The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 31, 2020

Filed:

Jul. 30, 2015
Applicant:

Nicira, Inc., Palo Alto, CA (US);

Inventors:

Azeem Feroz, San Jose, CA (US);

Vasantha Kumar, Tamil Nadu, IN;

James Christopher Wiese, Dublin, CA (US);

Amit Vasant Patil, Pune, IN;

Assignee:

NICIRA, INC., Palo Alto, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 12/927 (2013.01); G06F 9/455 (2018.01); G06F 16/9535 (2019.01); H04L 29/06 (2006.01); G06F 16/958 (2019.01);
U.S. Cl.
CPC ...
G06F 9/45558 (2013.01); G06F 16/9535 (2019.01); G06F 16/972 (2019.01); H04L 63/0236 (2013.01); H04L 63/0281 (2013.01); H04L 63/0876 (2013.01); H04L 63/20 (2013.01); G06F 2009/45587 (2013.01); G06F 2009/45595 (2013.01);
Abstract

A method for performing network access filtering and/or categorization through guest introspection on a device data compute node (DCN) that executes on a host is provided. The method, through a guest introspector installed on the DCN, intercepts a data message that the DCN is preparing to send. The method identifies a category of the network resource. The method uses the category of the network resource to examine a set of network access policies that are stored on the host in order to determine whether the network access should be allowed. The method identifies a network access policy that requires the rejection of the network access when the access to the network resource causes an aggregate bandwidth for accessing the identified category of network resource to exceed a bandwidth threshold. The method rejects the network access based on the identified network access policy.


Find Patent Forward Citations

Loading…