The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 18, 2017

Filed:

May. 26, 2015
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Ming Da Ho, Taipei, TW;

Ming-Pin Hsueh, Taipei, TW;

Ting-Jui Hu, Taipei, TW;

Ping-Hung Lee, Taipei, TW;

Ming-Hsun Wu, Taipei, TW;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 15/16 (2006.01); H04L 29/08 (2006.01); G06F 21/62 (2013.01); H04L 29/06 (2006.01); H04L 12/851 (2013.01); H04L 12/801 (2013.01);
U.S. Cl.
CPC ...
H04L 63/1441 (2013.01); H04L 47/2441 (2013.01); H04L 47/33 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01);
Abstract

A security appliance system routing strings of data packets in a high availability environment. The security appliance system contains a plurality of intrusion prevention systems connected to a load balancer and a computing device. Each intrusion prevention system contains stored session state information in a local session state data store, the load balancer contains a shared hash algorithm, and the computing device contains a connection state manager containing a network session state data store. The computing device includes a topology manager recording connectivity changes of the intrusion prevention systems and accordingly adjusting the shared hash algorithm for the recorded connectivity changes. Using the shared hash algorithm and routing information, a hash value is assigned to received strings. Strings are forwarded an intrusion prevention system based on assigned hash value and processed using stored session state information within the local session state data store and the network session state data store.


Find Patent Forward Citations

Loading…