IP Library Granted Patent US 7,093,287
Granted Patent B1
US 7,093,287 · App. 09/687,100 · Granted Aug 15, 2006

Method and system for building dynamic firewall rules, based on content of downloaded documents

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,093,287
App. No.
09/687,100
Granted
Aug 15, 2006
Kind
B1
Abstract

A method for filtering incoming data from an external computer network is provided. This method includes scanning the contents of incoming data for pre-selected keyword(s) and allowing it to pass per standard service rules if its content does not contain the pre-selected keyword(s). If the incoming data does contain pre-selected keywords, it is blocked and added to a “known-block” filtering table. Once added to the filtering table, the site will automatically be blocked in the future without having its contents scanned again for pre-selected keywords.

Claims (49)

1. A method for filtering incoming data from an external computer network, comprising:

a firewall that is coupled to said external computer network;

a server computer system coupled to an internal computer network;

a plurality of clients that are coupled to said server computer system, said plurality of clients being unable to access said external computer network directly;

receiving, at said firewall, a document from said external computer network;

determining, by said firewall, whether said document is from a known blocked site;

in response to determining that said document is from a known blocked site, blocking, by said firewall, said document without scanning said document;

determining, by said firewall, whether said document is from a known safe site;

in response to determining that said document is from a known safe site, forwarding, by said firewall, said document to said server without scanning said document, all of said plurality of clients being permitted to access said forwarded document;

in response to determining that said document is not from a known blocked site or a known safe site, scanning, by said firewall, text fields included in said document for pre-selected keyword(s);

blocking, by said firewall, the document if any of said text fields include content that contains pro-selected keywords;

said server computer system being prohibited from receiving said document in response to said document being blocked; and

indicating that a site that sent said document is a known blocked site by adding, by said firewall, the address of said site to a filtering table.

2. The method according to claim 1 , wherein the document is allowed to pass per standard service rules if the content does not contain pre-selected keyword(s).

3. The method according to claim 1 , further comprising storing an indication in said filtering table of each known safe site that can be passed per standard service rules without having to be scanned for pre-selected keywords.

4. The method according to claim 1 , wherein the step of indicating that a site that sent said document is a known blocked site by adding, by said firewall, the address of a site to a filtering table further comprises adding the address of the site to a “known-block” table when said site has sent a document that includes said pre-selected keywords so that the site will be blocked in the future without having its contents scanned for pre-selected keywords.

5. The method according to claim 1 , wherein addition of a site to the filtering table is implemented using a strong text parsing language.

6. The method according to claim 1 , wherein the instance of the filter is periodically refreshed to enact the updated filtering tables.

7. A computer program product in a computer readable medium for use in a data processing system for filtering incoming data from an external computer network, the computer program product comprising:

a firewall that is coupled to said external computer network;

a server computer system coupled to an internal computer network;

a plurality of clients that are coupled to said server computer system, said plurality of clients being unable to access said external computer network directly;

instructions for receiving, at said firewall, a document from said external computer network;

instructions for determining, by said firewall, whether said document is from a known blocked site;

in response to determining that said document is from a known blocked site, instructions for blocking said document without scanning said document;

instructions for determining, by said firewall, whether said document is from a known safe site;

in response to determining that said document is from a known safe site, instructions for forwarding said document to said server without scanning said document, all of said plurality of clients being permitted to access said forwarded document;

in response to determining that said document is not from a known blocked site or a known safe site, instructions for scanning, by said firewall, text fields included in said document for pre-selected keyword(s);

instructions for blocking, by said firewall, the document if any of said text fields include content that contains pre-selected keywords;

said server computer system being prohibited from receiving said document in response to said document being blocked; and

instructions for indicating a site that sent said document is a known blocked site by adding, by said firewall, the address of said site to a filtering table.

8. The computer program product according to claim 7 , further comprising instructions for allowing the document to pass per standard service rules if the content does not contain pre-selected keyword(s).

9. The computer program product according to claim 7 , further comprising instructions for storing an indication in said filtering table of each known safe site that can be passed per standard service rules without having to be scanned for pre-selected keywords.

10. The computer program product according to claim 7 , wherein the instructions for indicating that a site that sent said document is a known blocked site by adding, by said firewall, that address of said site to a filtering table further comprises adding the address of said site to a “known-block” table when said site has sent a document includes said pre-selected keywords so that the site will be blocked in the future without having its contents scanned for pre-selected keywords.

11. The computer program product according to claim 7 , wherein the instructions for addition of a site to the filtering table are implemented in a strong text parsing language.

12. The computer program product according to claim 7 , wherein the instance of the filter is periodically refreshed to enact the updated filtering tables.

13. A system for filtering incoming data from an external computer network, the system comprising:

a firewall that is coupled to said external computer network;

a server computer system coupled to an internal computer network;

a plurality of clients that are coupled to said server computer system, said plurality of clients being unable to access said external computer network directly;

said firewall for receiving a document from said external computer network;

said firewall for determining whether said document is from a known blocked site;

in response to determining that said document is from a known blocked site, said firewall for blocking said document without scanning said document;

said firewall for determining whether said document is from a known safe site;

in response to determining that said document is from a known safe site, said firewall for forwarding said document to said server without scanning said document, all of said plurality of clients being permitted to access said forwarded document;

in response to determining that said document is not from a known blocked site or a known safe site, said firewall for scanning text fields included in said document for pre-selected keyword(s);

said firewall for blocking the document if any of said text fields include content that contains pre-selected keywords;

said server computer system being prohibited from receiving said document in response to said document being blocked; and

said firewall for indicating that a site that sent said document is a known blocked site by adding the address of said site to a filtering table.

Assignments (13)
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 061377/0208 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 061377/0231 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN IP RECORDED AT R/F 045327/0877 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061179/0602 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN IP RECORDED AT R/F 054260/0746 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061521/0086 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 30, 2020
From: BARRAUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054260/0746 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 045327/0934 Recorded Apr 15, 2019
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 048895/0841 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 14, 2018
From: BARRACUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045327/0877 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 14, 2018
From: BARRACUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045327/0934 →
RELEASE OF SECURITY INTEREST Recorded Jan 8, 2018
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 045027/0870 →
SECURITY INTEREST Recorded Oct 12, 2012
From: BARRACUDA NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 029218/0107 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2008
From: WHITE SEAL, INC
To: BARRACUDA NETWORKS, INC
Reel/Frame 021172/0847 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2008
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: WHITE SEAL INC
Reel/Frame 021172/0896 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2000
From: GUSLER, CARL PHILLIP; HAMILTON, RICK ALLEN II
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 011279/0659 →