白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Bypassing a firewall for authorized flows using software defined networking

專利號
US10079805B2
公開日期
2018-09-18
申請人
FUJITSU LIMITED(JP Kawasaki)
發(fā)明人
David D. Jameson; Russell DeMolay
IPC分類
G06F9/00; H04L29/06
技術(shù)領(lǐng)域
sdn,firewall,router,may,data,flow,criteria,packet,network,pe
地域: Kawasaki-Shi, Kanagawa

摘要

Methods and systems for managing authorized data flows using software defined networking include receiving flow criteria sent from a firewall and extracted from a first data packet, determining whether flow criteria of the first data packet matches an entry in a master data flow list, inserting the flow criteria from the first data packet into the master data flow list on a software defined networking controller, and sending the flow criteria of the first data packet to the router. The router may forward a second data packet associated with the data flow toward a destination based on the validation of the first data packet by the firewall. The flow criteria may not match an entry in a router data flow list on the router and may include at least two of: a source IP address, a destination IP address, a destination port, and a protocol of transmission.

說明書

SDN flow arbiter 504 may communicate with firewall flow master list 508 over link 518, and may communicate with SDN flow limiter 506 over link 514. SDN flow arbiter 504 may determine whether a data flow was recently forwarded to an SDN controller with a delay or wait period. The delay or wait period may account for the latency of the link 516 to the SDN controller, the SDN controller, and/or any subsequent links from the SDN controller. SDN flow arbiter 504 may also send the flow criteria to a firewall flow master list to determine whether the flow criteria matches an entry. A timestamp associated with the entry may be found based on a matching entry. The timestamp may be compared to a current timestamp to determination whether the flow criteria was recently inserted or updated in the list. Firewall flow master list 508 may communicate with SDN flow limiter 520 to avoid saturation of link 516 to an SDN controller and/or any other portion of the network. Although flow validation unit 502, SDN flow arbiter 504, SDN flow limiter 506, and firewall flow master list 508 are shown in communication in order, the elements of firewall 500 may be connected in any order suitable to validate unknown data flows and/or reduce the likelihood of network saturation.

權(quán)利要求

1
微信群二維碼
意見反饋