Yonghui Cheng - Santa Clara CA, US Yi Sun - San Jose CA, US
Assignee:
Juniper Networks, Inc. - Sunnyvale CA
International Classification:
G06F 15/16 G06F 12/00
US Classification:
709227, 709213, 709229
Abstract:
A network device is described in which a dedicated resource scheduler monitors memory consumption to provide for improved processing of communication sessions. The scheduler maintains a dependency list of communication sessions, and reserves memory for communication sessions as requests for memory are received. The amount of memory reserved is determined based on the amount of memory currently reserved for the communication sessions in the dependency list. The network device may control ongoing communication sessions by way of window manipulation. Communication sessions are processed in a first mode when available memory has not reached a predetermined amount, while communication sessions are processed in a second mode when available memory reaches a predetermined amount.
Yonghui Cheng - Santa Clara CA, US Yi Sun - San Jose CA, US
Assignee:
Juniper Networks, Inc. - Sunnyvale CA
International Classification:
G06F 15/16 G06F 12/00
US Classification:
709227, 713188
Abstract:
A network device is described in which a dedicated resource scheduler monitors memory consumption to provide for improved processing of communication sessions. The scheduler maintains a dependency list of communication sessions, and reserves memory for communication sessions as requests for memory are received. The amount of memory reserved is determined based on the amount of memory currently reserved for the communication sessions in the dependency list. The network device may control ongoing communication sessions by way of window manipulation. Communication sessions are processed in a first mode when available memory has not reached a predetermined amount, while communication sessions are processed in a second mode when available memory reaches a predetermined amount.
Yonghui Cheng - Santa Clara CA, US Yi Sun - San Jose CA, US
Assignee:
Juniper Networks, Inc. - Sunnyvale CA
International Classification:
G06F 15/16 G06F 12/00
US Classification:
709227
Abstract:
A network device is described in which a dedicated resource scheduler monitors memory consumption to provide for improved processing of communication sessions. The scheduler maintains a dependency list of communication sessions, and reserves memory for communication sessions as requests for memory are received. The amount of memory reserved is determined based on the amount of memory currently reserved for the communication sessions in the dependency list. The network device may control ongoing communication sessions by way of window manipulation. Communication sessions are processed in a first mode when available memory has not reached a predetermined amount, while communication sessions are processed in a second mode when available memory reaches a predetermined amount.
Lock-Less Access Of Pre-Allocated Memory Buffers Used By A Network Device
Monty S. Gill - San Jose CA, US Yi Sun - San Jose CA, US
Assignee:
Juniper Networks, Inc. - Sunnyvale CA
International Classification:
H04L 12/28
US Classification:
370254, 370412, 711150, 711154
Abstract:
In general, the present disclosure describes techniques for both removing memory buffers from and adding memory buffers to a list (e. g. , a linked list) of available buffers, for use by a network device, without locking the list during access. One example method includes allocating a list of memory buffers that are each available for use by multiple modules executed within the network device, wherein the list includes a first end and a second, opposite end, and removing a first memory buffer from the first end of the list by a first module of the multiple modules without locking the list. The method further includes adding the first memory buffer to the second end of the list by a second module of the multiple modules without locking the list.
Hitoshi Takanashi - Fremont CA, US Yi Sun - San Jose CA, US
International Classification:
G06F 15/173
US Classification:
709225000
Abstract:
A technique includes selectively preventing decryption of a file by a client based on whether a network connection exists between the client and a server.
Dynamic Session Migration Between Network Security Gateways
Meng Xu - Los Altos CA, US Yi Sun - San Jose CA, US
Assignee:
VARMOUR NETWORKS, INC. - Santa Clara CA
International Classification:
G06F 15/173
US Classification:
709223
Abstract:
A method and apparatus is disclosed herein for migrating session information between security gateways are disclosed. In one embodiment, receiving, at a first security gateway, session information associated with a session corresponding to a network connection, the session information having been transferred from a second security gateway, the first and second security gateway being separate physical devices; and thereafter performing security processing for the session at the first security gateway.
Yi Sun - San Jose CA, US Meng Xu - Los Altos CA, US
International Classification:
H04L 12/46
US Classification:
370392, 370401
Abstract:
A method and apparatus is disclosed herein for IP packet tunneling in a network. In one embodiment, the method comprises receiving, at a first network device, a first IP packet of a IP connection; creating a second IP packet by replacing information in a field in the first IP packet with a session ID identifying the IP connection; and forwarding, by the first network device, the second IP packet to the second network device in the distributed network environment.
Distributed Computer Network Zone Based Security Architecture
Yi Sun - San Jose CA, US Meng Xu - Los Altos CA, US Lee Cheung - Foster City CA, US Sean Wang - Santa Clara CA, US
International Classification:
H04L 29/06
US Classification:
726 12, 726 11
Abstract:
A method and apparatus is disclosed herein for distributed zone-based security. In one embodiment, the method comprises: determining an ingress security zone associated with an ingress of a first network device based on a first key and a media access control (MAC) address of a source of a packet; determining an egress security zone of a second network device based on a MAC address of a destination for the packet and a second key; performing a policy lookup based on the ingress security zone and the egress security zone to identify a policy to apply to the packet; and applying the policy to the packet.
Mckinsey & Company - Greater New York City Area May 2012 - Dec 2012
Analyst
Centerline Capital Investment Group - Greater New York City Area Feb 2012 - Apr 2012
Tax Associate
University of Montana - Missoula, Montana Area Jun 2011 - Aug 2011
Business Service Assistant
WY Associates Inc Jul 2010 - Sep 2010
Pension Plan Assistant Intern
JP Morgan Asset Management Jun 2009 - Sep 2009
Trading Department Intern
Education:
Bentley University - McCallum Graduate School of Business 2009 - 2012
Master, Accountancy&Taxation
Shanghai International Studies University 2005 - 2009
Bachelor, Accountancy
MIT 2011 - 2015
Ph.D., Mathematics
University of Cambridge 2010 - 2011
M.A.St., Mathematics
Harvard University 2006 - 2010
A. M., Mathematics
Harvard University 2006 - 2010
A.B., Mathematics with secondary field in Economics
Consultant- Supply Chain at Resources Global Professionals
Location:
Other
Industry:
Logistics and Supply Chain
Work:
Resources Global Professionals since Feb 2013
Consultant- Supply Chain
Evergreen Inc - Richmond, Virginia Area Jun 2012 - Dec 2012
Logistics Analyst
The Walt Disney Company- Supply Chain Solution Group - Orlando Jan 2012 - Jun 2012
Supply Chain Strategy and Operations Professional Intern
Protexer Inc. - Knoxville, Tennessee Area Jul 2011 - Aug 2011
Business Analyst Intern
Raindrops Networking Technology (Shanghai) Co. Ltd Oct 2008 - May 2010
Distribution Manager
Education:
The University of Tennessee at Knoxville 2010 - 2011
MBA, Supply Chain and Marketing
Heriot-Watt University 2002 - 2003
Master of Science, Logistics and Supply Chain Management
Shanghai International Studies University 1992 - 1996
BA, International Trade
Peoples Daily Online San Mateo, CA Aug 2012 to Dec 2012 Journalist AssistantConfucius Institute San Francisco, CA Apr 2011 to Dec 2011 Administrative AssistantHangzhou Bank
Jul 2010 to Sep 2010 Loan Officer Assistant
Education:
San Francisco State University 2009 to 2013 B.S. in Financial Services
Skills:
Proficient in PC and Macintosh OS platforms Microsoft Office 2010; Apple iWork