IP Library Granted Patent US 7,171,681
Granted Patent B1
US 7,171,681 · App. 09/774,001 · Granted Jan 30, 2007

System and method for providing expandable proxy firewall services

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,171,681
App. No.
09/774,001
Granted
Jan 30, 2007
Kind
B1
Abstract

A mechanism that enables flexible expansion of proxy firewall services is disclosed. In accordance with the present invention, the firewall system can be configured to include a dispatch host computer and one or more load host computers. Proxy firewall services can be provided by proxy applications that reside on either the dispatch host computer and/or the load host computers. In one embodiment, a load host computer can be configured to support multiple proxy applications. In other embodiments, a load host computer can be dedicated to a single resource intensive application. In this framework, a network administrator can flexibly decide how to accommodate the demand for proxy firewall services. Load hosts can be added or removed from the firewall system without disrupting ongoing security services. In one embodiment, this feature is enabled through the inclusion of a configuration file on the dispatch host computer that stores information relating to the load host computers in the firewall system.

Claims (35)

1. A computer system for providing proxy firewall services for a computer network, comprising:

a dispatch host computer, said dispatch host computer being connectable to an external network; and

at least one load host computer coupled to said dispatch host computer, said at least one load host computer configured to provide proxy firewall services, said at least one load host computer being connectable to one or more application servers, wherein said connection from the external network is distributed from said dispatch host computer to a particular load host computer based on an analysis of the type of protocol of the connection and an analysis of activity across the load host computers;

wherein said at least one load host computer and said dispatch host computer communicate information regarding the connection of said at least one load host computer to the computer system;

wherein said dispatch host computer includes a configuration file with information relating to load host computers in the computer system, wherein upon the connection of another load host computer to the computer system, said configuration file is updated to reflect the availability of said another load host computer in the computer system.

2. The computer system of claim 1 , wherein said dispatch host computer includes a monitoring element that listens for connections on multiple ports.

3. The computer system of claim 2 , wherein said monitoring element is a dispatch proxy.

4. The computer system of claim 1 , wherein said at least one load host computer is a protocol specific load host computer.

5. The computer system of claim 1 , wherein said at least one load host computer can handle multiple protocols.

6. The computer system of claim 1 , wherein said dispatch host computer provides proxy firewall services.

7. A method of providing proxy firewall services for a computer network, comprising: identifying a set of load host computers, each load host computer in said set of load host computers being configured to provide proxy firewall services;

monitoring one or more incoming ports at a dispatch host computer for a connection;

upon identification of said connection, selecting from said set of load host computers a load host computer to which said connection should be forwarded based on an analysis of the type of protocol of said connection and an analysis of activity across the load host computers;

wherein said identifying comprises communicating information between said dispatch host computer and said load host computers relating to the availability of said load host computers.

8. The method of claim 7 , wherein said monitoring comprises monitoring for a connection with a dispatch proxy that monitors one or more incoming ports on said dispatch host computer simultaneously.

9. The method of claim 7 , wherein said selecting comprises selecting a load host computer based on a round robin load distribution among said load host computers.

10. The method of claim 7 , wherein said selecting comprises selecting a load host computer based on the availability of the load host computers.

11. The method of claim 7 , wherein said selecting comprises selecting a load host computer based on the percentage of the total number of simultaneous proxied connections the load host computer can support.

12. The method of claim 7 , wherein said selecting comprises selecting a load host computer that can support a resource intensive protocol.

13. A firewall network resource method comprising: identifying a resource intensive protocol;

designating a load host computer for providing primary support for said resource intensive protocol; and

routing a connection for said resource intensive protocol from a dispatch host computer to said designated load host, wherein said designated load host provides exclusive support for said resource intensive protocol and wherein designating includes analyzing activity across a plurality of host computers and selecting a load host computer based on the load host computer activity analysis.

14. The method of claim 13 , further comprising:

processing on the dispatch host computer a connection for at least one protocol other than said resource intensive protocol.

15. The method of claim 13 , wherein said designated load host is dedicated to said resource intensive protocol.

16. The method of claim 13 , further comprising:

designating another load host for multi-purpose support.

17. The method of claim 13 , wherein said dispatch host computer has multi-purpose support.

18. A method of expanding proxy firewall services for a computer network comprising: receiving a connecting at a dispatch host computer;

selecting a first load host computer to which the connection should be forwarded;

forwarding said connection to said first load host computer;

connecting a second load host computer to said dispatch host computer; and

updating a configuration file on said dispatch host computer to reflect the connection of said second load host computer, wherein upon said updating, said second load host computer is available to process forwarded connections from said dispatch host computer, wherein said updating comprises communicating information between said dispatch host computer and said second load host computer regarding the availability of said second load host computer.

19. The method of claim 18 , wherein said connecting and said updating occur during the provision of proxy firewall services.

20. The method of claim 18 , wherein said connecting includes signaling the dispatch host computer upon connection.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 024456/0724 →
CHANGE OF NAME Recorded Mar 25, 2010
From: SECURE COMPUTING CORPORATION
To: SECURE COMPUTING, LLC
Reel/Frame 024128/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2008
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 021523/0713 →