the application in response to the rule assessment, a first check specified by the application security profile; and processing, via the computer in response to the rule assessment, a second check specified by the application security profile. Corresponding systems may include a packet processor for receiving a flow and a policy mechanism for evaluating one or more application security profiles and starting to act in an associated manner.
Details of the various modalities of the invention are reported in the accompanying drawings and in the description below.
Brief Description of the Drawings
The background and other objectives, aspects, characteristics and advantages of the invention will become clear and better understood by reference to the description that follows taken in combination with the accompanying drawings, in which:
Figure 1A is a block diagram of a modality of a network environment for a client to access a server via a computer;
Figure 1B is a block diagram of another embodiment of a network environment for distributing a computing environment from a server to a client via a plurality of computers;
Fig. 1 is a block diagram of another modality of a network environment for distributing a computing environment from a server to a client via one or more different computers;
Figure 1D is a block diagram of an environment modality for distributing a computing environment from a server to a client over a network;
Figures 1E and 1F are block diagrams of modalities of a computing device;
Figure 2A is a block diagram of a computer embodiment for processing communications between a client and a server;
Figure 2B is a block diagram of another modality of a computer for optimizing, accelerating, balancing load and communications to apportion communications between a client and a server;
Figure 3 is a block diagram of a modality for a client to communicate with a server via a computer;
Figure 4A is a diagram of an exemplary object model that can be used to structure HTTP communications;
Figure 4B is an example documentation screen for an object model that can be used to structure HTTP communications;
Figure 4C illustrates a series of exemplary object-oriented expressions related to HTTP communications;
Figure 5 illustrates an example of a policy;
Figure 6 is an example screen that can be used to configure one or more expressions;
Figure 7 is an example screen of a configuration interface that can be used to configure policies for a network device;
Figure 8 is a block diagram of a modality of a configuration interface running on a client;
Figure 8A is a flow diagram of an embodiment of a method for configuring a policy expression;
Figure 8B is a flow diagram of a method for processing object-oriented expression on a network computer;
Figure 8C is a flow diagram of an embodiment of a method for using object oriented expressions to rewrite parts of a received packet flow;
Figure 9 is a flow diagram of an embodiment of a method for executing undefined policy elements;
Figure 10A is a diagram of an example of a policy bank modality;
Figure 10B is a flow diagram of an embodiment for controlling order of processing in a group of policies;
Figure 11A is a block diagram of a processing order control modality among a plurality of policy groups;
Figure 11B is a block diagram of a modality of a processing order control method among a plurality of policy groups;
Figure 12 illustrates a series of exemplary configuration screens that can be used to configure an application security profile;
Figure 13A is a flow diagram of an embodiment of a method for configuring an application security profile; and
Figure 13B is a flow diagram of an embodiment of a method for processing an application security profile.
The features and advantages of the present invention will become clear from the detailed description below when taken in combination with the drawings, in which similar reference characters identify corresponding elements throughout. In the drawings, similar reference numbers generally indicate identical elements, similar functionality, and / or structurally similar.
Detailed Description of the Invention
For the purposes of reading the description below of the various modalities of the present invention, the following description of the sections of the report and their respective contents may be useful:
Section A describes a network environment and a computing environment useful for practicing an embodiment of the present invention;
Section B describes modalities of a computer system and architecture to accelerate the distribution of a computing environment to a remote user;
Section C describes ways for a client agent to speed up communication between a client and a server;
Section D describes systems modalities and methods for configuring and using object-oriented expressions;
Section E describes modalities of systems and methods for executing undefined policy expressions;
Section F describes modalities of systems and methods for configuring and using policy groups; and
Section G describes system modalities and methods for configuring and using application security profiles.
A. Network and Computing Environment
Before commenting on the specifications of the modalities of the systems and methods of a computer and / or client, it may be useful to comment on the network and computing environments in which these modalities can be organized. Referring to figure 1A, a modality of a network environment is described. In a brief overview, the network environment comprises one or more 102a-102n clients (also commonly referred to as a local 102 machine (s), or 102 client (s)) communicating with one or more 106a-106n servers (also generally referred to as server (s) 106, or remote machine (s) 106) via one or more networks 104, 104 '(generally referred to as network 104). In some embodiments, a client 102 communicates with a server 106 via an application 200.
Although figure 1A illustrates a network 104 and a network 104 'between clients 102 and servers 106, clients 102 and servers 106 can be on the same network 104. Networks 104 and 104' can be the same type of network or different types of network. Network 104 and / or network 104 'can be a local area network (LAN), such as a company intranet, a metropolitan area network (MAN), or a wide area network (WAN), such as the Internet or the World Wide Web. In one embodiment, network 104 'can be a private network and network 104 can be a public network. In some embodiments, network 104 may be a private network and network 104 'may be a public network. In another embodiment, networks 104 and 104 'can be private networks. In some embodiments, customers 102 may be located in a branch of an incorporated company communicating via a WAN connection over network 104 with servers 106 located in an embedded data center.
Network 104 and / or 104 'can be of any type and / or form of network and can include any of the following: a point-to-point network, a broadcast network, a wide area network, a local area network , a telecommunications network, a data communication network, a computer network, an ATM (Asynchronous Transfer Mode) network, a SONET (Synchronous Optical Network) network, an SDH (Synchronous Digital Hierarchy) network, a wireless network and a wired network. In some embodiments, network 104 may comprise a wireless link, such as, for example, an infrared channel or satellite band. The network topology 104 and / or 104 'can be a bus, star, or ring network topology. The network 104 and / or 104 'and the network topology can be of any network or network topology as known to those skilled in the art capable of supporting the operations described herein.
As shown in Figure 1A, computer 200, which can also be referred to as an interface unit 200 or port 200 is illustrated between networks 104 and 104 '. In some embodiments, computer 200 may be located on network 104. For example, a branch of an incorporated company may organize a computer 200 in the branch. For example, a computer 200 may be located in an embedded data center. In yet another embodiment, a plurality of computers 200 may be organized on the network 104. In some embodiments, a plurality of computers 200 may be arranged on the network 104 '. In one embodiment, a first computer 200 communicates with a second computer 200 '. In another embodiment, computer 200 may be part of any client 102 or server 106 on the same or different network 104, 104 'as client 102. One or more computers 200 can be located anywhere on the network or network communications path between a client 102 and a server 106.
In some embodiments, computer 200 comprises any network devices manufactured by Citrix Systems, Inc., of Ft. Lauderdale, Florida, referred to as the NetScaler Citrix device. In other embodiments, computer 200 may include any of the product modalities referred to as Web Accelerator and Biglp manufactured by F5 Networks, Inc. of Seattle, Washington. In another embodiment, computer 205 includes any of the DX accelerator device platforms and / or SSL, VPN series of devices, such as the SA 700, SA 2000, SA 4000, and SA 6000 devices manufactured by Juniper Networks , Inc. of Sunnyvale, California. In yet another embodiment, computer 200 includes any application acceleration and / or security-related computers and / or software manufactured by Cisco Systems, Inc. San Jose, California, such as the Cisco ACE Application Control Engine Module and Cisco AVS Series Application Velocity System service module software and network modules.
In one embodiment, the system may include multiple logically grouped servers 106. In those embodiments, the logical group servers may be referred to as server site 38. In some of these modalities, servers 106 may be geographically dispersed. In some cases, a site 38 can be administered as a single entity. In other embodiments, the server site 38 comprises a plurality of server sites 38. In one embodiment, the server site runs one or more applications on behalf of one or more clients 102.
Servers 106 within each server site 38 can be heterogeneous. One or more of the 106 servers may operate according to a type of operating system platform (for example, WINDOWS NT, manufactured by Microsoft Corp. of Redmond, Washington), while one or more of the 106 servers may operate according to a type of operating system platform (for example, Unix or Linux). The servers 106 at each site 38 do not need to be physically close to another server 106 at the same site 38. Therefore, the group of servers 106 logically grouped as a site 38 can be interconnected using wide area network (WAN) or network connection. medium area network (MAN). For example, a site 38 may include servers 106 physically located on different continents or different regions of a continent, country, state, city, campus, or dependency. Data transmission speeds between servers 106 at site 38 can be increased if servers 106 are connected using a local area network (LAN) connection or some form of direct connection.
Servers 106 can be referred to as a file server, application server, web server, proxy server, or port server. In some embodiments, a server 106 may be provided with the ability to function either as an application server or as a master application server. In one embodiment, a server 106 may include an Active Directory. Customers 102 can also be referred to as customer nodes or endpoints. In some embodiments, a client 102 has the ability to function both as a client node seeking access to applications on a server and as an application server providing access to hosted applications for other clients 102a-102n.
In some embodiments, a client 102 communicates with a server 106. In one embodiment, client 102 communicates directly with one of the servers 106 at a site 38. In another embodiment, client 102 runs a program proximity application to communicate with a server 106 at a site 38. In yet another embodiment, server 106 provides the functionality of a master node. In some embodiments, client 102 communicates with a server 106 on site 38 over a network 104. On network 104, client 102 can, for example, request the execution of several applications hosted by servers 106a through 106n on the site 38 and receive output from application performance results to display. In some embodiments, only the master node can provide the functionality required to identify and provide address information associated with the server 106 'hosting a requested application.
In one embodiment, server 106 provides functionality of a web server. In another embodiment, server 106a receives requests from client 102, transfers requests to a second server 106b and responds to requests by client 102 with a response to requests from server 106b. In yet another embodiment, server 106 acquires an enumeration of the applications available to the client 102 and address information associated with a server 106 that hosts an application identified by the application enumeration. In yet another embodiment, server 106 presents the response to the request to client 102 using a web interface. In one embodiment, client 102 communicates directly with server 106 to access the identified application. In another embodiment, client 102 receives application exit data, such as display data, generated by the performance of the application identified on server 106.
Fig. 1B describes an embodiment of a network environment developing multiple computers 200. A first computer 200 can be developed on a first network 104 and a second computer 200 'can on a second network 104'. For example, an incorporated company may develop a first computer 200 in a branch and a second computer 200 'in a data center. In another embodiment, the first computer 200 and the second computer 200 'are developed on the same network 104. For example, a first computer 200 can be developed for a first server site 38, and a second computer 200 can be developed for a second server site 38 '. In another example, the first computer 200 can be developed in a branch while the second computer 200 'is developed in a second branch'. In some embodiments, the first computer 200 and the second computer 200 'work in cooperation or in combination with each other to accelerate network traffic or the transfer of application and data between a client and a server.
Figure 1C describes another embodiment of a network environment by developing computer 200 with one or more other types of computers, such as between one or more WAN optimization computers 205, 205 '. For example, a first WAN 205 optimization computer between networks 104 and 104 'is illustrated and a second WAN optimization computer 205' can be developed between computer 200 and one or more servers 106. As an example, an incorporated company can develop a first WAN 205 optimization computer in a branch and a second WAN 205 'optimization computer in a data center. In some embodiments, computer 205 may be located on network 104 '. In other embodiments, computer 205 'may be located on network 104. In some embodiments, computer 205' may be located on network 104 'or network 104. In one embodiment, computer 205 and 205' are on the same network. In another embodiment, computer 205 and 205 'are on different networks. In another example, a first WAN 205 optimization computer can be developed for a first server site 38 and a second WAN optimization computer 205 'for a second server site 38'.
In one embodiment, computer 205 is a device for accelerating, optimizing or otherwise improving the performance, operation, or quality of service of a type and form of network traffic to and / or a WAN connection. In some embodiments, computer 205 is a performance-enhancing proxy. In other embodiments, computer 205 is any type and form of WAN optimization or acceleration device, sometimes referred to as a WAN optimization controller. In one embodiment, computer 205 is any of the product embodiments referred to as WANScaler manufactured by Citrix Systems, Inc. of Ft. Lauderdale, Florida. In other embodiments, computer 205 includes any of the product modalities referred to as the BIG-IP and WANjet link controller manufactured by F5 Networks, Inc. of Seattle, Washington. In other embodiments, computer 205 includes any WX and WXC accelerator device platforms manufactured by Juniper Networks, Inc. from Sunnyvale, California. In some embodiments, the 205 computer includes any steel-tipped line of WAN optimization computers manufactured by Riverbed Technology of San Francisco, California. In other embodiments, computer 205 includes any of the related WAN devices manufactured by Expand Networks Inc. of Roseland, New Jersey. In one embodiment, computer 205 includes any WAN-related computers manufactured by Packeteer Inc. Cupertino, California, such as the PacketShaper, iShared, and SkyX product modalities provided by Packeteer. In yet another embodiment, computer 205 includes any WAN-related computers and / or software manufactured by Cisco systems, Inc. of San Jose, California, such as area network application services software and network modules Wide Cisco and Wide Area Network engine computers.
In one embodiment, computer 205 provides application and data acceleration services for branch or remote offices. In one embodiment, computer 205 includes optimization of Wide Area File Services (WAFS). In other modalities, computer 205 speeds up the distribution of files, such as, for example, via the Common Internet File System (CIFS) protocol. In other embodiments, computer 205 provides cache in memory and / or storage to speed up application and data distribution. In one embodiment, computer 205 provides compression of network traffic at any level of the network stack or any protocol or network layer. In another embodiment, computer 205 provides transport layer protocol optimizations, flow control, performance increases and / or modifications and / or management to accelerate application and data distribution over a WAN connection. For example, in one embodiment, computer 205 provides Transport Control Protocol (TCP) optimizations. In other embodiments, computer 205 provides optimizations, flow control, performance increases and / or modifications and / or management for any application layer session or protocol.
In another embodiment, computer 205 encoded any type and form of data or information in custom or standard TCP and / or IP initial record fields or network packet option fields to announce the presence, functionality or capability of another computer 205 ' . In another embodiment, a computer 205 'can communicate with another computer 205' using data encoded both in TCP and in the initial record fields or IP options. For example, the computer can use the TCP option (s) or initial registration fields or IP options to communicate one or more parameters to be used by computers 205, 205 'in the performance of functionality, such as WAN acceleration, or to work in combination with each other.
In some embodiments, computer 200 preserves any information encoded in TCP and / or initial record and / or IP option fields communicated between computers 205 and 205 '. For example, computer 200 may terminate a transport layer connection by traversing computer 200, such as, for example, a transport layer connection between computers 205 and 205 'traversing a client and a server. In one embodiment, computer 200 identifies and preserves any information encoded in a transport layer packet transmitted by a first computer 205 via a first transport layer connection and communicates a transport layer packet with information encoded to a second computer 205 'via a second transport layer connection.
Figure 1D depicts a network environment for distributing and / or operating a computing environment on a client 102. In some embodiments, a server 106 includes an application delivery system 190 for delivering a computing environment or an application and / or data file for one or more clients 102. In a brief overview, a client 10 is communicating with a server 106 via network 104, 104 'and computer 200. For example, client 102 can reside in a remote office of a company, for example, a branch, and server 106 can reside in an embedded data center. Client 102 comprises a client agent 120, and a computing environment 15. Computing environment 15 can run or operate an application that accesses, processes, or uses a data file. The computing environment 15, the application and / or the data file can be distributed via computer 200 and / or server 106.
In some embodiments, computer 200 accelerates the delivery of a computing environment 15, or any part thereof, to a customer 102. In one embodiment, computer 200 accelerates the delivery of computing environment 15 through the application delivery system 190 . For example, the modalities described here can be used to accelerate the distribution of a streamable application and processable data file by applying a centrally embedded data center to a remote user location, such as a company branch. In other embodiments, computer 200 accelerates transport layer traffic between a client 102 and a server 106. The computer 200 can provide acceleration techniques to accelerate any transport layer payload from a server 106 to a client 102, such as: 1) transport layer connection fusion, 2) transport layer connection multiplexing , 3) use of transport control protocol temporary memory, 4) compression and 5) cache. In some embodiments, computer 200 provides load balancing of servers 106 in response to requests from clients 102. In other embodiments, computer 200 acts as a proxy or access server to provide access to one or more servers 106. In another embodiment , computer 200 provides a secure virtual private network connection from a first network 104 of the client 102 to the second network 104 'of the server 106, such as, for example, an SSL VPN connection. In yet another embodiment, computer 200 provides firewall application security, control and management of the connection and communication between a client 102 and a server 106.
In some embodiments, the application distribution management system 190 provides application distribution techniques for distributing a computing environment to a user's desktop, remote or otherwise, based on a plurality of performance methods and based on in any authentication and authorization policies applied via a policy mechanism 195. With these techniques, a remote user can obtain a computing and access environment for applications stored on the server and data files from a connected 100 network device. In one embodiment, application distribution system 190 can reside or run a server 106. In another embodiment, application delivery system 190 may reside or run on a plurality of servers 106a through 106n. In some embodiments, the application delivery system 190 can run on server site 38. In one embodiment, the server 106 running the application delivery system 190 can also store the application and the data file. In another embodiment, a first set of one or more servers 106 can run application distribution system 190, and a different server 106n can store or provide the application and data file. In some embodiments, each application distribution system 190, the application, and the data file may reside or be located on different servers. In yet another embodiment, any part of the application distribution system 190 can reside, execute, or be stored on or distributed to computer 200, or a plurality of computers.
Client 102 may include a computing environment 15 to run an application that uses or processes a data file. Client 102 via networks 104, 104 'and computer 200 can request an application and data file from server 106. In one embodiment, computer 200 can transfer a request from client 102 to server 106. For example, the client 102 may not have the application and data file stored or accessible on site. In response to the request, application distribution system 190 and / or server 106 can distribute the application and data file to client 102. For example, in one embodiment, server 106 can transmit the application as a stream of application to operate in the computing environment 15 on client 102.
In some embodiments, the application distribution system 190 comprises any part of Citrix Access Suite ™ by Citrix Systems, Inc., such as, for example, MetalFrame or Citrix Presentation Server ™ and / or any of the Microsoft® Windows Terminal Services manufactured by Microsoft Corporation. In one embodiment, the application delivery system 190 may deliver one or more applications to customers 102 or users via a remote display protocol or otherwise via remote based or remote based computing. In another embodiment, the application delivery system 190 can deliver one or more applications to customers or users via continuous application flow.
In one embodiment, application delivery system 190 includes a policy mechanism 195 for controlling and managing access to, selection of application performance methods, and application distribution. In some embodiments, policy mechanism 195 may terminate to one or more applications that a user or client 102 may access. In another embodiment, policy mechanism 195 determines how the application is to be distributed to the user or client 102, for example, the performance method. In some embodiments, the application distribution system 190 provides a plurality of distribution techniques from which to select a system performance method, such as, for example, streaming or application distribution locally to the customer 120 for local performance.
In one embodiment, a client 102 requests the performance of an application program and the application distribution system 190 comprising a server 106 selects an application program performance method. In some embodiments, server 106 receives credentials from client 102. In another embodiment, server 106 receives a request for an enumeration of available applications from client 102. In one embodiment, in response to requesting or receiving credentials, the application distribution system 190 lists a plurality of application programs available to the client 102. The application distribution system 190 receives a request to run an enumerated application. The application delivery system 190 selects one of a predetermined series of methods to execute the enumerated request, for example, in response to a policy from a policy mechanism. The application distribution system 190 can select an application performance method that enables the client 102 to receive application output data generated by the performance of the application program on a server 106. The application delivery system 190 may select an application performance method that enables the local mechanism 10 to execute the application program on the spot after receiving a plurality of application files comprising the application. In yet another embodiment, the application distribution system 190 can select an application performance method to flow the application via the network 104 to the client 102.
A client 102 can run, operate or otherwise offer an application22, which can be any type and / or form of executable software, program, or instructions such as any type and / or form of web browser, client web-based, client server application, a thin computing client, an Active X control, or a Java utility, or any other type and / or form of executable instructions capable of executing on the 102 client. In some embodiments, the application can be a server-based or remote-based application that runs on behalf of client 102 on a server 106. In one embodiment, server 106 can display output to client 102 using any thin client or protocol. remote display, such as the Independent Computing Architecture (ICA) protocol manufactured by Citrix Systems, Inc. of Ft. Lauderdale, Florida or the Remote Desktop Protocol (RDP) manufactured by the Microsoft Corporation of Redmond, Washington. The application can be any type of protocol and can be, for example, an HTTP client, an FTP client, an Oscar client, or a Telnet client. In other modalities, the application comprises any type of software related to VoiP communications, such as, for example, a smooth IP phone. In additional modalities, the application includes any application related to real-time data communications, such as, for example, applications for streaming video and / or audio.
In some embodiments, server 106 or a server site 38 may be running one or more applications, such as, for example, an application providing thin client computing or remote display presentation applications. In one embodiment, server 106 or server site 38 runs as an application, any part of Citrix Access Suite ™ by Citrix Systems, Inc., such as, for example, MetaFrame or Citrix Presentation Server ™, and / or any Services Microsoft® Windows terminals manufactured by Microsoft Corporation. In one embodiment, the application is an iCA client, developed by Citrix Systems, Inc. of Ft. Lauderdale, Florida. In other ways, the application includes a Remote Desktop (RDP) client, developed by Microsoft Corporation of Redmond, Washington. In addition, server 106 can run an application, which, for example, can be an application server providing email services such as Microsoft Exchange, manufactured by Microsoft Corporation of Redmond, Washington, a web or Internet server, or a server sharing a desktop, or a collaboration server. In some embodiments, any application may comprise any type of hosted service or product, such as GoToMeeting ™ provided by Citrix Online Division Inc. of Santa Barbara, California, WebEX ™ provided by WebEx, Inc. of Santa Clara, California, or Microsoft Office Live Meeting provided by Microsoft Corporation of Redmond, Washington.
Still with reference to figure 1D, a network environment modality can include a monitoring server 106A. The 106A monitoring server may include any type and form of performance monitoring service 198. The performance monitoring service 198 may include monitoring, measurement and / or management software and / or hardware, including data collection, aggregation, analysis , management and reporting. In one embodiment, the performance monitoring service 198 includes one or more monitoring agents 197. Monitoring agent 197 includes any software, hardware or combination of these to perform monitoring, management and data collection activities on a device, such as , for example, a client 102, server 106 or a computer 200, 205. In some embodiments, the monitoring agent 197 includes any type or form of script, such as, for example, a Visual Basic script, or Java script. In one embodiment, the monitoring agent 197 runs transparently for any application and / or user of the device. In some embodiments, monitoring agent 197 is installed and operated without obstruction for the application or customer. In yet another embodiment, monitoring agent 197 is installed and operated without any instrumentation for the application or device.
In some modalities, the monitoring agent 197 monitors, measures and collects data at a predetermined frequency. In other modalities, the monitoring agent 197 monitors, measures and collects data24 based on the detection of any type or form of event. For example, the monitoring agent 197 can collect data when it detects a request for a web page or receives an HTTP response. In another example, monitoring agent 197 can collect data when detecting any user input events. The monitoring agent 197 can report or provide any data monitored, measured or collected to the monitoring service 198. In one embodiment, the monitoring agent 197 transmits information to the monitoring service 198 according to a predetermined schedule or frequency. In another embodiment, monitoring agent 197 transmits information to monitoring service 198 when detecting an event.
In some modalities, the monitoring service 198 and / or the monitoring agent 197 performs the monitoring and performance measurement of any network resource or network infrastructure element, such as a client, server, server site, computer 200, computer 205, or network connection. In one embodiment, the monitoring service 198 and / or the monitoring agent 197 performs the monitoring and performance measurement of any transport layer connection, such as, for example, a TCP or UDP connection. In another embodiment, the monitoring service 198 and / or the monitoring agent 197 monitors and measures network latency. In yet another modality, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the bandwidth utilization.
In other modalities, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the end user response times. In some modalities, the monitoring service 198 performs the monitoring and measures an application. In another modality, the monitoring service and / or the monitoring agent
197 performs the monitoring and performs measurement of any session or connection to the application. In one modality, the monitoring service
198 and / or the monitoring agent 197 monitors and measures the performance of a browser. In another embodiment, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the performance of HTTP-based transactions. In some modalities, the monitoring agent 197 monitors and measures the performance of a Voice over an application or IP session (VolP). In other embodiments, the monitoring service 198 and / or monitoring agent 197 monitors and measures the performance of a remote display protocol application, such as, for example, an ICA client or an RDP client. In yet another modality, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the performance of any type or form of continuous flow medium. In yet another modality, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the performance of a hosted application or a Software As A Service (SaaS) distribution model.
In some modalities, the monitoring service 198 and / or the monitoring agent 197 performs the monitoring and performance measurement of one or more transactions, requests or responses related to the application. In other modalities, the monitoring service 198 and / or the monitoring agent 197 monitors and measures any part of an application layer stack, such as, for example, any .NET or J2EE calls. In one embodiment, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the database or SQL transactions. In yet another modality, the monitoring service 198 and / or the monitoring agent 197 monitors and measures any method, function, or application programming interface (API) call.
In one embodiment, the monitoring service 198 and / or the monitoring agent 197 performs the monitoring and measurement performance of an application and / or data distribution from a server to a client via one or more computers, such as, for example, a computer 200 and / or application 205. In some embodiments, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the distribution performance of a virtual application. In other modalities26, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the distribution performance of a streaming application. In another embodiment, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the performance of the distribution of a desktop application to a client and / or the execution of a desktop application on the client. In another embodiment, the monitoring service 198 and / or the monitoring agent 197 monitors and measures the performance of a client / server application.
In one embodiment, monitoring service 198 and / or monitoring agent 197 is designed and built to provide application performance management for application distribution system 190. For example, monitoring service 198 and / or the agent Monitoring System 197 can monitor, measure and manage application distribution performance via the Citrix Presentation Server. In this example, monitoring service 198 and / or monitoring agent 197 monitors individual ICA sessions. Monitoring service 198 and / or monitoring agent 197 can measure total system usage and per session, as well as application and network performance. The monitoring service 198 and / or the monitoring agent 197 can identify the active servers for a given user and / or user session. In some embodiments, the monitoring service 198 and / or the monitoring agent 197 monitors the final rear connections between the application distribution system 190 and an application and / or database server. The monitoring service 198 and / or the monitoring agent 197 can measure network latency, delay and volume per user session or ICA session.
In some modalities, the monitoring service 198 and / or the monitoring agent 197 measures and monitors the memory usage for the application distribution system 190, such as, for example, the total memory usage, per user session and / or by process. In other modalities, the monitoring service 198 and / or the monitoring agent 197 measures and monitors the CPU usage of the application distribution system 190, such as, for example, the total CPU usage, per user session and / or per process. In another modality, the monitoring service 198 and / or the monitoring agent 197 measures and monitors the time required to enter the system for an application, a server, or the application distribution system, such as, for example, the Citrix presentation. In one embodiment, the monitoring service 198 and / or the monitoring agent 197 measures and monitors the duration of a user within an application, a server, or in the application distribution system 190. In some embodiments, the monitoring service 198 and / or the monitoring agent 197 measures and monitors the active and inactive session counts for an application, a server or an application distribution system session. In yet another modality, the monitoring service 198 and / or the monitoring agent 197 measures and monitors user session latency.
In yet another modality, the monitoring service 198 and / or the monitoring agent 197 measures and monitors the measures and monitors any type and form of server metrics. In one embodiment, the monitoring service 198 and / or the monitoring agent 197 measures and monitors metrics related to the memory system, CPU usage, and disk storage. In another modality, the monitoring service 198 and / or the monitoring agent 197 measures and monitors metrics related to page faults per second. In other modalities, the monitoring service 198 and / or the monitoring agent 197 measures and monitors the circular travel time metrics. In yet another modality, the monitoring service 198 and / or the monitoring agent 197 measures and monitors metrics related to breaks, errors and / or modes of an application.
In some embodiments, monitoring service 198 and monitoring agent 197 include any of the product modalities referred to as EdgeSight manufactured by Citrix Systems, Inc. of Ft. Lauderdale, Florida. In another embodiment, monitoring service 197 and / or monitoring agent 198 includes any part of the product modalities referred to as the True View product suite manufactured by Symphoniq Corporation of Paio Alto, California. In one embodiment, the monitoring service 197 and / or the monitoring agent 198 includes any part of the product modalities referred to as the TeaLeaf CX product suite manufactured by TeaLeaf Technology Inc. of San Francisco, California. In other embodiments, the monitoring service 198 and / or the monitoring agent 197 includes any part of the company's service management products, such as the BMC Performance Manager and Patrol products, manufactured by BMC Software, Inc., Houston, Texas.
Client 102, server 106, and computer 200 can be developed and / or executed on any type and form of computing device, such as, for example, a computer, network device or application capable of communicating any type or form of network and perform the operations described here. Figures 1E and 1F depict block diagrams of a computing device 100 useful for practicing a client 102, server 106 or computer 200 embodiment. As shown in figures 1E and 1F, each computing device 100 includes a central processing unit 101, and a main memory unit 122. As illustrated in figure 1E, a computing device 100 may include a visual display device 124, a keyboard 126 and / or a pointing device 127, such as a mouse. Each computing device 100 may include additional optional elements, such as, for example, one or more input / output devices 13a-130b (generally referred to using numeric reference 130), and a cache memory 140 in communication with the central processing unit 101.
Central processing unit 101 is any logic circuit that responds to and processes instructions retrieved from main memory unit 122. In many embodiments, the central processing unit is provided by a microprocessor unit, such as: those manufactured by Intel Corporation of Mountain View, California; those manufactured by Motorola Corporation of Schamburg, Illinois; a29 those manufactured by Transmeta Corporation of Santa Clara, California, the RS / 6000 processor, those manufactured by International Business Machines of White Plains, New York. Or those manufactured by Advanced Micro Devices from Sunnyvale, California. Computing device 100 can be based on any of these processors, or any other processor capable of operating as described herein.
Main memory unit 122 may be one or more memory chips capable of storing data and allowing any storage location to be directly accessed by microprocessor 101, such as, for example, Static random access memory (SRAM), intermittent SRAM or SRAM SynchBurst (BSRAM), Dynamic Random Access Memory (DRAM), DRAM Quick Page Mode (FPM DRAM), Enhanced DRAM (EDRAM), Extended Data Output RAM (EDO RAM), Extended Data Output DRAM (EDO DRAM), Intermittent Extended Data Output DRAM (BEDO DRAM), Enhanced DRAM (EDRAM), Synchronous DRAM (SDRAM), JEDEC SRAM, PC100 SDRAM, Dual Data Rate SDRAM (DDR SDRAM ), Enhanced SDRAM (ESDRAM), DRAM Synclink (SLDRAM), DRAM Rambus Direct (DRDRAM), or Ferroelectric RAM (FRAM). Main memory 122 can be based on any of the memory chips described above, or any other available memory chips capable of operating as described herein. In the embodiment illustrated in Figure 1E, processor 101 communicates with main memory 122 via a system bus 150 (described in more detail below). Figure 1E describes an embodiment of a computing device 100 in which the processor communicates directly with main memory 122 via a memory port 103. For example, in figure 1F, main memory 122 can be DRDRAM.
Fig. 1F describes a mode in which the main processor 101 communicates directly with the cache memory 140 via a secondary bus, sometimes referred to as a rear bus. In other embodiments, main processor 101 communicates directly with cache 140 using the system bus
150. Cache memory 140 typically has a faster response time than main memory 122 and is typically provided by SRAM, BSRAM or EDRAM. In the embodiment illustrated in figure 1E, processor 101 communicates with various Input / Output devices 130 via a local system bus 150. Multiple buses can be used to connect the central processing unit 101 to any of the Input / Output devices 130, including a VESA VL bus, an ISA bus, an EISA bus, a Microchannel Architecture (MCA) bus, a PCI bus, a PCl-X bus, a PCI Express bus, or a NuBus bus. For modes in which the Input / Output device is a video monitor 124, processor 101 can use an Advanced Graphics Port (AGP) to communicate with monitor 124. Figure 1F describes a mode of a computer 100 in which main processor 101 communicates directly with the Input / Output device via HyperTransport, Fast Input / Output, or InfiniBand. Figure 1F also describes a modality in which local buses and direct communications are mixed: processor 101 communicates with the Input / Output device 130 using a local interconnect bus while communicating directly with the communication device. Input / Output 130.
Computing device 100 can support any suitable installation device 116, such as a floppy drive for receiving floppy disks, such as 8.89 cm (3.5 inch) floppy disks, 13.33500 cm (3, 5 inches), or ZIP diskettes, a CD-ROM drive, a CDR / RW drive, a DVD-ROM drive, tape drives of various shapes, USB device, hard drive or any device suitable for installing software and programs, such as any client agent 120, or part of it. The computing device 100 may also comprise a storage device 128, such as, for example, one or more hard drives or redundant arrangements of independent disks, for storing an operating system and other related software, and for storing software programs application, such as any program related to client agent 120. Optionally, any of the installation devices 116 can be used as the storage device 128. Additionally, the operating system and the software can run from a bootable medium, for example, a bootable CD, such as, for example, KNOPPIX®, a Bootable CD for GNU / Linux that is available as GNU / Linux distribution from Knoppix.net.
In addition, computing device 100 may include a network interface 118 to interface to a Local Area Network (LAN), Wide Area Network (WAN) or the Internet through a variety of connections including, but not limited to , standard phone lines, LAN or WAN links (for example, 802.11, Ti, T3, 56kb, X.25), broadband connections (for example, ISDN, Frame Relay, ATM), wireless connections, or some combination of any or all of the above. The network interface 118 may comprise a built-in network adapter, a network interface card, a PCMCIA network card, a card bus network adapter, a wireless network adapter, a USB network adapter, modem or any other device suitable for interfacing computing device 100 to any type of network capable of communicating and performing the operations described herein. A wide variety of Input / Output devices 130a through 130n can be present in computing device 100. Input devices include keyboards, mice, trackpads, trackballs, microphones, and drawing graphics tables. Output devices include video monitors, speakers, inkjet printers, laser printers, and dye sublimation printers. Input / Output devices 130 can be controlled by an Input / Output controller 123 as shown in figure 1E. The Input / Output controller can control one or more Input / Output devices, such as the keyboard 126 and the pointing device 127, for example, a mouse or an optical pen. In addition, an Input / Output device may also provide storage 128 and / or an installation medium 116 for computing device 100. In yet another embodiment, computing device 100 may provide USB connections for receiving manual USB storage devices such as USB Flash Drive wire from devices manufactured by Twintech Industry, Inc. of Los Alamitos, California.
In some embodiments, computing device 100 may comprise or be connected to multiple display devices 124a through 124n, whose cache may be of the same type or shape and / or of a different type or shape. As such, any of the devices 130a through 130n and / or the Input / Output controller 123 may comprise any type and / or form of suitable hardware, software or combinations of hardware and software to support, enable or provide the connection and use of the multiple display devices 124a through 124n by computing device 100. For example, computing device 100 can include any type and / or form of video adapter, video card, driver, and / or library to interface, communicate, connect or otherwise use display devices 124a through 124n. In one embodiment, a video adapter may comprise multiple connectors to interface with multiple display devices 124a through 124n. In other embodiments, computing device 100 may include multiple display adapters, with each display adapter connected to one or more display devices 124a through 124n. In some embodiments, any part of the operating system of computing device 100 can be configured to use multiple devices 124a through 124n. In other embodiments, one or more of the display devices 124a through 124n can be provided by one or more computing devices, such as, for example, computing devices 100a and 100b connected to computing device 100, for example, via a network. The modalities can include any type of software designed and built to use another computer display device as a second display device 124a for computing device 100. One skilled in the art will recognize and appreciate the various ways and modalities in which a computing device 100 can be configured to be provided with multiple display devices 124a through 124n.
In additional embodiments, an Input / Output device can be a bridge 170 between the system bus 150 and an external communication bus, such as a USB bus, an Apple Desktop bus, an RS-232 serial connection, a SCSI bus, a FireWire bus, an 800 FireWire bus, an Ethernet bus, an AppIeTalk bus, a Gigabit Ethernet bus, an Asynchronous Transfer Mode bus, a HIPPI bus, a Super HIPPI bus, a SerialPIus bus, a SCI / LAMP bus, a FibreChannel bus, or a Serial Attached small computer system interface bus.
A computing device 100 of the type described in figures 1E and 1F typically operates under the control of the operating systems, which control the schedule of tasks and access to system resources. Computing device 100 can be running any operating system, such as any version of Microsoft® Windows operating systems, different versions of Unix and Linux systems, any version of Mac OS® for Macintosh computers, any system built-in operating system, any real-time operating system, any open source operating system, any proprietary operating system, any operating system for mobile computing devices, or any other operating system capable of executing on the computing device and performing the operations described herein. Typical operating systems include: WINDOWS 3.x, WINDOWS 95, WINDOWS 98, WINDOWS 2000, WINDOWS NT 3.51, WINDOWS NT 4.0, WINDOWS CE, and WINDOWS XP, all of which are manufactured by the Microsoft Corporation of Redmond, Washington; MacOS, manufactured by Apple Computer of Cupertino, California; OS / 2, manufactured by International Business Machines of Armonk, New York, and Linux, a freely available operating system distributed by Caldera Corp. Salt Lake city, Utah, or any type and / or form of a Unix operating system, among others.
In other embodiments, computing device 100 may be provided with different processors, operating systems, and input devices consistent with the device. For example, in one embodiment, computer 100 is a Treo 180, 270, 1060, 600, or 650 smart phone manufactured by Palm, Inc. In this mode, the Treo smart phone is operated under the control of the PalmOS operating system and includes a Stylus input device as well as a five-mode browser device. In addition, computing device 100 can be any workstation, desktop computer, laptop or notebook computer, server, laptop, mobile phone, any other computer, or other form of computing or telecommunication device that is capable of communicating and that it has sufficient energy and memory capacity to perform the operations described here.
B. Application Architecture
Figure 2A illustrates an exemplary embodiment of application 200. The architecture of application 200 in figure 2A is provided by way of illustration only and is not intended to be limiting. As shown in Figure 2, application 200 comprises a hardware layer 206 and a software layer divided into user space 202 and kernel space 204.
A hardware layer 206 provides the hardware elements on the basis of which programs and services are run within kernel space 204 and user space 202. Hardware layer 206 also provides the structures and elements that allow programs and services within kernel space 204 and user space 202 to communicate data both internally and externally with respect to computer 200. As shown in Figure 2, hardware layer 206 includes a processing unit 262 to run software programs and services, a memory 264 to store software and data, network ports 266 to transmit and receive data over a network, and a processor code 260 to perform functions related to the processing of data transmitted and received over the Protected Sockets Layer network. In some embodiments, the central processing unit 262 can perform the functions of the coding processor 260 in a single processor. In addition, hardware layer 206 may comprise multiple processors for each processing unit 262 and coding processor 260. Processor 262 may include any of the processors 101 described above with respect to figures 1E and 1F. In some embodiments, the central processing unit 262 can perform the functions of the coding processor 260 in a single processor. In addition, hardware layer 206 may comprise multiple processors for processing unit 262 and coding processor 260. For example, in one embodiment, computer 200 comprises a first processor 262 and a second processor 262 '. In other embodiments, processor 262 or 262 'comprises a multi-core processor.
Although hardware layer 206 of computer 200 is generally illustrated with a coding processor 260, processor 260 can be a processor to perform functions related to any encryption protocol, such as the Protected Socket Layer (SSL) or the Transport Layer Security (TLS) protocol. In some embodiments, processor 260 may be a general purpose processor (GPP), and in additional embodiments, it may be provided with executable instructions for performing processing of any security related protocol.
Although the hardware layer 206 of computer 200 is illustrated with certain elements in figure 2, the hardware parts or components of computer 200 can comprise any type and shape of elements, hardware or software, of a computing device, such as, for example , the computing device 100 illustrated and commented on here in combination with Figures 1E and 1F. In some embodiments, computer 200 may comprise a server, port, router, switch, bridge or other type of computing device or network, and be provided with any hardware and / or software elements associated therewith.
The operating system of computer 200 allocates, manages, or otherwise segregates the system memory available in kernel space 204 and user space 204. In the exemplary software architecture 200, the programming system can be any type and / or form of Unix operating system despite the invention is not so limited. As such, computer 200 can be running any operating system, such as any versions of Microsoft ® Windows operating systems, different versions of Unix and Linux operating systems, any version of Mac OS® for Macintosh computers , any embedded operating system, any network operating system, any real-time operating system, any open source operating system, any proprietary operating system, any operating system for mobile computing devices or network devices, or any other operating system capable of running on computer 200 and performing the operations described herein.
The kernel space 204 is reserved to run the kernel 230, including any device drivers, kernel extensions or other kernel related software. As known to those skilled in the art, the 230 kernel is the core of the operating system, and provides access, control, and management of the computer's 104 hardware related resources and elements. According to a computer modality 200, kernel space 204 also includes a series of network services or processes running in combination with a cache manager 232, sometimes also referred to as integrated cache, the benefits of which are described in more detail here. . Additionally, the mode of kernel 230 will depend on the mode of the operating system installed, configured, or otherwise used by device 200.
In one embodiment, device 200 comprises a network stack 267, such as a TCP / IP-based stack, to communicate with client 102 and / or server 106. In one embodiment, network stack 267 it is used to communicate with a first network, such as network 108, and a second network 110. In some modalities, device 200 terminates a first transport layer connection, such as a TCP connection from a client 102, and establishes a second transport layer connection to a server 106 for use by a client 102, for example, the second transport layer connection is terminated on computer 200 and server 106. The first and second transport layer connections can be established via a single network stack 267. In other embodiments, device 200 may comprise multiple network cells, for example, 267 and 267 ', and the first transport layer connection can be established or terminated in a network cell 267, and the second transport layer connection in the second network stack 267 '. For example, a network stack can be for receiving and transmitting network packets on a first network, and another network stack for receiving and transmitting network packets on a second network. In one embodiment, network stack 267 comprises a buffer 243 for queuing one or more network packets for transmission from computer 200.
As illustrated in Figure 2, kernel space 204 includes cache manager 232, a high-speed layer 2-7 integrated packet mechanism 240, an encryption mechanism 234, a policy mechanism 236, and a protocol compression logic multiple 238. The execution of these components or processes 232, 240, 234, 236 and 238 in kernel space 204 or kernel mode instead of user space 202 improves the performance of each of these components, alone or in combination. The kernel operation means that these components or processes 232, 240, 234, 236 and 238 perform in the core address space of the device 200's operating system. For example, running the 234 kernel encryption engine improves cryptographic performance by moving encryption and decryption operations to the kernel, thereby reducing the number of transitions between memory space or a kernel string in kernel mode. and space or a memory chain in user mode. For example, data obtained in kernel mode may not need to be passed or copied to a process or chain running in user mode, for example, from a kernel-level data structure to a user-level data structure. In another aspect, the number of context switches between kernel mode and user mode is also reduced. Additionally, synchronization of and communications between any of the components or processes 232, 240, 235, 236 and 238 can be performed more efficiently in the kernel space 204.
In some embodiments, any part of components 232, 240, 234, 236 and 238 can run or operate in kernel space 204, while the other parts of components 232, 240, 234, 236 and 238 can run or operate in user space 202 . In one embodiment, computer 200 uses a kernel-level data structure providing access to any part of one or more packets, for example, a network packet comprising a request from a client 102 or a response from a server 106. In some modalities, the kernel-level data structure can be obtained by the packet mechanism 240 via an interface or transport layer driver filter for the network stack 267. The kernel level data structure may comprise any interface and / or data accessible via kernel space 204 related to network stack 267, network traffic or packets received or transmitted by network stack 267. In other embodiments, the structure of Kernel level data can be used by any components or processes 232, 240, 234, 236 and 238 to perform the described operation of the component or process. In one embodiment, a component 232, 240, 234, 236, and 238 is running in kernel mode 204 when using the kernel level data structure, while in another embodiment, component 232, 240, 234, 236, and 238 is running in user mode when using the kernel level data structure. In some embodiments, the kernel-level data structure can be copied or passed to a second kernel-level data structure, or any desired user-level data structure.
The cache manager 232 can comprise software, hardware or any combination of software and hardware to provide access, control and management of cache of any type and form of content, such as the dynamically generated objects or objects served by the creative servers 106. The data, objects or content processed and stored by the cache manager 232 can comprise data in any format, such as, for example, a composition language, or composition via any protocol. In some embodiments, cache manager 232 duplicates the original data stored elsewhere or the data previously computed, generated or transmitted, in which the original data may require longer access time to retrieve, compute or otherwise obtain with respect reading a cache memory element. Once the data is stored in the cache memory element, future use can be made by accessing the cached copy instead of retrieving or computing the original data again, thus reducing the access time. In some embodiments, the cache memory element does not comprise a data object in the memory 264 of the device 200. In other embodiments, the cache memory element may comprise memory having a faster access time than the memory 264. In another embodiment, the cache memory element may comprise any type or form of storage element of the device 200, such as, for example, a part of a hard disk. In some embodiments, processing unit 262 may provide cache memory for use by cache manager 232. Still, in additional embodiments, the cache manager 232 can use any part and combination of the memory unit, storage, or processing for the data cache, and other content.
In addition, cache manager 232 includes any logic, functions, rules, or operations to perform any modalities of the application techniques 200 described herein. For example, cache manager 232 includes logic or functionality to invalidate objects based on the expiration of an invalidation time period or on receiving an invalidation command from a client 102 or server 106. In some embodiments, cache manager 232 may operate as a program, process, or task service running in kernel space 204, and in other embodiments, in user space 202. In one embodiment, the first part of the cache manager 232 runs in user space 202 while a second part runs in kernel space 202. In some embodiments, cache manager 232 can comprise any type of general purpose processor (GPP), or any other type of integrated circuit, such as, for example, a Field Programmable Port Array (FPGA), Programmable Logic Device ( PLD), or Application Specific Integrated Circuit (ASIC).
Policy mechanism 236 may include, for example, an intelligent statistical mechanism or other programmable application (s). In one embodiment, policy mechanism 236 provides a configuration mechanism to allow a user to identify, specify, define or configure a cache policy. Policy mechanism 236, in some embodiments, is also provided with access to memory to support data structures such as query tables or hash tables to enable user-selected cache policy decisions. In other embodiments, the policy mechanism 236 can comprise any logic, rules, functions or operations to determine and provide access, control and management of objects, data or content being cached by the computer 200 in addition to access, control and management of security, traffic network access, network access, compression or any other function or operation performed by computer 200. Additional examples of specific cache policies are also described here.
In some embodiments, policy mechanism 236 may provide a configuration mechanism to allow a user to identify, specify, define or configure policies for driving behavior of any other components or functionality of a computer including, without limitation, the components described in figure 2B such as, for example, V-Servers 275, VPN functions 280, IP Intranet functions 282, switching functions 284, DNS functions 286, accelerator functions 288, application firewall functions 290, and monitoring agents 197. In other embodiments, policy mechanism 236 can verify, evaluate, implement, or otherwise act on any configured policies, and it can also direct the operation of one or more computer functions in response to a policy.
The encryption mechanism 234 comprises any logic, business rules, functions or operations to perform the processing of any security-related protocol. Like, for example, SSL or TLS, or any function related to it. For example, the encryption mechanism 234 encrypts and decrypts network packets, or any part of them, communicated via computer 200. The encryption engine 234 can also configure and establish SSL or TSL connections on behalf of client 102a to 102n, server 106a to 106n, or computer 200. As such, encryption engine 234 provides offloading and slowing down SSL processing. In one embodiment, the encryption mechanism 234 uses a synchronization protocol to provide a virtual private network between a client 102a through 102n and a server 106a through 106n. In some embodiments, the cryptography engine 234 is in communication with the Cryptographic processor 260. In other embodiments, the cryptographic engine 234 comprises executable instructions executing on the Cryptographic processor 260.
The multiple protocol compression mechanism 238 comprises any logic, business rules, function or operations to condense one or more protocols of a network packet, such as, for example, any of the protocols used by the network stack 267 of the device 200. In one embodiment, the multiple protocol compression mechanism 238 condenses bidirectionally between clients 102a to 102n and servers 106a to 106n any protocol based on TCP / IP, including Message Application Programming Interface (MAPI) (e- mail), File Transfer Protocol (FTP), HyperText Transfer Protocol (HTTP), Common Internet File System (CIFS) (file transfer) protocol, Independent Computing Architecture (ICA) protocol, Remote Desktop Protocol (RDP), Wireless Application Protocol (WAP), Mobile IP Protocol, and Protocol over IP Voice (VolP). In other modalities, the multiple protocol compression mechanism 238 provides compression of the protocols based on the Hypertext Markup Language (HTML) and in some modalities, it provides compression of any markup languages, such as, for example, Extensible Markup Language (XML ). In one embodiment, the multi-protocol compression mechanism 238 provides compression for any high performance protocol, such as, for example, any protocol designed for computer 200 for communications from computer 200. In other embodiments, the multi-protocol compression mechanism 238 condenses any payload of any communication using a modified transport control protocol, such as TCP Transaction (T / TCP), TCP with selection acknowledgments (TCP-SACK ), TCP with large windows (TCP-LW), a congestion prediction protocol such as the TCP-Vegas protocol, TCP spoofing protocol.
As such, the 238 multiple protocol compression engine accelerates performance for users accessing applications via desktop clients, for example, Microsoft Outlook and thin non-WEB clients, such as any client launched by popular company applications. type Oracle, SAP and Siebel, and even mobile customers, such as the Pocket PC. In some embodiments, the multi-protocol compression mechanism 238 by running in kernel mode 204 and interacting with the packet processing mechanism 240 accessing a network stack 267 is able to condense any protocol carried by the TCP / IP protocol, such as example, any application layer protocol.
The high speed layer 240 integrated packet mechanism 2-7, also generally referred to as a packet processing mechanism or packet mechanism, is responsible for managing the kernel level processing of packets received and transmitted by computer 200 via network ports 266. The high-speed layer 2-7 integrated packet mechanism 240 may comprise a buffer for queuing one or more network packets during processing, such as for receiving a network packet or transmitting a network packet. In addition, the high-speed layer 27 integrated packet mechanism 240 is in communication with one or more network stacks 267 to send and receive network packets via network ports 266. The high-speed layer 2-7 integrated packet mechanism 240 works in combination with encryption mechanism 234, cache manager 232, policy mechanism 236 and multi-protocol compression logic 238. Specifically, the 234 encryption engine is configured to perform SSL packet processing, the 236 policy engine is configured to perform functions related to traffic management, such as switching request-level content and redirecting the level-level cache. request, and the multi-protocol compression logic 238 is configured to perform functions related to data compression and decompression.
The high-speed layer 240 integrated packet mechanism 240 includes a packet processing timer 242. In one embodiment, packet processing timer 242 provides one or more intervals for triggering incoming processing, that is, received or outgoing, that is, network packets transmitted. In some embodiments, the high-speed layer 2-7 integrated packet mechanism 240 processes network packets responsive to timer 242. The packet processing timer 242 provides any type and form of signal to the packet mechanism 240 to notify, trigger, or report a time-related event, interval, or occurrence. In many embodiments, the packet processing timer 242 operates on the order of milliseconds, such as, for example, 100ms, 50ms or 25ms. For example, in some embodiments, the packet processing timer 242 provides time slots or otherwise takes the network packet to be processed by the high speed layer 240 integrated packet mechanism 240 over a time slot of 10ms, while in other modalities, in a time interval of 5ms, and still in additional modalities, time interval as short as 3.2, or 1ms. The high speed layer 2-7 integrated packet mechanism 240 can be interfaced, integrated or in communication with the encryption mechanism 234, cache manager 232, policy mechanism 236 and the multi-protocol compression mechanism 238 during operation . As such, any of the logic, functions, or operations of the encryption engine 234, cache manager 232, policy engine 236, and multiple protocol compression engine 238 can be executed responsive to packet processing timer 242 and / or the packet mechanism 240. Therefore, any of the logic, functions or operations of the encryption mechanism 234, cache manager 232, policy mechanism 236 and multiple protocol compression mechanism 238 can be performed at the granularity of the time intervals provided via the data timer. packet processing 242, for example, in a time interval less than or equal to 10ms. For example, in the modality, the cache manager 232 can perform invalidation of cached objects responsive to the high-speed layer 240 integrated packet mechanism 240 and / or the packet processing timer 242. In another modality, the expiration or invalidation of a cached object can be adjusted to the same granularity order as the 242 packet processing timer time interval, such as every 10ms.
In comparison to kernel space 204, user space 202 is in the area or part of the operating system memory used by user mode applications or programs otherwise running in user mode. A user mode application may not access kernel space 204 directly and use service calls to access kernel services. As shown in Figure 2, user space 202 on computer 200 includes a graphical user interface (GUI) 210, a command line interface (CLI) 212, shell services 214, health monitoring programs 216, and services daemon 218. GUI 210 and CLI
212 provide a means by which a system administrator or other user can interact with and control the operation of computer 200, such as via the computer operating system 200 and either is user space 202 or kernel space 204 GUI 210 can be any type and form of graphical user interface and can be presented via text, graphics or otherwise, by any type of program or application, such as a browser. CLI 212 can be any type and form of command line or text or text based interface, such as, for example, a command line provided by the operating system. For example, CLI 212 can comprise a Shell, which is a tool to enable users to interact with the operating system. In some embodiments, CLI 212 can be provided via a bash, csh, tcsh, or ksh shell. Shell services 214 comprise executable programs, services, tasks, processes or instructions to support interaction with computer 200 or the operating system by a user via GUI 210 and / or CLI 212.
The health monitoring program 216 is used to monitor, verify, report and ensure that network systems are functioning properly and that users are receiving requested content over a network. The health monitoring program 216 comprises one or more executable programs, services, tasks, processes or instructions to provide logic, rules, functions or operations to monitor any computer activity 200. In some modalities, the health monitoring program 216 interprets any network traffic passed via computer 200. In other modalities, the health monitoring program 216 interacts by any appropriate means and / or mechanisms with one or more of the following: encryption engine 234, cache manager 232, policy engine 236, multiple protocol compression logic 238, packet engine 240, daemon services 218, and shell services 214. As such, the health monitoring program 216 can call any application programming interface (API) to determine a state, status, or health of any part of the computer 200. For example, the health monitoring program 216 can ping or submit a status request on a periodic basis to verify that a program, process, service or task is currently active and running. In another example, the health monitoring program 216 can check any error status or history transaction files provided by any program, process, service or task to determine any condition, status or error with any part of the computer 200.
Daemon services 218 are programs that run continuously or in the background and handle periodic service requests received by the computer 200. In some ways, a daemon service can transfer requests to other programs or processes, such as another daemon service 218 as appropriate. As known to those skilled in the art, a 218 daemon service can run without being present to perform extensive continuous or periodic system functions, such as network control, or to perform any desired task. In some modalities, one or more daemon services 218 runs in user space 202, while in other modalities, one or more daemon services 218 runs in kernel space.
Figure 2B describes another modality of computer 200. In a brief overview, computer 200 provides one or more of the following services, functionality or operations: SSL VPN connectivity 280, switching / load balancing 284, Name Service resolution Domain 286, acceleration 288 and an application firewall 290 for communications between one or more clients 102 and one or more servers 106. Each server 106 can provide one or more related network services 270a to 270n (referred to as services 270). For example, a server 106 can provide an http 270 service. Computer 200 comprises one or more virtual Internet protocol servers or servers, referred to as vServer, VIP server, or VIP only 275a to 275n also referred to herein as vServer 275). The vServer 275 receives, intercepts, or otherwise processes communications between a client 102 and a server 106 according to the configuration and operations of the computer 200.
The vServer 275 can comprise software, hardware or any combination of software and hardware. The vServer 275 can comprise any type or form of executable program, service, task, process or instructions operating in user mode 202, kernel mode 204 or any combination thereof on computer 200. VServer 275 includes any logic, functions, rules, or operations to perform any of the techniques described here, such as SSL VPN 280, load / switch balance 284, Domain Name service resolution 286, acceleration 288 and a firewall application 290. In some embodiments, the vServer 275 establishes a connection to a service 270 of a server 106. Service 275 can comprise any executable program, application, process, task, or instruction set capable of connecting and communicating with computer 200, client 102, or vServer 275. For example, service 275 can comprise a web server, a http server, FTP server, email server or database. In some modalities, the 270 service is a daemon or network driver process for listening, receiving and / or sending communications to an application, such as, for example, email, database or a company application. In some modalities, the 270 service can communicate on a specific IP address, or IP address and port.
In some embodiments, vServer 275 applies one or more policies from policy engine 236 for network communications between client 102 and server 106. In one embodiment, policies are associated with a VServer 275. In another embodiment, policies are based on a user, or a group of users. In yet another modality, a policy is global and applies to one or more vServers 275a to 275n, and any user or group of users communicating via computer 200. In some modalities, the policies of the policy mechanism have conditions under which the policy is applied based on any content of the communication, such as, for example, Internet protocol address, port, type of protocol, initial registration or fields in a package, or the context of the communication, such as, for example, user, user group, vServer 275, transport layer connection, and / or identification or attributes of client 102 or server 106.
In other embodiments, computer 200 communicates with or interfaces with policy mechanism 236 to determine authentication and / or authorization of a remote user or remote client 102 to access configuration environment 15, application, and / or data file for a server 106. In another embodiment, computer 200 communicates with or interfaces with policy mechanism 236 to determine authentication and / or authorization of a remote user or remote client 102 so that the application distribution system 190 distributes one or more of the computing environment. 15, application, and / or data file. In yet another embodiment, computer 200 establishes a VPN or SSL VPN connection based on the authentication and / or authorization of policy mechanism 126 from a remote user or remote client 103. In one embodiment, computer 102 controls traffic flow networking and communication sessions based on policy mechanism policies 236. For example, computer 200 can control access to a computing environment 15, application or data file based on policy mechanism 236.
In some embodiments, the vServer 275 establishes a transport layer connection, such as a TCP or UDP connection to a client 102 via client agent 120. In one embodiment, the vServer 275 listens to and receives communications from the client 102. In other embodiments, vServer 275 establishes a transport layer connection, such as a TCP or UDP connection to a client server 106. In one embodiment, vServer 275 establishes the transport layer connection to an Internet protocol address and port on a server 270 running on server 106. In another embodiment, vServer 275 associates a first transport layer connection with a client 102 with a second transport layer connection to a server 106. In some embodiments, a vServer 275 establishes a pool of transport layer connections to a server 106 and multiplexes client requests via pooled transport layer connections.
In some embodiments, computer 200 provides SSL VPN connections 280 between a client 102 and a server 106. For example, a client 102 on a first network 102 requests to establish a connection to a server 106 on a second network 104 '. In some embodiments, the second network 104 'cannot be routed from the first network 104. In other embodiments, client 102 is on a public network 104 and server 106 is on a private network 104', such as a network incorporated. In one embodiment, client agent 120 intercepts client 102 communications on the first network 104, encrypts communications, and transmits communications via a first transport layer connection to computer 200. Computer 200 associates the first network connection. transport layer on the first network 104 to a second transport layer connection to server 106 on the second network 104. The computer 200 receives the intercepted communication from the client agent 102, decodes the communications, and transmits the communication to the server 106 and the second network 104 via the second transport layer connection. The second transport layer connection can be a pooled transport layer connection. As such, computer 200 provides an end-to-end transport layer connection for client 102 between the two networks 104, 104 '.
In one embodiment, computer 200 hosts an Internet Intranet protocol or IntranetIP address 282 of client 102 on a virtual private network 104. Client 102 is provided with a local network identifier, such as a protocol (IP) address Internet and / or main name of the first network 104. When connected to the second network 104 'via computer 200, computer 200 establishes, assigns or otherwise provides an IntranetIP, which is a network identifier, such as IP address and / or primary name, for client 102 on the second network 104 '. Computer 200 listens to and receives on the second or private network 104 'for any communications directed towards client 102 using client's established IntranetIP 282. In one embodiment, the computer
200 acts as or on behalf of client 102 on the second private network 104. For example, in another modality a vServer 275 listens and responds to communications to IntranetIP 282 from client 102. In some embodiments, if a computing device 100 on the second network 104 'to transmit a request, computer 200 processes the request as if it were client 102. For example, computer 200 can respond to a ping to client 282's IntranetlP. In another example, the computer can establish a connection, such as a TCP or UDP connection, to computing device 100 on the second network 104 requesting a connection to the client's IntranetIP 282.
In some embodiments, computer 200 provides one or more of the following acceleration techniques 288 for communications between client 102 and server 106: 1) compression; 2) decompression; 3) Transmission Control Protocol pooling; 4) multiplexing the Transmission Control Protocol; 5) use of the Transmission Control Protocol buffer; and 6) cache. In one embodiment, application 200 relieves servers 106 of a lot of processing load caused by repeatedly opening and closing transport layer connections for clients 102 by opening one or more transport layer connections with each server 106 and maintaining these connections to allow repeat data access by customers via the Internet. This technique is referred to here as connection pooling.
In some embodiments, to seamlessly link communications from a client 102 to a server 106 via a pooled transport layer connection, computer 200 translates or multiplexes communications by modifying the sequence number of acknowledgment numbers at the layer protocol level. carriage. This is referred to as connection multiplexing. In some embodiments, no application layer protocol interaction is required. For example, in the case of an in-bound packet (that is, a packet received from a client 102), the source network address of the packet is changed so that the outgoing port of computer 200, and the destination network address be changed to that of the intended server. In the case of an outbound packet (that is, a packet received from a server 106), the source network address is changed from that of server 106 to that of an outbound port on computer 200 and the destination address is changed from that on computer 200 for that of the requesting customer 102. Sequence numbers and package confirmation numbers are also translated into sequence and confirmation numbers expected by client 102 on the transport layer connection from computer 200 to client 102. In some embodiments, the checksum of the layer protocol transport is recalculated to be responsible for these translations.
In another embodiment, computer 200 provides load balancing switching or functionality 284 for communications between client 102 and server 106. In some embodiments, computer 200 distributes traffic and directs client requests to a server 106 based on layer 4 or application layer request data. In one embodiment, despite the network layer or layer 2 of the network packet identifying a destination server 106, computer 200 determines that server 106 distributes the network packet by application information and data carried as the payload of the transport layer packet. In one embodiment, the output monitoring programs 216 of computer 200 monitor the health of the servers to determine the server 106 to which to distribute a client request. In some embodiments, if computer 200 detects that a server 106 is unavailable or has a load above a predetermined threshold, computer 200 may direct or distribute client requests to another server 106.
In some embodiments, computer 200 acts as a Domain Name Service (DNS) resolver or otherwise provides resolution of a DNS request from clients 102. In some embodiments, the computer intercepts a DNS request transmitted by client 102. In In one embodiment, application 200 responds to a client DNS request with an IP address from or hosted by computer 200. In this embodiment, client 102 transmits network communication for the domain name to computer 200. In another embodiment, computer 200 responds to a client DNS request with an IP address from or hosted by a second computer 200 '. In some embodiments, application 200 responds to a client DNS request with an IP address from a server 106 determined by computer 200.
In yet another embodiment, computer 200 provides functionality for application firewall 290 for communications between client 102 and server 106. In one embodiment, policy mechanism 236 provides rules for detecting and blocking illegitimate requests. In some embodiments, application firewall 290 protects against denial of service attacks (DoS). In other ways, the application inspects the content of requests to identify and block attacks based on the application. In some embodiments, the rules / policy mechanism 236 comprises one or more application firewall or security control policies to provide protection against various classes and types of vulnerabilities based on the web or Internet, such as one or more than follows: 1) buffer overflow, 2) GGI-BIN parameter manipulation, 3) form / hidden field manipulation, 4) vigorous search, 5) cookie 'or session poisoning, 6) broken access control list (ACLs) or weak passwords, 7) cross-site script (XSS), 8) command injection, 9) SQL injection, 10) leakage of sensitive error triggering information, 11) insecure use of encryption, 12) server misconfiguration, 13) rear doors and debugging options, 14) modification of the appearance (defacement) of the web site 15) vulnerabilities of platform or operation systems, and 16) zero-day exploits. In one embodiment, application firewall 290 provides HTML field protection in the form of inspection or analysis of network communications for one or more of the following: 1) required fields are returned, 2) no field addition is allowed , 3) read-only and hidden field reinforcement, 4) radio button field option and compliance list box, and 5) max-leght form field reinforcement ”(maximum size of characters that are accepted as input). In some embodiments, application firewall 290 ensures that cookies are not modified. In other modalities, application firewall 290 protects against vigorous search by enforcing legal URLs.
In yet other embodiments, application firewall 290 protects any confidential information contained in the network communication. Application firewall 290 can inspect or analyze any network communication according to the rules and policies of the 236 mechanism to identify any confidential information in any field of the network packet. In some embodiments, application firewall 290 identifies in network communication one or more occurrences of a credit card number, social security number, name, patient code, contact information, and age. The encrypted part of the network communication can comprise these occurrences or confidential information. Based on these occurrences, in one mode, the application firewall 290 can start to act on the policy in network communication, such as, for example, preventing transmission of the network communication. In another embodiment, application firewall 290 may rewrite, remove or otherwise mask such identified occurrence or confidential information.
Still with reference to figure 2B, computer 200 may include a performance monitoring agent 197 as discussed above in combination with figure 1D. In one embodiment, computer 200 receives monitoring agent 197 from monitoring service 198 or monitoring server 106 as described in figure 1D. In some embodiments, computer 200 stores monitoring agent 197 in storage, such as a disk, to distribute to any client or server communicating with computer 200. For example, in one embodiment, computer 200 transmits the 197 monitoring agent to a customer when receiving a request to establish a transport layer connection. In other embodiments, computer 200 transmits monitoring agent 197 when establishing the transport layer connection with client 102. In another embodiment, computer 200 transmits monitoring agent 197 to the client when intercepting or detecting a request for a web page. In yet another embodiment, computer 200 transmits monitoring agent 197 to a client or server in response to a request from monitoring server 198. In one embodiment, computer 200 transmits monitoring agent 197 to a second computer 200 'or computer 205.
In other embodiments, computer 200 runs monitoring agent 197. In one embodiment, monitoring agent 197 measures and monitors the performance of any application, program, process, service, task, or chain execution on computer 200. For example, monitoring agent 197 can monitor and measure the performance and operation of the yServers 275<sup>The</sup>-275N. In another embodiment, monitoring agent 197 measures and monitors the performance of any transport layer connections on computer 200. In some embodiments, monitoring agent 197 measures and monitors the performance of any user sessions traversing computer 200. In In one embodiment, the monitoring agent 197 measures and monitors the performance of any virtual private network connections and / or sessions running through computer 200, such as, for example, the SSL VPN session. In additional modalities, the monitoring agent 197 measures and monitors the memory, CPU and disk usage and performance of the computer 200. In yet another modality, the monitoring agent 197 measures and monitors the performance of any acceleration technique 288 performed by the computer 200, such as SSL offloading, connection pooling and multiplexing, caching, and compression. In some modalities, monitoring agent 197 measures and monitors the performance of any load balancing and / or content switching 284 performed by computer 200. In other modalities, monitoring agent 197 measures and monitors the protection and processing performance of the computer. application firewall 290 performed by computer 200.
C. Client Agent
Figure 3 describes a modality of the client agent. The client
102 includes a client agent 120 for establishing and executing communications with computer 200 and / or server 106 via a network 104. In brief overview, client 102 operates on computing device 100 and is provided with an operating system with a kernel mode 302 and user mode 303, and a network stack 310 with one or more layers 310a through 310b. client 102 may have installed and / or run one or more applications. In some embodiments, one or more applications can communicate via the network stack 310 with network 104. One of the applications, such as, for example, a web browser, may also include a first 322 program, for example, the first program 322 can be used in some ways to install and / or run client agent 120, or any part thereof. Client agent 120 includes an interception mechanism, or interceptor 350, for intercepting network communications from network stack 310 of one or more applications.
The network stack 310 of client 102 may comprise any type and form of software, or hardware, or any combination thereof, to provide connectivity to and communications with a network. In one embodiment, the network stack 310 comprises a software implementation for a network protocol set. The network stack 310 may comprise one or more network layers, such as, for example, any network layers of the Open Systems Interconnection (OSI) communications model as those skilled in the art will recognize and appreciate. As such, network stack 310 can comprise any type and form of protocols for any of the following layers of the OSI model: 1) physical link layer, 2) data link layer, 3) network layer, 4) transport layer, 5) session layer, 6) presentation layer, and 7) application layer. In one embodiment, the network stack 310 may comprise a transport control protocol (TCP) over the Internet protocol (IP) network layer protocol, generally referred to as TCP / IP. In some embodiments, the IP protocol can be carried over the Ethernet protocol, which can comprise any family of IEEE wide area network (WAN) or local area network (LAN) protocols, such as those protocols covered by the IEEE 802.3. In some embodiments, network stack 310 may comprise any type and form of a wireless protocol, such as, for example, the IEEE 802.11 protocol and / or mobile Internet protocol.
In view of a TCP / IP based network, any TCP / IP based protocol can be used, including Message Application Programming Interface (MAPI) (email), File Transfer Protocol (FTP), HyperText Transfer (HTTP), (file transfer) Common Internet File System (CIFS) protocol, Independent Computing Architecture Protocol (ICA), Remote Desktop Protocol (RDP), Wireless Application Protocol (WAP), IP Protocol Mobile, and About Voice over IP (VolP) protocol. In another embodiment, the network stack 310 may comprise any type or form of transport control protocol, such as, for example, a modified transport control protocol, for example, TCP Transaction (T / TCP), TCP with acknowledgments of selection (TCP-SACK), TCP with wide windows (TCP-LW), a congestion prediction protocol such as the TCP-Vegas protocol, TCP spoofing protocol. In other modalities, any type and form of user datagram protocol (UDP), such as UDP over IP, can be used over the network stack 310, for example, for voice communications or data communications in real time real.
In addition, network stack 310 may include one or more network drivers supporting one or more layers, such as, for example, a TCP driver or a network layer driver. Network drivers can be included as part of the operating system of computing device 100 or as part of any network interface cards or other network access components of computing device 100. In some embodiments, which of the network drivers of the network stack 310 can be customized, modified or adapted to provide a custom or modified part of the network stack 310 in support of any techniques described herein. In other embodiments, the acceleration program 120 is designed and built to operate with or function in combination with the network stack 310 installed or otherwise provided by the client's operating system 102.
The network stack 310 comprises any type or form of interface for receiving, obtaining, providing or otherwise accessing any information and data related to the client's network communications 102. In one embodiment, an interface to the network stack 310 comprises a application programming interface (API). The interface can comprise any function call mechanism, video layer distortion or filtering, call retrieval or event mechanism, or any type of interface technique. The network stack 310 via the interface can receive or provide any type or form of data structure, such as, for example, an object, related to the functionality or operation of the network stack 310. For example, the data structure can comprise information and data related to a network packet or one or more network packets. In some embodiments, the data structure comprises a portion of the network packet processed in a protocol layer of the network stack 310, such as, for example, a transport layer network packet. In some embodiments, data structure 325 comprises a kernel-level data structure, while in other embodiments, data structure 325 comprises a user mode data structure. A kernel-level data structure comprises a data structure obtained from or related to a portion of the network stack 310 operating in kernel mode 302, or a network driver or other software running in kernel mode 302, or any data structure obtained or received by a service, process, task, chain, or other executable instructions executing or operating in the operating system's kernel mode.
Additionally, the same parts of the network stack 310 can run or operate in kernel mode 301, for example, the data link or network layer, while other parts run or operate in user mode 303, such as, for example, a network stack application layer 310. For example, a first part 310a of the network stack may provide user mode access to the network stack 310 for an application while a second part 310a of the network stack 310 provides access to a network. In some embodiments, a second portion 310a of the network stack may comprise one or more upper layers of the network stack 310, such as, for example, layers 5 to 7. In other embodiments, a second part 310b of the mesh stack 310 comprises one or more lower layers, such as, for example, any of layers 1 to 4. Each of the first part 310a and second part 310b of the network stack 310 may comprise any part of the network stack 310, in any one or more layers, in user mode 203, in kernel mode 202, or combinations thereof, or in any part of the network layer or interface point for a network layer or any part of or interface point for user mode 203 and kernel mode 203.
Interceptor 350 comprises software, hardware, or any combination of software and hardware. In one embodiment, interceptor 350 intercepts network communication at any point in network stack 310, and redirects and transmits network communication to a desired destination, managed or controlled by interceptor 350 or client agent 120. For example, interceptor 350 can intercept network communication from a network stack 310 of a first network and transmit network communication to computer 200 for transmission on second network 104. In some embodiments, interceptor 350 comprises any type of interceptor 350 comprising a driver, such as a network driver built and designed to interface and work with the network stack 310. In some embodiments, the client agent 120 and / or the interceptor 350 operates on one or more layers of the network stack 310, such as, for example, the transport layer. In one embodiment, interceptor 350 comprises a filter driver, a hooking mechanism, or any form and type of suitable network driver interface that interfaces to the transport stack of the network stack, such as via the interface transport driver (TDI). In some embodiments, interceptor 350 interfaces with a first protocol layer, such as, for example, the transport layer and another protocol layer, such as, for example, any layer above the transport protocol layer, for example, a application protocol layer. In one embodiment, interceptor 350 may comprise a driver that complies with the Network Driver Interface Specification (NDIS), or an NDIS driver. In another embodiment, interceptor 350 may comprise a minifilter or a miniport driver. In one embodiment, interceptor 350 or part of it, operates in kernel mode 202. In another embodiment, interceptor 350 or part of it, operates in user mode 203. In some embodiments, a part of interceptor 350 operates in kernel mode. 202 while another part of interceptor 350 operates in user mode 203. In another embodiment, client agent 120 operates in user mode 203, but interfaces via interceptor 350 with a kernel-mode driver, process, service, task, or part of the operating system, such as, for example, to obtain a structure kernel level data 225. In additional modalities, interceptor 350 is a user mode application or program, such as an application.
In one embodiment, interceptor 350 intercepts any transport layer connection requests. In these modalities, the interceptor 350 makes calls to the transport layer application programming interface (API) calls to adjust destination information, such as, for example, destination IP address and / or port to a desired location for the location. In this way, interceptor 350 intercepts and redirects the transport layer connection to an IP address and port controlled or managed by interceptor 350 or client agent 120. In one embodiment, interceptor 350 adjusts the destination information for the connection to an address Local IP and client port 102 on which client agent 120 is listened. For example, client agent 120 may comprise a Proxy service listening on a local IP address and port to redirect transport layer communications. In some embodiments, the client agent 120 then communicates with the redirected transport layer communicating to the computer 200.
In some embodiments, interceptor 350 intercepts a Domain Name Service (DNS) request. In one mode, the a60 people client 120 and / or intercept 350 resolves the DNS request. In another embodiment, the interceptor transmits the intercepted DNS request to computer 200 for DNS resolution. In one embodiment, computer 200 resolves the DNS request and communicates the DNS response to client agent 120. In some embodiments, computer 200 resolves the DNS request via another computer 200 'or a DNS server 106.
In yet another embodiment, the client agent 120 may comprise two agents 120 and 120 '. In one embodiment, a first agent 120 may comprise an intercept 350 operating at the network layer of the network stack 310. In some embodiments, the first agent 120 intercepts network layer requests, such as Internet Control Message Protocol (ICMP) requests (for example, ping and route tracking). In other embodiments, the client agent 120 ' it can operate at the transport layer and intercept the transport layer communications. In some embodiments, the first agent 120 intercepts communications on one layer of the network stack 210 and interfaces with or communicates the intercepted communication to the second layer 120 '.
Client agent 120 and / or intercept 350 may operate on or interface with a protocol layer in a manner transparent to any other protocol layer of network stack 310. For example, in one embodiment, the intercept 350 operates or interfaces with the transport layer of the network stack 310 transparently to any protocol layer below the transport layer, such as the network layer, and any protocol layer. above the transport layer, such as session, presentation or application layer protocols. This allows other protocol layers of the network stack 310 to operate as described and without modification to use the intercept 350. As such, the client agent 120 and / or the intercept 350 can interface with the transport layer to secure, optimize, accelerate , route or balance the load of any communication provided via any protocol carried by the transport layer, such as, for example, application layer protocol over TCP / IP.
In addition, the client agent 120 and / or the interceptor can operate on or interface with the network stack 310 in a transparent manner to any application, a client user 102, and any other computing device, such as a server, in communication with client 102. Client agent 120 and / or interceptor 350 can be installed and / or run on client 102 in a manner without modifying an application. In some embodiments, the user of client 102 or a computing device communicating with client 102 is unaware of the existence, execution or operation of client agent 120 and / or interceptor 350. As such, in some embodiments, client agent 120 and / or interceptor 350 is installed, executed, and / or operated transparently for an application, client user 102, another computing device, such as a server, or any of the protocol layers above and / or below the protocol layer interfaced by interceptor 350.
Client agent 120 includes an acceleration program 302, a continuous client 306, a collection agent 304, and / or monitoring agent 197. In one embodiment, client agent 120 comprises an Independent Computing Architecture (ICA) client, or any part thereof, developed by Citrix systems, Inc. of Fort Lauderdale, Florida, and is also referred to as an ICA customer. In some embodiments, client 120 comprises a continuous application client 306 to flow an application from a server 106 to a client 102. In some embodiments, client agent 120 comprises an acceleration program 302 to accelerate communications between client 102 and server 106. In another embodiment, client agent 120 includes a collection agent 304 to perform endpoint detection / examination and collection of endpoint information for computer 200 and / or server 106.
In some embodiments, the acceleration program 302 comprises a client-side acceleration program to perform one or more acceleration techniques to accelerate, augment or otherwise improve client communication with and / or to a server 106, such as example, accessing an application provided by a server
106. The logic, functions, and / or operations of the 302 acceleration program executable instructions can perform one or more of the techniques and acceleration: 1) multiple protocol compression, 2) transport control protocol pooling, 3) protocol protocol multiplexing transport control, 4) use of the transport control protocol buffer, and 5) cache via a cache manager. In addition, the acceleration program 302 can perform encryption and / or decryption of any communications received and / or transmitted by the client 102. In some embodiments, the acceleration program 302 performs one or more acceleration techniques in an integrated manner or mode. In addition, the acceleration program 302 can perform compression on any of the protocols, or multiple protocols, carried as a payload of a transport layer protocol network packet.
The continuous client 306 comprises an executable application, program, process, service, task or instruction to receive and execute a fluid application from a server 106. A server 106 can stream one or more application data files to the continuous client 306 to trigger, execute or otherwise take the application to run on client 102. In some embodiments, server 106 transmits a set of condensed or packaged application data files to the flowing client 306. In some embodiments, the plurality of application files are condensed and stored on a file server within an archive as , for example, a CAB, ZIP, SIT, TAR, JAR, or other archive. In another embodiment, server 106 unzips, unpacks or unarchives the application files and transmits the files to client 102. In another embodiment, client 102 unzips, unpacks or unarchives the application files. The continuous client 306 dynamically installs the application, or part of it, and runs the application. In one embodiment, the continuous client 306 can be an executable program. In some embodiments, the continuous client 306 may be able to launch another executable program.
Collection agent 304 comprises an executable application, program, process, service, task or instruction to identify, obtain and / or collect information about customer 102. In some embodiments, application 200 transmits collection agent 304 to customer 102 or client agent 120. Collection agent 304 can be configured according to one or more policies of the computer's 236 policy engine. In another embodiment, collection agent 304 transmits the information collected on client 102 to computer 200. In one embodiment, policy mechanism 236 on computer 200 uses the collected information and provides access control, authentication and authorization for the client connection. for a 104 network.
In one embodiment, the collection agent 304 comprises an endpoint detection and scanning mechanism, which identifies and determines one or more attributes or characteristics of the customer. For example, collection agent 304 can identify and determine one or more of the following client-side attributes: 1) the operating system and / or a version of the operating system, 2) an operating system service pack , 3) an execution service, 4) an execution process, and 5) a file. Collection Agent 34 can also identify and determine the presence or versions of one or more of the following on the client: 1) antivirus software, 2) personal firewall software, 3) anti span software, and 4) Internet security software . The policy mechanism 236 may be provided with one or more policies based on any one or more of the attributes or characteristics of the client or attributes of the client side.
In some embodiments, the client agent 120 includes a monitoring agent 197 as discussed in combination with figures 1D and 2B. Monitoring agent 197 can be any type and form of script, such as a Visual Basic or Java script. In one embodiment, the monitoring agent 129 monitors and measures the performance of any part of the client agent 120. For example, in some modalities, the monitoring agent 129 monitors and measures the performance of the acceleration program 302. In another modality, the monitoring agent 129 monitors and measures the performance of the continuous client 306. In other 64 modes, the monitoring agent monitoring 129 monitors and measures the performance of the collection agent 304. In yet another modality, the monitoring agent 129 monitors and measures the performance of the interceptor 350. In some embodiments, the monitoring agent 129 monitors and measures any client resource 102, such as, for example, memory, CPU and disk.
The monitoring agent 197 can monitor and measure the performance of any customer application. In one embodiment, the monitoring agent 129 monitors and measures the performance of a browser on the client 102. In some embodiments, the monitoring agent 197 monitors and measures the performance of any application distributed via the client agent 120. In other modalities, the monitoring agent 197 measures and monitors user response times for an application, such as, for example, web-based or HTTP response times. Monitoring agent 197 can monitor and measure the performance of an ICA or RDP client. In another embodiment, the monitoring agent 197 measures and monitors for a user session or application session. In some modalities, monitoring agent 197 measures and monitors an ICA or RDP session. In one embodiment, the monitoring agent 197 measures and monitors the performance of the computer 200 in accelerating the distribution of an application and / or data to the customer 102.
In some embodiments and also with respect to figure 3, a first program 322 can be used to install and / or run client agent 120, or part of it, such as interceptor 350, automatically, silently or transparently , or otherwise. In one embodiment, the first 322 program comprises a connection component, such as an ActiveX control or Java control or script that is located in and executed by an application. For example, the first program comprises an Active X control located and executed by a web browser application, such as, for example, in the memory space or context of the application. In another embodiment, the first program 322 comprises a set of executable instructions loaded into and executed by the application, such as, for example, a shipper. In one embodiment, the first program 322 comprises a program designed and built to install client agent 120. In some embodiments, the first program 322 obtains, loads, or receives client agent 120 via the network of another computing device. In another embodiment, the first program 322 is an installer program or a plug and activates the manager to install programs, such as network drivers, on the client's 102 operating system.
D. Systems and Methods for configuring and using object-oriented policy expressions
With reference to figure 4A, an example of a part of an object model used to facilitate the processing of HTTP data is illustrated. In a brief overview, object classes are defined by a series of elements in the HTTP protocol. The defined classes include a request 405, response 410, hostname (name given to a computer in order to facilitate its connection) 415, uri 420, query 425, cookie 430, and text 435. Each class is defined to include a number of fields and / or methods, which can include or return objects corresponding to other classes or can include or return other types of data, such as integers.
Still with reference to figure 4A, now in more detail, an object model can comprise a set of defined object classes that allow a computer device to specify and manipulate data, and / or a defined set of object classes that allows a user of a computing device to direct the operations of the computing device. An object model can be endowed with any properties associated with object oriented design or programming including, without limitation, inheritance, abstraction, condensation, and polymorphism. Examples of object models that can be used in combination with the object-oriented expressions described here include, without limitation, the Java object model, Component Object Model (COM), and the HTML Document Object Model (DOM) , and any part or combination of parts of those models. In some embodiments, an object model or part of an object model may correspond to a protocol. For example, an object model can be created to represent HTTP communications, with the object model providing classes and methods for accessing and handling HTTP communications. Or an object model can be created to represent TCP, IP, UDP, ICA, or SSL communications. Or an object model can be created to represent an application, as an object model providing classes and methods for accessing and manipulating state information related to a network computer 200.
An object class can comprise an abstract description of an object and any methods associated with the object. An object, a particular instance of a class, can represent any type or form of data, process, or protocol. Exemplary objects may include, without limitation, strings, text, numbers, lists, protocols, data flows, connections, devices, data structures, systems, and network packets.
An object class can have a number of members. A member of an object class can comprise any field, method, constructor, property, or variable specified by the object class. In some embodiments, a member of an object class may comprise an object of a second object class. For example, in the illustrated modality, the object class http_request 405 contains a getUrl method that returns a uri object. In other embodiments, a member of an object class can be a primitive data type of a basic architecture, such as an integer, floating point number, byte, array, or Boolean variable. For example, the cookie class contains a count field which is an integer identifying the number of name value pairs in the list. In yet another embodiment, a member of the object class can comprise a constant. In still other embodiments, a member of an object class can understand a method.
In some cases, a member of an object class can be defined in the object class definition. In other cases, a member of an object class can be defined in a main class of the object class. In still other cases, a member of an object class can be defined in a principal of the object class and modified in the class definition for the object. For example, both cookie class 430 and query class 425 inherit the getName and getValue methods from their main class list_nv, which is a class representing lists of name value pairs.
In the illustrated modality, the class http_request 405 contains a series of methods that can be used to process an HTTP request. Fields and methods can be provided to identify and manipulate any part or parts of an HTTP request including, without limitation, the URL, cookie, body, content type, date, version, and hostname. In one embodiment, a method or methods may be provided to determine whether a given data stream is a valid formatted HTTP request. A similar class and / or methods for an HTTP response may also be provided.
The illustrated uri class 420 can comprise any number of fields and methods for operating and identifying a uri. In one embodiment, the uri can contain methods for analyzing one or more hostname, port, server, domain, file suffix, path, and query. In one embodiment, the uri can be a subclass of a general text object, which can allow the uri to be treated as unformatted text. For example, class uri 420 may be a subclass of text class 435. In one embodiment, the uri class can comprise methods for rewriting all or part of the uri. In some embodiments, the uri class can be applied to any part of the text. For example, the uri class can comprise a constructor that accepts a text string and creates a uri object by analyzing the string. In these and other modalities, the uri class can comprise a method of indicating whether a URL is a properly formatted URL. In some embodiments, a URL class may comprise a method for identifying one or more URLs in a text string.
For example, a static findURL method can be provided that returns a list of URLs validly formatted in a given text string. This method can be used, for example, to find a number of URLs contained in the body of an HTTP response. The uri class can then provide methods for modifying one or more of the URLs found.
The cookie class 430 can comprise any number of fields and methods for identifying and processing a cookie. In one embodiment, the cookie can be an HTTP cookie. In the illustrated embodiment, the cookie class represents a cookie as a list of name value pairs. The getValue method, in response to receiving a number n, can return a text object of the value nth in the list. The getName method, in response to receiving a number n, can return a text object of the value nth in the name. In other embodiments, a cookie can be represented using any other syntax or data type including, without limitation, a string, or linked list. In some embodiments, the cookie class can provide a method for inserting and / or changing a cookie. In other embodiments, an HTTP response or request object class can provide a method for inserting or modifying a cookie contained in a request or response.
The illustrated text class 435 can comprise any number of fields and / or methods for operating in a text string. A text string can comprise any sequence of bytes capable of being treated as characters. In some embodiments, a text object can comprise a discrete byte sequence. In other embodiments, the text object may comprise one or more bytes in a byte stream. In these modalities, a text object can be used to operate on parts of the byte stream even though the entire stream has not been received. Methods that can be used in combination with text objects can include, without limitation, comparisons, truncations, searches, sorts, and regular expression search and matching. For example, a method may be provided to determine whether a given secondary sequence is found within a text object. Or, for example, a method may be provided to determine a part of a text object preceding a special character. Or, for example, a method may be provided to identify a text string following a given regular expression.
In some embodiments, methods can also be provided to format or confirm formatting of text so that it can be processed by other classes and / or methods. For example, a method can be provided that ensures that the text object can be treated as XML. This method could check that the text object conforms to the standards for formatting the appropriate XML and does not contain any malice or inadvertent errors. Or, for example, a similar method can be provided to determine whether a text string can be treated as a URL. The method can, for example, find and replace any characters that need to be replaced for escape strings so that the text object complies with the appropriate URL formatting conventions.
An object model can be implemented using any physical data structures or other basic physical implementations. In some embodiments, a number of objects can access the same object in physical memory to execute the methods associated with each object. In one embodiment, the illustrated object model can be implemented so that a plurality of object instances operate on a basic data stream, without having to produce separate copies of the data stream for each object instance. To provide a detailed example, with respect to the illustrated object model, an application can receive an HTTP communication from a client and store it in memory. The application can then perform identification of an http_request object, and then call functions in the http_request 305 object class to obtain a uri and / or a cookie object. The computer can then call additional functions or reference fields in the uri and cookie objects. Some or all of the methods can operate by analyzing some or all of the basic data flow, and then return references to parts of the flow. For example, an uri object can store memory locations beginning and ending with the uri of the basic data stream. Each method of the uri class can then analyze and / or modify parts of the data within the identified memory locations. In this way, the computer may be able to process a data stream using an object model without having to maintain additional copies in the data stream.
In other implementations, one or more additional copies of some or all of the data stream can be made with respect to some objects. These objects can perform operations on a copy of a data stream portion, and, as appropriate, update the data stream with any changes made to the copy.
The illustrated object model and others can specify object classes and data structures that can be applied to any input stream. For example, the illustrated object model can be used to treat any input stream as an http_request object, and then use any functionality provided by the http_request object class. Furthermore, although the object model illustrated relates to HTTP data, other object models can be used to provide functionality with respect to TCP, SSL, or ICA flows. In some embodiments, an object model and implementation can be provided so that a computer can select from a number of object models to process a given data stream. For example, upon receiving a given data stream, an application can determine that the data stream is an ICA stream, and apply an appropriate object model to process the ICA items. However, if HTTP data is transmitted within an ICA stream, the computer can also apply an HTTP object model, such as an illustrated one, to process HTTP data. In this way, a computer can specify any structure or structures to apply to a received data stream.
Figure 4B illustrates an example of a documentation screen for an object class representing a URL. In brief overview, the documentation screen comprises a partial list of a number of methods and a constructor for the class http_url_t, which represents a URL. The documentation screen indicates a number of the methods that are implemented in the http_url_t class, and a number of the methods implemented in the main text_t class. These classes can correspond to the uri and text classes described in relation to figure 4A.
Figure 4C illustrates a number of object-oriented expressions for use in a policy mechanism. In brief overview, an object oriented expression 400 contains a number of object classes, which can correspond to protocols, protocol objects, data structures, and data types. An object-oriented expression can specify a member of an object identifier, which can comprise methods, data types, or other object classes. A number of exemplary object oriented expressions 400a, 400b, 400c are illustrated. These object-oriented expressions can be used by a network device to perform any function including, without limitation, traffic flow analysis, identification of system properties, load balancing, content switching and application security.
Still with respect to figure 4C, now more detailed, object-oriented expressions can include any expression that allows the specification of data and functions with respect to the object model. An exemplary first object oriented expression 400 identifies an object class and an object class number. In the syntax of illustrated object-oriented expressions, an object number is assigned a period following the object and then a sequence naming the object's member. For example, HTTP.REQ identifies the method of the member named REQ for the HTTP object. In this example, the method names can all be indicated in capital letters. In other embodiments, any other syntax can be used to specify object-oriented expressions. Exemplary syntaxes that can be used include, without limitation, the syntax or syntax combination of ActionRoteiro, Java, JavaRoteiro, C<sup>2</sup>, Visual FoxPro, VB.Net, C ++, Python, Perl, PHP, Ruby and / or
Objective-C.
In the exemplary object-oriented expression 400a, the expression identifies the HTTP protocol. In one embodiment, HTTP can correspond to an object class, an abstract object class, a static object class, or any other component of an object model. In some embodiments, HTTP can be a main class of a number of object classes used to represent and process HTTP communications. In other embodiments, HTTP can be a static class or method comprising one or more objects and / or methods referring to the representation and processing of HTTP communications. For example, the expression HTTP.REQ can return an object corresponding to an HTTP request within a data stream. In one embodiment, this object can be an instance of an object class, such as an http_request class commented in figure 4A. In the illustrated modality, the expression 400a can take up a Boolean value indicating whether Joe is contained in a value named id in the query part of a URL of an HTTP request.
The exemplary object-oriented expression 400b provides an explicit typecasting (example of composition with moving types), which can be used to specify structure with respect to the arbitrary parts of a data stream. In the example, the sequence returned from an HTTP request initial record item corresponding to an AcceptLanguage is explicitly typecast in a list. The TYPECAST_TO_LIST method accepts the list delimiter as an argument, and returns a list based on the delimiter. The expression then identifies a CONTAIN method to determine whether one of the elements is en. This example 400b can be used to configure a device to detect whether an HTTP request indicates that the partner accepts English as a language. In some embodiments, an object model and expression syntax can follow a data stream to be typecast explicitly in an object class. This can allow a user to configure a device to specify arbitrary structures with respect to a data stream. This can successively allow a user to leverage knowledge of a protocol or convention to format input streams in a convenient way for processing.
As another example of explicit typecasting, the expression HTTP. RES. HEADER (Location) .TYPECAST_TO_URL. QUERY can be used to type an element of the HTTP main record so that it is treated as a URL. Typecasting the text elements for a URL, URL processing methods can be made available to analyze content anywhere in a network traffic flow.
In some modalities, two or more object-oriented expressions can be used in combination with an operator, such as AND (E), OR (OU), NOT (NO), GREATER THAN (GREATER THAN), or LESS THAN (LESS THAN), to produce value. For example, in expression 400c two expressions that can return Boolean values are joined with an OR operator. The result of the combined expression will be OR of the values returned by the two expressions. In other embodiments, operators can work with any object or data type including, without limitation, integers, floating point numbers, and strings.
Although the specific examples illustrated reflect object-oriented claims in the context of an HTTP object model, object-oriented claims and models can be used to access any parts of network traffic passing through a device. In addition, object-oriented declarations and models can be used to access system properties for a device, or properties for a particular connection or connected device.
In one embodiment, an object-oriented expression for base network device behavior can be used in any device properties. For example, the expression SYS.TIME.WITHIN (time1.time2) can be used to base behavior based on a time of day, or day of the year. Or for example, the expression SYS.CONNECTION.SSL_OPEN.COUNT can be used to return a count of the total number of SSL connections that are currently open with a system. In both examples, the SYS object represents the system executing the policy, and a number of methods and / or fields are provided within the SYS object to access system status information.
In another embodiment, an object-oriented expression can be used to base network device behavior on any properties of a client connected to the device. In one embodiment, a CLIENT object can be provided to represent a customer's properties by sending or receiving a currently processed data stream. For example, the expression: CLIENT.IP.SR.IN_SUBNET (10.100.202.0/24), can be used to return a true / false value based on whether a client corresponding to a data stream is on a particular subnet. Or, for example, the expression CLIENT.AGENT.VERSION_NUM can be used to retrieve the version number of a client agent running on the client. Or, for example, the expression: CLIENT.VLAN.VIRTUAL_IP can be used to access a client's virtual IP address.
In yet another embodiment, an object-oriented expression can be used to base a network device's behavior on any property of a server connected to the device. For example, SERVER.METRICS.HTTP.AVG_RESP_TIME can be used to access the average response time for a server to generate HTTP requests. Or, for example, SERVER.ICA.MAX_CONNECTIONS. can be used to identify a maximum number of specified ICA connections for a given server. Or, for example, SERVER.ETHER.HEADER can be used to identify the initial ethernet packet records for a given connection to a server.
In some embodiments, object-oriented expression can be used to isolate a certain amount of communication from before or during processing. For example, an application serving as a proxy for HTTP communications may want to base some behavior on an initial part of the response. In that case, it may be desirable to only isolate part of the response, so that the end-to-end response time does not suffer unduly. In one embodiment, an expression can specify a number of bytes to receive before an expression is evaluated. For example, the expression HTTP.REQ.getBody (500) .TYPECAST_TO_NV_LIST ('=<sup>,</sup>,<sup>,</sup>& '). getValue (id) can be used to isolate the first bytes of an HTTP request body, and then treat those bytes as a list of name value pairs. The expression then specifies to obtain the value corresponding to the name id.
Figure 5 illustrates an example of a policy that can be used when configuring a device. In brief overview, a policy 500 comprises an expression 510 that can be evaluated in the context of a rule 505. A policy 500 can also comprise an action 515 that specifies a way of acting if the rule is satisfied.
Still with respect to figure 5, now more detailed, a policy can be used to configure a device. In some embodiments, the policy can be used to configure any device including, without limitation, a WAN 200 optimization computer, an SSL / VPN computer 200, an acceleration computer 200, a cache computer 200, a load balancing computer , and / or a device providing any combination of those devices. In another embodiment, a policy can be used to configure a client agent or a server agent.
In some embodiments, a policy mechanism running on a device can interpret, evaluate, and / or execute policies with respect to the device's functions. For example, a policy engine 236 can run on a computer 200 and interpret and execute a number of policies targeting other actions and application modules including, without limitation, an SSL / VPN module 280, an IP intranet module 282, an switch 284, a DNS module 286, an acceleration module 288, an application firewall module 290, and / or a monitoring agent
197. In some embodiments, a single set of policies may be provided to target a plurality of enforcement functions. In other embodiments, a separate set of policies can be used to configure each application role. Policies can be stored in any way inside a device. In some embodiments, a policy can be compiled before being executed on a device. In other modalities, a policy can be executed at run time.
A policy 500 can comprise one or more expressions 510. An expression in a policy can be evaluated by a device at run time against the objects specified in the expression to produce a value. A 510 expression can be any type of expression. In one embodiment, an expression 510 can be an object-oriented expression. An expression can be used anywhere within a policy. In some embodiments, an expression can be specified in a policy rule. In other modalities, an expression can be specified in a policy action.
A 500 policy can also comprise a 505 rule. The rule can be evaluated at run time against the objects, methods, and operators identified in the rule to produce a result. Depending on the result, the computer can then perform one or more actions specified in the policy. For example, if the rule evaluates how true a computer can perform the action associated with the rule. Or if the rule evaluates to false, the computer cannot perform the action associated with the rule. In some embodiments, a rule can comprise a single expression. In other embodiments, a rule can comprise a plurality of expressions connected by operators.
A policy 500 can also comprise an action 515. An action can specify any action to be taken. Examples of actions may include, without limitation, blocking or allowing data flow, transferring data flow or objects to a particular server or device, storing an object in memory, changing a part of a data flow, changing one or more system properties, perform an acceleration technique and perform a compression technique. In the illustrated policy 500, when determining that an HTTP URL request contains a JOE user identifier, the policy dictates an action to transfer the request to a specific server. In some modalities, an action may comprise an expression to be evaluated at runtime.
Figure 6 illustrates an example of an expression input screen 600 for a user to enter an object oriented expression. In brief overview, an expression entry screen 600 comprises a number of pull-down menus 620 that allow a user to specify the members of the classes to include in a created expression. Screen 610 may also comprise a monitor where a user may be able to view and / or edit a text version of the expression. The screen may also comprise a monitor 630 that displays information to the user corresponding to one or more objects.
Still with respect to figure 6, now in more detail, an expression entry screen allows the entry of object oriented expressions by a user in any way. In the illustrated mode, the pull-down menus 620 can be used to select objects. In other embodiments, any other input elements can be used to accept an object-oriented expression including, without limitation, text fields, menus, buttons, check boxes and toolbars. In some embodiments, the input elements of a screen 600 can provide functionality for a user to create and verify valid expressions. In some embodiments, the 620 pull-down menus can be populated automatically with members of the previously specified class. For example, by selecting URL from the illustrated menu, the following pull-down menu can be populated with members of the URL object class. In this way a user may be able to efficiently navigate class hierarchies and object models to generate an expression. In other modalities, syntax highlighting, self-completion, and / or self-recommendation can be used to enable a user to easily create and verify expressions. For example, a user can be provided with a 610 text field to compose an expression, in which the text field highlights any unrecognized objects or syntax in red. Or for example, a user may be provided with a text field 610 which, when the user types an object class, the text field displays a list of members of the object class.
In some embodiments, an expression entry screen 600 can display information about any objects or expressions to the user. In some embodiments, the screen 600 can display the properties and / or recommended uses of a particular class. In one embodiment, the screen 600 can be integrated with or used across one or more screens of class documentation, for example, described in figure 4B.
Figure 7A illustrates an example of a configuration interface screen that can be used to configure a plurality of policies corresponding to one or more network devices. In a brief overview, a screen displays a list of 710 network device functions with folders containing one or more policies, policy groups, or settings related to the functions. In the illustrated example, the screen displays folders for system policies, network policies, DNS policies, SSL policies, download policies, condensation policies, integrated cache policies, protection features, load balancing policies, switching policies content, cache redirection policies, global load balancing policies, SSL VPN policies, and application security policies. In some embodiments, a number of policies, policy groups, and / or settings corresponding to a role can be referred to as a profile.
Still with respect to figure 7A, known in more detail, a configuration interface can allow a user to specify policies or adjustments related to one or more network devices. In some embodiments, a configuration interface can be used to configure a computer 200 including, without limitation, a VPN computer, accelerator computer, or WAN optimization device. In some embodiments, a single configuration interface can allow a user to configure a plurality of computers. For example, a user may be able to specify one or more computers to apply a particular policy, policy group or adjustment. In one embodiment, a user may be able to specify that a number of computers share a configuration profile. For example, a user can configure a group of computers 200 so that each computer has the same policy settings. In other embodiments, a configuration interface 700 can be used to configure one or more client agents 120.
A configuration interface 700 can comprise any means of collecting input including, without limitation, GUIs and command line interfaces. A configuration interface can comprise one or more 600 expression input screens. In one embodiment, a configuration interface can read configuration information from a file. In another embodiment, a configuration interface can receive configuration information about a network. For example, a configuration interface 700 may comprise means for a user to load one or more policies, settings, policy groups or profiles. These can comprise commonly used policies or adjustments for a number of applications.
A configuration interface can hide any aspect of a policy, policy groups or configuration from a user. For example, a configuration interface can populate any part of a policy or policy group automatically or by basic value so that a user does not need to actively configure those parts. For example, a configuration interface can provide a basic stock value list, where the user only needs to specify a list of rules under which the actions are to be taken. The syntax and implementation of the actions can be completely or partially hidden from the user.
Figure 7B illustrates an example of using a computer to configure a computer using a configuration interface. In brief overview, a configuration interface 700 comprising an expression input screen 500 is displayed on a client 102. Client 102 trans80 transmits configuration data received via the configuration interface to computer 200.
Still with reference to figure 7B, now in more detail, a configuration interface 700 can be displayed on a client 102 anyway. In some embodiments, a configuration interface 700 may comprise an application running on the client. In other embodiments, a configuration interface 700 may comprise a web page displayed by the computer. In still other embodiments, a configuration interface 700 may comprise a web page displayed by a third device.
A configuration interface 700 can comprise any means for a user to enter configuration data including, without limitation, text fields, buttons, windows, check boxes, and drag and drop functions. In some embodiments, a configuration interface 700 may comprise an expression input screen 500. In some embodiments, a configuration interface may also provide screens for a user to enter one or more policies. In some embodiments, these screens can be integrated with one or more expression input screens.
A configuration interface can transmit configuration information to a computer 200 by any means. The configuration information can be transmitted via any protocol or protocols. In one embodiment, the configuration information entered by the user can be saved to a file on client 102, and then the file can be transmitted to the computer. In other embodiments, a user can enter information for a web page or a web application that can then transfer the configuration information to the computer. In some embodiments, the configuration information may be compiled, formatted, or otherwise processed before being transmitted to the computer 200. In still other embodiments, the configuration information may be compiled, formatted, or otherwise processed after having received by the computer.
Figure 8A describes an embodiment of a method of configuring an object-oriented policy of a network device with an object-oriented expression to specify structure in a payload of a packet flow received by a network device. In brief overview, a configuration interface 700 is provided by a device in order to configure a policy 600 for a network device 200 (step 801). The device receives, via configuration interface 700, an expression 610 for policy 600 (step 803). The device receives user information via the configuration interface 700, identifying an action to be taken based on an evaluation of the expression (step 805).
Still with reference to figure 8A, now in further details, a configuration interface can be provided to configure a policy 600 for a network device 200 anyway (step 801). In some embodiments, the configuration interface 700 may comprise a command line interface. In other embodiments, the configuration interface 700 may comprise a graphical user interface. The configuration interface 800 can comprise one or more drag and drop interfaces, a list selection interface, or a syntax highlighting interface. In some embodiments, the configuration interface 700 resides on a client device 102. In other embodiments, the configuration interface 700 runs on the network device 200. In some embodiments, a device providing the configuration interface 700 is connected to a computer 200 over a network 104. In some embodiments, the 700 configuration interface is a web page. In some embodiments, the configuration interface 700 is a web page that resides on the network device 200. In some embodiments, the configuration interface 700 is a web page that resides on a separate server 106.
A device receives, via configuration interface 700, an expression 610 for policy 600 specifying an object class to apply to a portion of the payload of a packet flow and a member of the object class (step 803). In some embodiments, the expression may be received via an expression entry screen 500. In one embodiment, the expression 610 identifies a portion of the text within a packet flow. In certain embodiments, expression 610 specifies a protocol, and may also specify one or more methods and fields related to the protocol. For example, the expression can specify an HTTP, HTML, FTP, SMTP, ICA, and / or SSL protocol. The specified protocol can then be applied to analyze a data stream according to the protocol.
The received expression can specify any object class. For example, the expression received can specify any object classes described in the object model in figure 4A. An object class can be specified in any way. In one embodiment, the specification of an object class can comprise the specification of an instance of the object class. For example, the expression HTTP.REQ can specify an instance of the http_resquest object in figure 4A. In some embodiments, the expression received may comprise an object-oriented expression.
The received expression can also specify any member of an identified object class. The member can understand any object, data type or method. In some modalities, the member comprises a field. In some embodiments, the member may comprise a field corresponding to a second class of object. In some embodiments, the member of the object class comprises a method. In some embodiments, the member of the object class is inherited from a main class of the object class. The object class member can correspond to an HTTP request or response. In other cases, a member of the class may be a uniform resource locator (URL) or a cookie.
In other embodiments, the expression 610 comprises an explicit typecasting. Explicit typecasting can be used to specify an object class for use with respect to a field or returned object. For example, a field containing a number can be explicitly pypecast for an alphanumeric string in order to perform a string comparison. Or for example, a stream of bytes can be typecast for a list with a certain delimiter. Or, for example, a data stream can be typecast as corresponding to a specific protocol or protocol object.
A device can receive, via configuration interface 700, information that identifies an action 615 for policy 600, action 615 to be taken based on an evaluation of expression 610 (step 805). In some embodiments, action 615 may comprise an object-oriented expression. In certain modalities, the method performs action 615 in order to provide load balancing, content switching, application security, application distribution, network acceleration, or application acceleration. For example, in order to accelerate network activity, the method can evaluate a 610 expression to determine the user's location and, based on the user's location, apportion user traffic to the geographically closest server or servers 106. In some modalities, a policy can perform security, acceleration, load balancing or content switching functions by rewriting a URL in any HTTP request or response. For example, an action 625 may specify to modify the HTTP request so that the URL refers to a specific server or server site 106. In some cases, action 615 received from configuration interface 700 may be an expression for no action or for a stock of basic value.
Figure 8B describes a modality of an application method, by a device, object-oriented expression 610 in a policy 600 to specify a structure in a payload of a packet flow by a computer 200. In brief, an application 200 identifies a policy 600 comprising an object oriented expression 610 to evaluate against a payload of a received packet flow (step 821). Computer 200 assigns values to a data structure specified by object oriented expression 610 based on a part of the payload (step 823). Computer 200 performs an evaluation of expression 610 based on the assigned values (step 825) and performs, in response to the evaluation, an action 615 specified by policy 600 (step 827).
Still with respect to figure 8B, now in additional details, a computer can identify a policy to apply to a data stream anyway (step 821). In some embodiments, a computer can read a policy from one or more configuration files. In other embodiments, a policy mechanism 236 on a computer can store a number of policies in memory. In still other embodiments, a computer can identify a policy in response to a data flow type or protocol. For example, a computer can have a set of policies applied to all incoming TCP flows. Or, for example, a computer can identify one or more policies that are applied to SSL flows. In one embodiment, a computer can identify a policy based on a dispatcher or recipient of a data stream. For example, a VPN computer can be provided with a set of policies that are applied to connection requests that arrive from customers. Or, an accelerator device can identify one or more policies to apply to an HTTP stream from a server 106. In some embodiments, the policy can comprise a policy received via a configuration interface 700.
The packet stream can be received in any way, and from any source. In some embodiments, the packet flow can be intercepted transparently by the computer. In other embodiments, the computer can receive the packet flow in the process of proxying one or more transport layer connections. The packet flow can comprise any type of packets including, without limitation, IP packets, TCP packets, UDP packets, and ICMP packets. The packet flow can comprise any other protocol or protocols.
The identified policy can comprise an object-oriented expression to evaluate against the payload of a packet flow. The object-oriented expression can comprise any type of object-oriented expression, and can specify one or more object classes, fields, and methods. In some embodiments, the object-oriented expression may comprise part of a rule. In some embodiments, the expression can specify one or more objects corresponding to a client, server, HTTP protocol, or the computer.
The object-oriented expression can be evaluated against any payload in a packet flow. In one embodiment, the expression can be evaluated with respect to the payload of a TCP or UDP stream. In another embodiment, the expression can be evaluated against an SSL flow. In yet another modality, the expression can be evaluated with respect to the payload of an ICA flow. The stream can be received from any source including, without limitation, a client, client agent, server agent, or second computer.
The computer assigns values to a data structure as specified by object oriented expression 610 (step 823). A data structure can comprise the physical representation of an object instance. In some embodiments, the computer can analyze part or all of the payload received to assign the values. In other embodiments, the computer can execute any methods specified by the expression or included in an object model to assign values. For example, with respect to the expression.
The HTTP.REQ application. HEADER (AcceptLanguage) .TYPECAST_TO_LIST (,) can assign values to an object corresponding to each request, initial record, and comma-delimited specified list. In some embodiments, the assignment of values may comprise the determination of a part or parts of the data flow corresponding to an object. In some embodiments, step 823 includes applying, by computer 200, a class specified by object-oriented expression 610 for a payload byte flow. For example, if an expression specifies a URL class, the computer can assign a value to a highlight in a URL data structure by determining the start and end points of a URL within the received payload. These start and end points can then be stored in a URL data structure and used to execute any of the methods in the URL class. In some embodiments, the computer can assign values to a plurality of data structures specified by the object-oriented expression. In one embodiment, the policy mechanism 236 can perform any functions related to the evaluation of a policy.
The computer can perform an evaluation of the 610 expression based on the assigned values anyway (step 825). In some embodiments, the computer can use one or more methods of an object class specified by the expression to perform the evaluation. In some embodiments, the assessment can produce a Boolean value. In other modalities, the evaluation can produce an integer, a sequence or another object. The computer can use the assigned values in any way. In the URL example above, the computer, after determining a start and end point for the URL, can then use these values to perform any operations with respect to the URL. In some embodiments, the computer can then execute the getSuffix () method referred to in figure 4A, which identifies a file type suffix of the requested URL. This method can also comprise a suffix start and end point in relation to the URL start and end point. The application can then use the suffix start and end points to perform a file suffix evaluation, for example, comparing it to the .jsp string to determine whether the requested URL matches the Java Server Page.
In some embodiments, the computer can evaluate a rule by understanding the expression. In other embodiments, the computer can evaluate a rule comprising a plurality of expressions.
The computer can then, in response to the assessment, take action 615 specified by policy 600 (step 827). In one mode, the computer acts if the result of the evaluation is a value corresponding to the truth. In another mode, the computer can take an action if the evaluation result is not zero. The action taken can be any action including, without limitation, any action related to load balancing, content switching, application security, application distribution, network acceleration, or application acceleration. In some embodiments, action 615 comprises a non-action.
In some embodiments, the computer can perform the action immediately following the assessment. In other embodiments, the computer can perform the action following the assessment of at least one other policy. In yet another modality, the computer can perform the action after waiting for a predetermined period of time or waiting for a resource to become available. In one embodiment, the computer can perform the action after receiving additional parts of the packet flow.
In some embodiments, the computer can then transfer the received packet flow to one or more computer servers, clients, or client agents. The computer can perform any other network computer functions with respect to packet flow including, without limitation, acceleration, compression, and load balancing.
Figure 8C illustrates a method, on a computer 200, to apply object oriented expressions 610 to a policy 600 to specify structure in a payload of a packet flow received by computer 200. In brief overview, the computer identifies a policy 600 including an object oriented expression 610 to evaluate against a payload of a received packet flow (step 841). The computer assigns values to a data structure specified by object-oriented expression 610 based on a portion of the payload (step 843). The computer also performs an evaluation of the 610 expression based on the assigned values (step 845). In response to the assessment, the computer changes part of the received packet flow (step 847) and transmits the changed packet flow (step 849).
Still with reference to figure 8C, now more detailed, the computer can identify a policy 600 that specifies an object oriented expression 610 to evaluate with respect to a payload of a received packet flow (step 821). This step can be performed in any way described here.
The computer can assign values to a data structure specified by object oriented expression 610 based on a portion of the payload in any way (step 823). This step can be performed in any way described here.
The computer performs an expression evaluation based on the assigned values (step 845). This step can be performed in any way described here.
In response to the assessment, the computer can change a portion of the received packet flow (step 847). In some embodiments, changing part of the received packet flow may comprise an action in response to the assessment (step 827). In some embodiments, the portion of the packet flow that is changed is specified by the data structure identified by the object-oriented expression. In other embodiments, the portion of the packet flow that is changed is specified by a second object-oriented expression. In some embodiments, the portion of the packet flow to be changed can be specified by an object-oriented expression in a policy action. In some embodiments, the computer may rewrite a URL in the body of an HTTP response or request. In other embodiments, the computer can rewrite a format field value in the packet stream. The value of the format field that is changed can be a field in an HTTP request, an HTTP response, or any other field in an object that is part of the packet flow. In yet another embodiment, the computer can change one or more name value pairs contained in the packet flow. In some embodiments, the computer may rewrite part of the received packet flow to hide or remove confidential data including, without limitation, personal identification numbers, bank account routing numbers, personal contact information, social security numbers, passwords and other confidential information.
To provide a detailed example, when receiving an HTTP stream from a client destined for a server, a computer providing application security functions to the server can determine to apply a policy:
if (HTTP.Request.getCookie (). getValue (username) .length> 20 then HTTP. Request.getCookie (). setValue (username.void)
In this example, the computer can analyze part or all of the HTTP stream to identify the part of the stream containing the request, and then the cookie within the request. The computer can do this in several ways, including maintaining one or more internal data structures with reference pointers pointing to the areas of the flow corresponding to the request and cookie. The computer can then identify the value of a username's name value pairs within the cookie and determine whether the length of the value is greater than 20 characters. An extension of more than 20 characters can indicate an application error or a malicious attack, such as, for example, an isolator overflow attack. When determining that the length is greater than 20 characters, the computer can then change the value to void (empty) or any other signal that can notify the server receiving the stream that an inappropriate value has been sent by the client. The computer can then use and / or modify any internal data structures to alter the flow. The computer can then transfer the changed stream to the server. In other embodiments, the computer can simply block the flow from reaching the server when it detects the potential overflow. In these modes, the computer may return an error message to the customer.
In another mode, the computer can replace an entire HTTP response with a new response. For example, if the computer determines that an answer contains confidential data in a form, the computer can replace the answer with an answer indicating an error or with neutral content comprising the answer. In yet another modality, a computer can replace or rewrite an entire HTTP request or initial response record.
The computer can then transmit the changed packet flow in any way (step 849). In some embodiments, the computer may transfer the altered packet flow to a server or client designated as the recipient of the flow. In other embodiments, the computer can redirect the flow to a computer, server, or client other than the intended recipient of the flow. The computer can transmit the changed packet flow using any protocol or protocols including, without limitation, TCP, IP, UDP, SSL, and ICA.
E. Systems and methods for executing undefined policy expressions
Figure 9 illustrates a modality of a method, on a computer 200, for applying a policy 600 specifying an action 615 to be taken in the event that an element of policy 600 is undefined. In a brief overview, a computer identifies a policy 600 to evaluate against a payload of a received packet flow, where policy 600 specifies (i) a 610 expression, (ii) a first action based on the 610 expression and ( iii) a second section 610 to adopt if an element is undefined (step 901). The computer determines that an element of policy 600 is undefined with respect to the payload (step 903). In response to your determination that an element is undefined, the computer takes the second action (step 905). Generally speaking, the method allows a policy to specify an action to take if an error or exception is encountered when the computer attempts to evaluate the policy. In this way, the second action can be a withdrawal or an error execution method.
Still with respect to figure 9, now in greater detail, a computer identifies a policy 600 to evaluate with respect to a payload of a received packet flow, where policy 600 specifies an expression, a first action to take based on the expression 610 and a second action 610 to be taken if an element of the policy is undefined (step 901). The computer can identify the policy in any way. In one embodiment, the expression can be an object-oriented expression. In another embodiment, the expression 610 can identify an object class to apply to a portion of the payload of a packet flow and a member of the object class. In another embodiment, expression 610 specifies a protocol, and can also specify one or more related methods and fields. The expression can identify any type of object and / or object classes. In some embodiments, the expression may comprise one or more methods of an object class.
The packet stream can be received in any way and from any source. In some embodiments, the packet flow can be intercepted transparently by the application. In other embodiments, the application can receive the packet flow in the process of proxying one or more transport layer connections. The packet flow can comprise any type of packets including, without limitation, IP packets, V TCP packets, UDP packets, and ICMP packets. The packet flow can comprise any other protocol or protocols.
The first action specified by the policy can comprise any action. In some embodiments, the first action may comprise an action to be taken if the expression or a rule containing the expression evaluates to true. In some embodiments, action 615 may refer to load balancing, load switching, application security, application distribution, network acceleration, or application acceleration. In other embodiments, any 615 share may consist of no share or share of basic value.
The second action specifies an action to be taken if an element of the policy is undefined. A policy element can comprise any part of the policy including, without limitation, one or more expressions, rules, or operations. An element can be undefined in any circumstance where a computer cannot successfully assign a value to the element. In one embodiment, an element can be undefined if the element results in a comparison of incompatible types, for example, determining whether an integer is greater than a list; or a Boolean value is equal to a string. In other embodiments, an element can be undefined if the element results in one or more null values. For example, if an expression attempts to access a username value within a URL object and the expression is applied to a packet flow with a URL with no username value specified, an operation can be defined against the name user. In other embodiments, an element may be undefined as a result of one or more inappropriate typecasts.
In some embodiments, the second action may have been specified by a user via a configuration interface. For example, when entering or viewing a policy in the configuration interface, a user may be prompted to enter an action to be taken if the policy is undefined at run time. In other embodiments, the second action may comprise a second action of pre-configured basic value. For example, a group of policies may be endowed with an action of basic value to take in the event of an indefinite element. For example, a group of policies enabling URL rewriting may be provided with a second action of basic value if it does not rewrite any URLs. Or a group of policies for performing load balancing may be provided with a second action of value. basic package flow transfer to a designated assistance server.
Computer 200 can determine if an element of policy 600 is undefined with respect to the payload in any way (step 903). In some modalities, the application may determine that the policy is undefined in the policy evaluation process. In other modalities, the computer can determine that the policy is undefined in the process of precompiling, compiling or interpreting the policy. In some embodiments, the computer may determine that the policy is undefined by detecting one or more exceptions generated during the policy assessment. For example, the computer can detect a null pointer, overflow, or arithmetic processing exception during policy evaluation.
In response to the determination that an element is undefined, the computer can take the second action (step 905). The second action can comprise any action described here. In some embodiments, the second action may comprise the receipt and / or transmission of the packet flow. In other embodiments, the second action may comprise no action.
F. Systems and methods for configuring and using policy groups
Figure 10A illustrates an example of a policy bank. In brief overview, a policy bank 1000a comprises a group of one or more policies with a specified order for evaluation. In the illustrated example, the order is specified by Line numbers for each policy. Each policy can also be provided with flow instructions 1010a, 1010b, 1010c, 1010d (usually 1010) indicating a policy to be evaluated after the evaluation of the current policy.
Still with reference to figure 10A, now more detailed, a policy bank 1000 can comprise any number of policies including, without limitation, 1, 2, 3, 4, 5, 6, 10, 20, 50 and 100 policies. A policy bank's policies can comprise any policies described here. In some embodiments, a policy bank may comprise a group of policies that perform a common function. For example, a policy bank may comprise a group of policies providing load balancing functions. Or, for example, a policy bank may comprise a group of all policies to improve caching.
A policy bank can be configured in any way. In some embodiments, a configuration interface 700 may be provided that allows a user to create and group one or more policies. In some embodiments, a configuration interface may be provided that allows a user to name a particular policy bank. In other embodiments, a configuration interface can be provided that allows a user to specify one or more attributes of a policy bank. For example, a policy bank may be endowed with an action of basic value to execute in the event of an exception or indefinite policy. Or for example, a policy bank may be endowed with a set of circumstances in which the policy bank is applied. For example, a user can specify that a policy bank should be used for all incoming HTTP traffic. Or, for example, a user can specify a policy bank to be used when receiving any connection requests from new devices. In other embodiments, a policy bank may comprise a set of attributes that are used to reinforce certain characteristics in the policy bank's policies. For example, a policy bank may require that no policy in the policy bank access a particular object. The attributes of a policy bank can be enforced at configuration time or at run time.
A policy bank can be stored in any way. In some embodiments, a policy bank can be stored in a file on a computer. In other embodiments, a policy bank can be stored in a computer's 216 policy mechanism.
A policy bank can understand any means of ordering policies for evaluation. In one embodiment, a policy bank can comprise an ordered list of policies. In other embodiments, a policy bank may comprise a set of policies with one or more 1010 flow instructions indicating an order of evaluation. In still other modalities, a policy bank may comprise a numbered list of policies to be implemented in order of increasing numbers.
Each expression in a policy bank can specify a 1010 flow instruction. A 1010 flow instruction can comprise any information or expression indicating a policy to be executed in the event that a policy containing the flow instruction evaluates to true. In one embodiment, a flow instruction may comprise a NEXT statement 1010a, which indicates that the next policy at the bank should be evaluated. In another embodiment, a flow instruction may comprise a GO TO 1010b statement that identifies another policy in the policy bank to be evaluated next. In some embodiments, a GO TO statement can identify a policy by a line number. In other embodiments, a GO TO statement can identify a policy by a policy name or other identifier. In yet another modality, a flow instruction may comprise an FIM statement, which indicates that no other policy bank policy should be evaluated.
In some embodiments, a 1010 flow instruction may comprise an expression or expression to be evaluated to determine the policy to be performed next. A flow instruction can comprise any expression including, without limitation, any object oriented expression. For example, flow instruction 1010 specifies that an integer following a servnum part of a query must be added to 17 to determine the policy line to be executed next. In the example policy bank, flow instruction 1010 can be used to distribute HTTP requests across a series of servers based on a parameter in the requests.
In some embodiments, a configuration interface 700 may be provided with a means for a user to order policies within a policy bank. The configuration interface can allow a user to specify line numbers, priorities, list ordering, or any other means of specifying order of evaluation. In some embodiments, a configuration interface 700 may allow a user to specify one or more flow instructions with respect to a policy or policy bank. In other embodiments, the configuration interface may also provide any input means for entering one or more flow instructions 1010 corresponding to the policies into the policy bank.
Figure 10B illustrates a modality of a policy flow control method 600 used on a network device 200 processing a packet flow. In a brief overview, the method includes identifying, by a computer 200, a plurality of policies 600 to apply to a received packet flow, where at least one of the policies 600 includes a policy identifier (step 1001). The computer processes a first policy 600 out of a plurality of policies 600, identifying (i) a rule 605 that includes a first expression 610 (ii) a first action 615 to be taken based on an assessment of rule 605, and (iii) a second policy 600 among multiple policies (step 1003). Based on an evaluation of expression 610, the computer determines that rule 605 evaluates to true (step 1005). In response to the determination, computer 200 processes the second identified policy 600 (step 1007).
Still with reference to figure 10B, now in additional detail, the computer identifies a plurality of policies 600 to apply to a received packet flow where at least one of the plurality of policies specifies a policy identifier (step 1001). The computer can identify the plurality of policies in any way. In some embodiments, the computer can identify that the plurality of policies corresponds to the policies for a given data stream, data stream source, or data stream receiver. In one embodiment, the plurality of policies may comprise a policy bank.
The packet stream can be received in any way and from any source. In some embodiments, the packet flow can be intercepted transparently by the computer. In other embodiments, the computer can receive the packet flow in the process of proxying one or more transport layer connections. The packet flow can comprise any type of packets including, without limitation, IP packets, TCP packets, UDP packets, and ICMP packets. The packet flow can comprise any protocol or protocols.
The at least one policy identifier can understand any means of identifying a policy, including, without limitation, a line number, a policy name, or a priority number. In some embodiments, each policy 600 of the plurality of policies 600 specifies a classification indicating an order of basic value in which policies are to be processed.
Computer 200 processes a first policy 600 of the plurality of policies 600 in which the first policy 600 identifies a rule 605 that specifies a first expression 610, a first action 615 to be taken based on the evaluation of rule 605, and an expression 610 identifying a second policy 600 of the plurality of policies 600 (step
1003). The first policy can be processed according to any method for evaluating and processing a policy. In some modalities, the first policy may comprise an object-oriented expression. In other embodiments, the first policy may comprise a rule comprising an object-oriented expression.
The first policy can contain any expression identifying a second policy. In some embodiments, the first policy may include a name for the second policy. In other embodiments, the first policy 600 includes an integer that specifies the classification of a second policy 600 to be processed next if a first action 615 is applied.
In some embodiments, the first policy can comprise a 1010 flow instruction. The first policy can comprise any flow instruction, including the next, go to or end. The first policy can comprise any other elements, including, without limitation, an action to be taken if an element of the first policy is undefined. In one embodiment, the first policy is undefined. In one embodiment, each policy of the plurality of policies can comprise a flow instruction.
Based on the evaluation of expression 610 by computer 200, the computer determines that rule 605 evaluates to true (step 1005). In some embodiments, this step includes the evaluation of an object-oriented expression 610.
In response to the determination that the rule evaluates to true, computer 200 may process the second identified policy 600 (step 1007). In one embodiment, step 1007 may comprise executing a flow instruction specified by the first policy. In some embodiments, computer 200 can evaluate an expression 610 to determine a ranking of a second policy 600 among the multiple policies 600 to be processed next. In some embodiments, computer 200 can evaluate an object oriented expression 610 to determine the classification of a second policy 600 among the multiple policies 600 to be processed next. For example, the computer can evaluate an expression to evaluate a line number to be used in combination with a GO TO packet flow instruction. After determining the line number, the computer can then process the policy on the given line number.
In some embodiments, the computer can also take the action specified by the first policy when determining that the rule is true. In other modalities, when determining that the rule is true, the computer can store the action specified by the first policy in a list. This list can be used to store a series of actions to be taken. In one embodiment, as a computer processes a series of policies in a policy bank, the computer can store a list for each policy that contains a rule that is evaluated to be true. After processing the policy series, the computer can then take all actions stored in the list. In another embodiment, as a computer processes a plurality of policy banks, the computer can store a list of actions for each policy that contains a rule that it has judged to be true, after processing the series of policy banks, the computer can then adopt all actions stored in the list.
Figure 11A illustrates a block diagram illustrating flow control among a plurality of policy groups. In brief overview, policy bank 1000b comprises a number of policies. One of the policies comprises an invocation action 1110 that invokes a second policy bank 1000c. Invocation action 1110 indicates a policy bank 1000c to be processed if the policy rule containing the action evaluates to true. After processing the invoked policy bank, a computer can then resume processing the first policy bank 1000b. This processing will be further described with reference to figure 11B.
Still with respect to figure 11A, a configuration interface 700 can be provided that allows a user to specify an order of execution among the policy groups by including one or more invocation actions 1110. An invocation action can identify a group policy in a manner including, without limitation, by name, memory location, or any other identifier. In some embodiments, policy groups may comprise policy banks. In still other embodiments, an 1110 invocation action can specify a specific policy within a second policy bank.
In some embodiments, an 1110 invocation action may include one or more drivers indicating how the second policy group should be processed. In one embodiment, an 1110 invocation action contained in a first policy bank can specify whether processing of the first policy bank should be resumed after processing the invoked policy bank. In another embodiment, an action of invocation 1110 may specify whether processing of the first policy bank should be resumed or not if a sudden stop or exception is found in the policy bank invoked. For example, an invocation action may specify that if an FIM flow instruction is found in the second policy bank, processing should resume with the first policy bank. Or an invocation action can specify that if an FIM flow instruction is found in the second policy bank, no other policies in the first policy bank should be processed.
In this way, a user can configure a series of policy banks to ensure that certain policies are processed, even where the results of one or more policy banks are uncertain. For example, a policy bank providing policies to deny access to restricted URLs can invoke a policy bank to provide SQL security when it detects that a URL indicates that a request contains SQL queries. The invocation can specify that regardless of the result of processing the SQL security policy bank, processing resumes in the URL module after processing the SQL policy bank. In this way, the user can be assured that the entire bank of strict URL enforcement policy is executed, which can
100 ensure that all restricted URLs are blocked.
A user can use policy bank 1110 invocation actions to ensure that policies are not evaluated in the event that a particular policy bank encounters an exception or a sudden stop. For example, a policy bank providing content switching policies, after determining an application corresponding to a request, can invoke a policy bank containing application security policies for the application. The invocation can indicate if the application security policy bank encounters an FIM instruction, no policy should be evaluated in the switching policy bank however. This can be used in cases where the FIM instruction in the application security policy bank indicates that a security requirement has not been met, and therefore, no processing of the request should be done.
In some embodiments, a computer can be configured with one or more basic execution orders for policy groups. For example, a computer may have one or more global policy groups that are always applied first, followed by one or more computers or specific vServer policy groups that are processed following global policy groups. In some modalities, policy banks can be endowed with basic value by ordering responsive to the functions performed by policy banks. For example, a plurality of SSL policies can be applied to incoming traffic first, and then a set of security policies can be applied to decrypted traffic, followed by a bank of content switching policies.
Fig. 11B illustrates a modality of a flow control method among policy groups used in a network device 200 processing a packet flow. In a brief overview, a computer identifies a first policy group to apply a received packet flow (step 1101). The computer processes a first policy from the first policy group, where the first policy identifies (i) a 605 rule specifying a first expression 610, and (ii) information identifying a second policy group (step 1103). The computer evaluates rule 605 (step 1105). In response to the evaluation of rule 605, the computer processes the second identified policy group (step 1107). After processing the second policy group, the computer processes a second policy 600 from the first policy group (step 1109).
Still with reference to figure 11, now more detailed, a computer can identify a first policy group to apply to a received packet flow anyway (step 1101). The packet stream can be received from any source and can comprise any protocol or protocols.
In some modalities, the first policy may comprise an object-oriented expression. In other embodiments, the first policy may comprise a rule including at least one object-oriented expression and / or expression. In some embodiments, the first policy 600 specifies action 615 based on an assessment of rule 605.
Information identifying a second policy group can comprise any format of identifying information. In one embodiment, the second policy group can comprise a policy bank, and the identifying information can comprise a name of the policy bank. In some embodiments, the information identifying the second policy bank may comprise an 1110 invocation action.
The computer can process the first policy 600 in any way (step 1103). The computer can evaluate one or more expressions oriented in processing the policy.
Computer 200 can evaluate rule 605 in any way (step 1105). In some modalities, the computer can evaluate an object oriented expression 610. In some modalities, the computer can determine a Boolean value corresponding to the rule.
In response to the evaluation of rule 605, the computer processes the second identified policy group (step 1107). In some embodiments, the computer can only process the second policy group if the
102 rule to evaluate to true. In other embodiments, the computer can only process the second policy group if the rule evaluates to a value other than zero. The computer can process the second group in any way. In some embodiments, the application computer can process the second policy bank starting with a specific policy identified by an 1110 invocation action.
In some embodiments, after processing the second policy group, the computer can process a second policy from the first policy group. For example, in figure 11A, a computer can evaluate the policy on line 11 in policy bank 1000b. If the rule is true, the computer can take invocation action 1110, and the computer can process policy bank 1000c. After the processing of policy bank P3 is finished, the computer can return to policy bank 1000b and process the next instruction, which is line 12. In some embodiments, the application can only resume the first policy bank if the second policy bank results in a soft stop, such as where the last statement from a policy bank points to a NEXT statement, as in line 30 of policy bank 1000c. In other modalities, the computer can resume processing the first policy bank even where a sudden stop is indicated, such as, for example, line 11 of policy bank 1000c.
In some embodiments, the second policy group may also contain one or more invocation actions. In these modalities, the evaluation of the policy bank can be linked in many ways. In some embodiments, a computer 200 can process a third policy group, where the third policy group is identified by a policy 600 in the second policy group. In other ways, the first policy bank can be endowed with a plurality of invocation actions 1110. In these embodiments, the computer can process a third policy group, where the third policy group is identified by the second policy 600 of the first policy group. In still other embodiments, the first policy 600 specifies a second policy 600 of the first policy group to be processed after the second policy group is processed. For example, a policy comprising an 1110 invocation action may also comprise a flow instruction that specifies a policy from the first policy group to be processed after processing resumes from the second policy group.
G. Systems and methods for configuring and using application security profiles
Figure 12 illustrates a series of configuration screens 1200, 1210, 1260, 1240 for configuring an application security profile. In brief overview, a 1200 profile creation screen allows a user to enter a name and general properties for a new application security profile. A 1210 profile configuration screen allows a user to select one or more checks contained within a profile. Two 1240, 1260 scan configuration screens can allow a user to modify settings for an individual scan.
Still with respect to figure 12, now more detailed, a creation screen 1200 allows a user to enter a profile name and additional information regarding the profile. A profile can be named in any way. In some embodiments, a profile name may reflect the role or functions of the profile. Any additional information can be specified together with the profile. In one embodiment, the profile can specify information about the type of network traffic that the profile applies. For example, the profile can apply HTTP or HTML traffic. Or the profile can apply for web service traffic.
A 1210 profile configuration screen can allow a user to specify one or more checks for use with the profile. A scan can comprise any set of policies or actions related to the common security role. For example, a cookie scan may comprise a set of policies, adjustments or actions to prevent cookie tampering. Or, a credit card verification may comprise a set of policies, or actions to prevent confidential credit card information from being transmitted via a device. In an illustrated mode, a user can choose to block, alert, or log into the system with respect to a particular scan. If blocking is selected, the profile can block all traffic that does not meet the scan. If alert is selected, an administrator or user can receive an alert if a packet flow does not meet the check. If entering the system is selected, an entry can be created in the system each time a packet flow is transmitted through a device that does not meet the scan. If the profile setup screen can provide the option to modify any of these checks and rules. In some modality, any modifications for a check can be translated into an enhancement policy expression used to configure a network device.
A scan configuration screen 1240, 1260 can comprise any input device for modifying a scan, in one embodiment, a user may be able to specify one or more policies to be included in a scan. In another mode, a user may be able to modify one or more of the scan settings. A verification fit can comprise any information used by the verification in determining whether a traffic flow satisfies the verification. For example, with respect to a check that validates the start URLs, an adjustment can comprise one or more permitted start URLs. Or for example, for a form field format check, an adjustment may comprise one or more addresses to which the format check should be applied. In some modalities, an adjustment can correspond to one or more elements of an enhancement policy. For example, an allowed start URL can be incorporated as an expression in the policy rule, being endowed with an action that allows traffic to pass.
Figure 13A illustrates a flow diagram of a method for configuring one or more application security profiles for a device, where each application security profile specifies a number of checks to perform security functions related to an application.
105
In brief overview, the method comprises providing a configuration interface for configuring an application security profile (step 1301). The method comprises receiving a first adjustment, via the configuration interface, which corresponds to a first verification of the application security profile (step 1301). The method also comprises receiving, via the configuration interface, a second adjustment, which corresponds to a second verification of the application security profile (step 1305). The method also comprises identifying a policy 600 that specifies a rule 605 that includes a first expression 600 (step 1307). The method can then comprise receiving information by identifying an application security profile to be processed based on an assessment of rule 605 (step 1309).
Still with respect to figure 13A, now with additional detail, a configuration interface is provided to configure an application security profile (step 1301). The configuration interface can comprise any configuration interfaces, components and methods described here. In some embodiments, the configuration interface comprises one or more drag and drop interfaces, a list selection interface, or a syntax highlighting interface. In other embodiments, the configuration interface may comprise an expression configuration web 600. In still other embodiments, the configuration interface may comprise a series of 1300 profiling screens, 1310 verification configuration screens, and / or screens configuration settings 1340, 1360. In still other embodiments, the configuration interface 700 is a command line interface. The configuration interface can run on any device. In some embodiments, the method includes running the configuration interface 700 on a device communicating with a network device 200. In other embodiments, the method included executing the configuration interface 700 on the network device 200. In one embodiment, the method provides a user with a 1300 configuration interface to create a plurality of configuration profiles.
A device can receive, via a configuration interface, a first setting that specifies a corresponding first check of the application security profile (step 1303). In some embodiments, the device receives a URL from the configuration interface 700 to be used for the first scan. In other embodiments, the device receives an expression 610 from the configuration interface 700 specifying one or more URLs to be used for the first scan. In still other embodiments, the device receives from the configuration interface 700 an object-oriented expression 600 specifying one or more URLs to be used for the first scan. In some embodiments, the adjustment may comprise an indication of whether the scan should block, enter the system, or generate an alert regarding a packet flow that violates the scan. In other embodiments, the adjustment may comprise an element of one or more policies included in the verification.
The device also receives, via configuration interface 700, a second setting that specifies a corresponding second check of the application security profile (step 1305). This adjustment can be received in any way in which the first adjustment was received.
The device can include, via configuration interface 700, a policy 600 that specifies a rule 605 that includes a first expression 610 (step 1307). In some modalities, politics may comprise an object-oriented expression. The policy can be identified in any way. In some embodiments, the policy can be chosen from a list. In other modalities, the policy can be chosen via a drag and drop interface. In still other modalities, the policy can be automatically chosen in relation to a given profile. In one embodiment, the policy can be introduced directly by the user.
The device can receive, via interface 700, information that identifies the application security profile to be processed based on an evaluation of rule 605 (step 1309). In one embodiment, the application security profile can be represented as a policy bank, and an invocation action can be added to the policy by identifying
107 the policy bank. In some embodiments, the method includes storing the application security profile. In other embodiments, the method includes transmitting the application security profile to a network device 200.
In some embodiments, an application security profile can be specified as an action for more than one policy. For example, there may be several conditions under which an application safety profile including field consistency and insulation overflow checks should be applied. A plurality of policies, each specifying one of several conditions, each can invoke an application security profile as an action.
Figure 13B illustrates an embodiment of a method for executing one or more application security profiles for a device, each application security profile specifying a number of policy group execution security functions related to an application. In a brief overview, the method includes a computer identifying a first policy to apply to a received packet flow; where first policy 600 specifies a rule 605 that includes a first expression 610 and identifies an application security profile (step 1321). Computer 200 evaluates rule 605 (step 1323). The computer, in response to the evaluation of rule 605, processes a first scan specified by the application security profile (step 1325). In response to the evaluation of rule 605, the computer also processes a second scan specified by the application security profile (step 1327).
Still with respect to figure 13B, now in additional detail, the method includes a computer to identify a first policy to apply to a received packet flow; where first policy 600 specifies a rule 605 that includes a first expression 610 and identifies an application security profile (step 1321). In some embodiments, computer 200 comprises a VPN proxy device. In some other embodiments, computer 200 identifies a first policy 600 to apply to a received TCP packet stream. The packet flow can be
108 received in any way and from any source. The packet flow can comprise any protocol or protocols.
Computer 200 evaluates the policy rule (step 1323). The computer can evaluate the rule according to any technique. In some embodiments, the rule may comprise an object-oriented expression. In other embodiments, the rule may comprise a plurality of object-oriented expressions. In some embodiments, the computer can determine a Boolean value as a result of evaluating expression.
In response to the evaluation of rule 605, computer 200 processes a first scan specified by the application security profile (step 1325). In some embodiments, the computer can process the first scan in response to the determination that the rule is true.
The computer can process the first scan anyway. In some embodiments, the computer evaluates at least one adjustment of the first scan to determine whether or not the first scan applies. In some other embodiments, the computer determines that a URL contained in the packet flow matches at least an adjustment of the first scan, and applies the first scan in response to the determination. In still other embodiments, the computer can determine that a URL contained in the packet flow matches a 610 expression of a first check fit in response to the first check, and apply the first check in response to the determination. In other embodiments, the computer can determine that the URL contained in the packet flow matches an object oriented expression 610 from an initial scan setting. The computer can apply the first scan in response to the determination.
Also in response to the evaluation of rule 605, computer 200 processes a second check for the application security profile (step 1327). In some embodiments, the computer can process the second check in response to the determination that the rule is true. In some modalities, the method uses at least one of the first
109 verification and second verification in order to perform one of: SQL injection determination, invalid start URL detection, cookie tamper detection, shape field consistency detection, isolator overflow detection, transverse place script detection, credit card number detection, invalid URL detection. In some other embodiments, the method uses at least a first check and a second check to perform an SQL injection block, an invalid start URL block, tamper and cookie block, inconsistent field block, isolator overflow block , cross-sectional roadblock, credit card number block, and invalid URL block.
At the same time that the invention has been specifically illustrated and described with respect to specific preferred embodiments, it should be understood by those skilled in the art that various changes in form and detail can be made in the present invention without departing from the spirit or scope of the invention. as defined by the appended claims.
Contents2
27 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27
34 members in 9 offices
Priority claims13
| Document | Office | Kind | Date |
|---|---|---|---|
| 11685167 | United States of America | – | |
| 11685171 | United States of America | – | |
| 11685147 | United States of America | – | |
| 11685177 | United States of America | – | |
| 11685180 | United States of America | – | |
| 11685175 | United States of America | – | |
| 68516707 | United States of America | A | |
| 68517107 | United States of America | A | |
| 68514707 | United States of America | A | |
| 68517707 | United States of America | A | |
| 68518007 | United States of America | A | |
| 68517507 | United States of America | A | |
| 2008056671 | United States of America | W |
Members34
| Document | Office | Kind | |
|---|---|---|---|
| AU2008225150A1 | Australia | A1 | |
| CA2679499A1 | Canada | A1 | |
| US2008225719A1 | United States of America | A1 | |
| US2008225720A1 | United States of America | A1 | |
| US2008225722A1 | United States of America | A1 | |
| US2008225748A1 | United States of America | A1 | |
| US2008225753A1 | United States of America | A1 | |
| US2008229381A1 | United States of America | A1 | |
| WO2008112769A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2008112769A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2135385A2 | European Patent Office (EPO) | A2 | |
| CN101682526A | China | A | |
| US2010095018A1 | United States of America | A1 | |
| IL200736D0 | Israel | D0 | |
| HK1139534A1 | Hong Kong, China | A1 | |
| US7853678B2 | United States of America | B2 | |
| US7853679B2 | United States of America | B2 | |
| US7865589B2 | United States of America | B2 | |
| US7870277B2 | United States of America | B2 | |
| EP2456125A1 | European Patent Office (EPO) | A1 | |
| US8341287B2 | United States of America | B2 | |
| HK1171292A1 | Hong Kong, China | A1 | |
| US8490148B2 | United States of America | B2 | |
| US2013298190A1 | United States of America | A1 | |
| EP2135385B1 | European Patent Office (EPO) | B1 | |
| CN101682526B | China | B | |
| US8631147B2 | United States of America | B2 | |
| CN103560905A | China | A | |
| US2014108635A1 | United States of America | A1 | |
| BRPI0808859A2This record | Brazil | A2 | |
| EP2456125B1 | European Patent Office (EPO) | B1 | |
| US9160768B2 | United States of America | B2 | |
| US9450837B2 | United States of America | B2 | |
| CN103560905B | China | B |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Definitive dismissal - extension of time limit for request of examination expired [chapter 11.1.1 patent gazette]ExpiredB11Y | B11Y | |
| Dismissal acc. art.33 of ipl - examination not requested within 36 months of filingB11A | B11A |
Numbers
- Publication
- PI0808859
- Application
- 8088594
Titles2
- Portuguese
- SISTEMAS E MÉTODOS PARA CONFIGURAR, APLICAR E GERENCIAR POLÍTICAS DE SEGURANÇA
- English
- SYSTEMS AND METHODS FOR CONFIGURING, APPLYING AND MANAGING SECURITY POLICIES
Classification
- CPC, 8
- H04L41/0893
- H04L41/0233
- H04L41/046
- H04L43/0852
- H04L43/12
- H04L63/0457
- H04L63/102
- H04L41/0894
- IPC, 4
- H04L12 24
- H04L29 06
- H04L41 0893
- H04L41 0894
