The present invention provides an integrated prevention of header, state,
rate and content anomalies along with network policy enforcement. A
hardware based apparatus classifies layers 2, 3, 4 and 7 network data and
maintains rate-thresholds through continuous and adaptive learning. In
the process of classifying the packets, the apparatus can determine
header and state anomalies and drop packets containing those anomalies.
Accurate detection and prevention of layer 7 content anomalies is
achieved using fragment assembly, TCP reorder and retransmission removal
components, which also identify anomalies in those areas. Content
inspection is achieved at high speed through a Content Inspection Engine.
The apparatus integrates advantageous solutions to prevent anomalous
packets and enables a policy based packet filter.