IP Library Granted Patent US 7,023,861
Granted Patent B2
US 7,023,861 · App. 09/912,305 · Granted Apr 4, 2006

Malware scanning using a network bridge

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,023,861
App. No.
09/912,305
Granted
Apr 4, 2006
Kind
B2
Abstract

A network bridge ( 14 ) has an associated malware scanner ( 16 ) that serves to concatenate portions of a data file from within data packets intercepted by the network bridge ( 14 ) and then scan the data file concerned before the data file is forwarded to its intended recipient by the network bridge ( 14 ). The network bridge ( 14 ) may be inserted in a network topology without requiring significant network configuration changes. The network bridge ( 14 ) may include a packet analysis unit ( 56 ) that serves to intercept only data packets having a predetermined network layer protocol or a predetermined application layer protocol.

Claims (74)

1. A network bridge, said network bridge including a malware scanner:

wherein said network bridge is address-transparent with respect to data packets passing therethrough, such that at least in terms of addressing, no configuration changes are required when said network bridge is introduced in an associated network segment;

wherein, upon receipt of at least one of said data packets, said network bridge determines if said at least one data packet is intended for a recipient on a side of said network bridge on which said at least one data packet was received;

wherein, if it is determined that said at least one data packet is intended for a recipient on a side of said network bridge on which said at least one data packet was received, said at least one data packet is not passed by said network bridge;

wherein, if it is determined that said at least one data packet is not intended for a recipient on a side of said network bridge on which said at least one data packet was received, it is determined if said at least one data packet has a predetermined network layer protocol selected from the group consisting of TCP/IP; IPX; SNA; and Appletalk;

wherein, if it is determined that said at least one data packet has said predetermined network layer protocol, it is determined if said at least one data packet has a predetermined application layer protocol selected from the group consisting of SMTP; FTP; HTTP; SMB; and NFS;

wherein, if it is determined that said at least one data packet has said predetermined application layer protocol, portions of a data file from a plurality of said data packets are concatenated to form a data file to be scanned;

wherein, if it is determined that said at least one data packet does not have said predetermined application layer protocol, said at least one data packet is passed by said network bridge without being scanned.

2. A network bridge as claimed in claim 1 , wherein said malware scanner is operable to scan for one or more of:

computer viruses;

Trojans;

worms;

banned computer programs; and

banned words within e-mail messages.

3. A network bridge as claimed in claim 1 , wherein data that has been scanned by said malware scanner is forwarded to its intended recipient.

4. A network bridge as claimed in claim 1 , wherein said malware scanner is formed of one or more of:

a software based malware scanner; and

a hardware based malware scanner.

5. A network bridge as claimed in claim 1 , wherein said network bridge includes a pair of network interface units that operate to receive said data packets on an associated network line and pass said at least one data packet to a packet analysis unit connected thereto, said packet analysis unit coupled to a software based malware scanner and a hardware based malware scanner.

6. A network bridge as claimed in claim 1 , wherein a plurality of said malware scanners is included with said network bridge, each malware scanner adapted for handling different predetermined network layer protocols and different predetermined application layer protocols, where said malware scanners are passed said at least one data packet based on said determination whether said at least one data packet has said predetermined network layer protocol and said determination whether said at least one data packet has said predetermined application layer protocol.

7. A network bridge as claimed in claim 1 , wherein, after scanning, a data file is broken down into said data packets for forwarding to an intended recipient.

8. A network bridge comprising:

means for intercepting at least one data packet,

means for forwarding at least a portion of said at least one data packet to a malware scanner for scanning, and

means for forwarding data from said at least one data packet after scanning to an intended recipient;

wherein said network bridge is address-transparent with respect to data packets passing therethrough, such that at least in terms of addressing, no configuration changes are required when said network bridge is introduced in an associated network segment;

wherein, upon receipt of at least one of said data packets, said network bridge determines if said at least one data packet is intended for a recipient on a side of said network bridge on which said at least one data packet was received;

wherein, if it is determined that said at least one data packet is intended for a recipient on a side of said network bridge on which said at least one data packet was received, said at least one data packet is not passed by said network bridge;

wherein, if it is determined that said at least one data packet is not intended for a recipient on a side of said network bridge on which said at least one data packet was received, it is determined if said at least one data packet has a predetermined network layer protocol selected from the group consisting of TCP/IP; IPX; SNA; and Appletalk;

wherein, if it is determined that said at least one data packet has said predetermined network layer protocol, it is determined if said at least one data packet has a predetermined application layer protocol selected from the group consisting of SMTP; FTP; HTTP; SMB; and NFS;

wherein, if it is determined that said at least one data packet has said predetermined application layer protocol, portions of a data file from a plurality of said data packets are concatenated to form a data file to be scanned;

wherein, if it is determined that said at least one data packet does not have said predetermined application layer protocol, said at least one data packet is passed by said network bridge without being scanned.

9. A malware scanner in combination with a network bridge, comprising:

means for receiving at least a portion of at least one data packet intercepted by said network bridge,

means for concatenating said at least one data packet into a data file to be scanned, and

means for forwarding said data file after scanning to an intended recipient via said network bridge;

wherein said network bridge is address-transparent with respect to data packets passing therethrough, such that at least in terms of addressing, no configuration changes are required when said network bridge is introduced in an associated network segment;

wherein, upon receipt of at least one of said data packets, said network bridge determines if said at least one data packet is intended for a recipient on a side of said network bridge on which said at least one data packet was received;

wherein, if it is determined that said at least one data packet is intended for a recipient on a side of said network bridge on which said at least one data packet was received, said at least one data packet is not passed by said network bridge;

wherein, if it is determined that said at least one data packet is not intended for a recipient on a side of said network bridge on which said at least one data packet was received, it is determined if said at least one data packet has a predetermined network layer protocol selected from the group consisting of TCP/IP; IPX; SNA; and Appletalk;

wherein, if it is determined that said at least one data packet has said predetermined network layer protocol, it is determined if said at least one data packet has a predetermined application layer protocol selected from the group consisting of SMTP; FTP; HTTP; SMB; and NFS;

wherein, if it is determined that said at least one data packet has said predetermined application layer protocol, portions of a data file from a plurality of said data packets are concatenated to form a data file to be scanned;

wherein, if it is determined that said at least one data packet does not have said predetermined application layer protocol said at least one data packet is passed by said network bridge without being scanned.

10. A malware scanner as claimed in claim 9 , wherein said malware scanner is operable to scan for one or more of:

computer viruses;

Trojans;

worms;

banned computer programs; and

banned words within e-mail messages.

11. A malware scanner as claimed in claim 9 , wherein said malware scanner is formed of one or more of:

a software based malware scanner; and

a hardware based malware scanner.

12. A method of malware scanning comprising the steps of:

receiving at least one data packet at a network bridge;

sending at least a portion of said at least one data packet from said network bridge to a malware scanner;

concatenating data received by said malware scanner to form a data file to be scanned;

scanning said data file with said malware scanner; and

forwarding said data file after scanning via said network bridge to an intended recipient;

wherein said network bridge is address-transparent with respect to data packets passing therethrough, such that at least in terms of addressing, no configuration changes are required when said network bridge is introduced in an associated network segment;

wherein, upon receipt of at least one of said data packets, said network bridge determines if said at least one data packet is intended for a recipient on a side of said network bridge on which said at least one data packet was received;

wherein, if it is determined that said at least one data packet is intended for a recipient on a side of said network bridge on which said at least one data packet was received, said at least one data packet is not passed by said network bridge;

wherein, if it is determined tat said at least one data packet is not intended for a recipient on a side of said network bridge on which said at least one data packet was received, it is determined if said at least one data packet has a predetermined network layer protocol selected from the group consisting of TCP/IP; IPX; SNA; and Appletalk;

wherein, if it is determined that said at least one data packet has said predetermined network layer protocol, it is determined if said at least one data packet has a predetermined application layer protocol selected from the group consisting of SMTP; FTP; HTTP; SMB; and NFS;

wherein, if it is determined that said at least one data packet has said predetermined application layer protocol, portions of a data file from a plurality of said data packets are concatenated to form a data file to be scanned;

wherein, if it is determined that said at least one data packet does not have said predetermined application layer protocol, said at least one data packet is passed by said network bridge without being scanned.

13. A method as claimed in claim 12 , wherein said scanning scans for one or more of:

computer viruses;

Trojans;

worms;

banned computer programs; and

banned words within e-mail messages.

14. A method as claimed in claim 12 , wherein said malware scanner is formed of one or more of:

a software based malware scanner; and

a hardware based malware scanner.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Aug 1, 2005
From: NETWORKS ASSOCIATES TECHNOLOGY, INC.
To: MCAFEE, INC.
Reel/Frame 016593/0812 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2001
From: MAKINSON, GRAHAM A.; BAULK, EAMONN J.; WOLFF, DANIEL J.
To: NETWORKS ASSOCIATES TECHNOLOGY, INC.
Reel/Frame 012020/0611 →