| CPC H04L 45/38 (2013.01) [H04L 41/0894 (2022.05); H04L 43/026 (2013.01); H04L 45/745 (2013.01); H04L 47/10 (2013.01); H04L 47/20 (2013.01); H04L 47/2483 (2013.01)] | 20 Claims |

|
1. A method comprising:
identifying a data protocol or application for a second network traffic flow expected to be subsequent to a first network traffic flow, wherein identifying the data protocol or application comprises,
based on identifying a first application level protocol for the first network traffic flow, selecting a pattern database of the first application level protocol;
based on matching a pattern in the first network traffic flow with an entry in the pattern database while scanning the first network traffic flow, extracting first traffic flow identifying information from the first network traffic flow according to the matching entry, wherein the matching entry indicates how to locate flow identifying information based on the matched pattern; and
associating an identifier of the first application level protocol with the first traffic flow identifying information; and
applying a policy indicated for the first application level protocol to the second network traffic flow based on the second network traffic flow being identified by the first traffic flow identifying information.
|