Patents by Inventor William A. Roberson

William A. Roberson has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10050936
    Abstract: A security device for processing network flows is described, including: one or more packet processors configured to receive incoming data packets associated with network flows where a packet processor is assigned as an owner of network flows and each packet processor processes data packets associated with flows for which it is the assigned owner; and a packet processing manager configured to assign ownership of network flows to the packet processors where the packet processing manager includes a global flow table containing global flow table entries mapping network flows to packet processor ownership assignments and a predict flow table containing predict flow entries mapping predicted network flows to packet processor ownership assignments. A predict flow entry includes a predict key and associated packet processor ownership assignment. The predict key includes multiple data fields identifying a predicted network flow where one or more of the data fields have a wildcard value.
    Type: Grant
    Filed: December 10, 2015
    Date of Patent: August 14, 2018
    Assignee: Palo Alto Networks, Inc.
    Inventor: William A. Roberson
  • Patent number: 9906495
    Abstract: A network security device includes a network flow statistics processing engine to process network flow information related to network flows. The network flow statistics processing engine includes a first processing stage performing per-flow information aggregation and a second processing stage performing per-destination system component information aggregation, with each processing stage implementing a threshold-based data export scheme and a timer-based data export scheme. In this manner, up-to-date flow information is available to peer system components regardless of the varying flow rates of the network flow.
    Type: Grant
    Filed: November 18, 2016
    Date of Patent: February 27, 2018
    Assignee: Palo Alto Networks, Inc.
    Inventors: Sidong Li, William A. Roberson, Savitha Raghunath, Subramani Ganesh, Gyanesh Saharia
  • Patent number: 9762538
    Abstract: A security device for processing network flows includes one or more packet processors configured to receive incoming data packets associated with one or more network flows where a packet processor is assigned as an owner of one or more network flows and each packet processor processes data packets associated with flows for which it is the assigned owner; and a packet processing manager configured to assign ownership of network flows to the one or more packet processors where the packet processing manager includes a global flow table containing entries mapping network flows to packet processor ownership assignments. The packet processing manager informs a packet processor of an ownership assignment after one or more packets are received, and the one or more packet processors learns of ownership assignments of network flows from the packet processing manager.
    Type: Grant
    Filed: June 2, 2015
    Date of Patent: September 12, 2017
    Assignee: Palo Alto Networks, Inc.
    Inventors: William A. Roberson, Wilson Xu
  • Publication number: 20170142066
    Abstract: A network security device includes a network flow statistics processing engine to process network flow information related to network flows. The network flow statistics processing engine includes a first processing stage performing per-flow information aggregation and a second processing stage performing per-destination system component information aggregation, with each processing stage implementing a threshold-based data export scheme and a timer-based data export scheme. In this manner, up-to-date flow information is available to peer system components regardless of the varying flow rates of the network flow.
    Type: Application
    Filed: November 18, 2016
    Publication date: May 18, 2017
    Inventors: Sidong Li, William A. Roberson, Savitha Raghunath, Subramani Ganesh, Gyanesh Saharia
  • Patent number: 9531672
    Abstract: A network security device includes a network flow statistics processing engine to process network flow information related to network flows. The network flow statistics processing engine includes a first processing stage performing per-flow information aggregation and a second processing stage performing per-destination system component information aggregation, with each processing stage implementing a threshold-based data export scheme and a timer-based data export scheme. In this manner, up-to-date flow information is available to peer system components regardless of the varying flow rates of the network flow.
    Type: Grant
    Filed: July 30, 2014
    Date of Patent: December 27, 2016
    Assignee: Palo Alto Networks, Inc.
    Inventors: Sidong Li, William A. Roberson, Savitha Raghunath, Subramani Ganesh, Gyanesh Saharia
  • Patent number: 9467422
    Abstract: A method in a security device for processing network flows includes storing local counter values for one or more events and providing global event counters to maintain event statistics for events in the security device. In one embodiment, the method stores local counter value of an event for each packet processor reporting the event in a counter memory and the method sums the local counter values of an event stored in the counter memory to generate the global counter sum value for the event. In another embodiment, the method compares the global counter sum to a threshold value to put the event in a conforming state or non-conforming state. The method sends a multicast message to the interested packet processors indicating an event has transitioned to a non-conforming state.
    Type: Grant
    Filed: February 17, 2015
    Date of Patent: October 11, 2016
    Assignee: Palo Alto Networks, Inc.
    Inventors: William A. Roberson, Wilson Xu
  • Publication number: 20160164836
    Abstract: A security device for processing network flows is described, including: one or more packet processors configured to receive incoming data packets associated with network flows where a packet processor is assigned as an owner of network flows and each packet processor processes data packets associated with flows for which it is the assigned owner; and a packet processing manager configured to assign ownership of network flows to the packet processors where the packet processing manager includes a global flow table containing global flow table entries mapping network flows to packet processor ownership assignments and a predict flow table containing predict flow entries mapping predicted network flows to packet processor ownership assignments. A predict flow entry includes a predict key and associated packet processor ownership assignment. The predict key includes multiple data fields identifying a predicted network flow where one or more of the data fields have a wildcard value.
    Type: Application
    Filed: December 10, 2015
    Publication date: June 9, 2016
    Inventor: William A. Roberson
  • Patent number: 9240975
    Abstract: A security device for processing network flows is described, including: one or more packet processors configured to receive incoming data packets associated with network flows where a packet processor is assigned as an owner of network flows and each packet processor processes data packets associated with flows for which it is the assigned owner; and a packet processing manager configured to assign ownership of network flows to the packet processors where the packet processing manager includes a global flow table containing global flow table entries mapping network flows to packet processor ownership assignments and a predict flow table containing predict flow entries mapping predicted network flows to packet processor ownership assignments. A predict flow entry includes a predict key and associated packet processor ownership assignment. The predict key includes multiple data fields identifying a predicted network flow where one or more of the data fields have a wildcard value.
    Type: Grant
    Filed: March 15, 2013
    Date of Patent: January 19, 2016
    Assignee: Palo Alto Networks, Inc.
    Inventor: William A. Roberson
  • Publication number: 20150341314
    Abstract: A security device for processing network flows includes one or more packet processors configured to receive incoming data packets associated with one or more network flows where a packet processor is assigned as an owner of one or more network flows and each packet processor processes data packets associated with flows for which it is the assigned owner; and a packet processing manager configured to assign ownership of network flows to the one or more packet processors where the packet processing manager includes a global flow table containing entries mapping network flows to packet processor ownership assignments. The packet processing manager informs a packet processor of an ownership assignment after one or more packets are received, and the one or more packet processors learns of ownership assignments of network flows from the packet processing manager.
    Type: Application
    Filed: June 2, 2015
    Publication date: November 26, 2015
    Inventors: William A. Roberson, Wilson Xu
  • Publication number: 20150229610
    Abstract: A method in a security device for processing network flows includes storing local counter values for one or more events and providing global event counters to maintain event statistics for events in the security device. In one embodiment, the method stores local counter value of an event for each packet processor reporting the event in a counter memory and the method sums the local counter values of an event stored in the counter memory to generate the global counter sum value for the event. In another embodiment, the method compares the global counter sum to a threshold value to put the event in a conforming state or non-conforming state. The method sends a multicast message to the interested packet processors indicating an event has transitioned to a non-conforming state.
    Type: Application
    Filed: February 17, 2015
    Publication date: August 13, 2015
    Inventors: William A. Roberson, Wilson Xu
  • Patent number: 9077702
    Abstract: A security device for processing network flows includes one or more packet processors configured to receive incoming data packets associated with one or more network flows where a packet processor is assigned as an owner of one or more network flows and each packet processor processes data packets associated with flows for which it is the assigned owner; and a packet processing manager configured to assign ownership of network flows to the one or more packet processors where the packet processing manager includes a global flow table containing entries mapping network flows to packet processor ownership assignments. The packet processing manager informs a packet processor of an ownership assignment after one or more packets are received, and the one or more packet processors learns of ownership assignments of network flows from the packet processing manager.
    Type: Grant
    Filed: March 15, 2013
    Date of Patent: July 7, 2015
    Assignee: Palo Alto Networks, Inc.
    Inventors: William A. Roberson, Wilson Xu
  • Patent number: 8997223
    Abstract: A security device for processing network flows includes packet processing cards with packet processors formed thereon where each packet processing card stores local counter values for one or more events and a packet processing manager including global event counters to maintain event statistics for events in the security device. In one embodiment, the packet processing manager stores a copy of the local counter value of an event for each packet processor reporting the event in the counter memory and the global event counter provides a global counter sum value for the event by summing the copies of local counter values in the local memory. In another embodiment, the global counter sum is compared to a threshold value to put the event in a conforming state or non-conforming state. The packet processing manager sends a multicast message to the interested packet processors indicating an event has transitioned to a non-conforming state.
    Type: Grant
    Filed: March 15, 2013
    Date of Patent: March 31, 2015
    Assignee: Palo Alto Networks, Inc.
    Inventors: William A. Roberson, Wilson Xu
  • Patent number: 5920705
    Abstract: A method and apparatus for dynamically shifting between switching and routing packets efficiently to provide high packet throughput. The present invention provides a method for transmitting packets between an upstream node and a downstream node in a network that utilizes flow classification and labelling to redirect flows. The method includes the steps of establishing default virtual channels between the upstream node and the downstream node, receiving a packet at the downstream node, performing a flow classification at the downstream node on the packet to determine whether the packet belongs to a specified flow that should be redirected in the upstream node, selecting a free label at the downstream node, and informing the upstream node that future packets belonging to the specified flow should be sent with the selected free label attached.
    Type: Grant
    Filed: January 30, 1997
    Date of Patent: July 6, 1999
    Assignee: Nokia IP, Inc.
    Inventors: Thomas Lyon, Peter Newman, Greg Minshall, Robert Hinden, Fong Ching Liaw, Eric Hoffman, Lawrence B. Huston, William A. Roberson