IP Library Granted Patent US 7,249,191
Granted Patent B1
US 7,249,191 · App. 10/251,101 · Granted Jul 24, 2007

Transparent bridge that terminates TCP connections

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,249,191
App. No.
10/251,101
Granted
Jul 24, 2007
Kind
B1
Abstract

A multi-application transparent platform intercepts an incoming application file communicated from a source across a first TCP connection by terminating the first TCP connection on the multi-application transparent platform and supplying the application file to an application program. The application file is received onto the platform in the form of multiple incoming Ethernet frames. The application layer program analyzes the application file and identifies characteristics of the application file, such as virus content, that are not apparent in the individual Ethernet frames that carried the application file over the first TCP connection. The platform resends the application file over a second TCP connection in outgoing frames having the same IP addresses and Ethernet MAC addresses as the incoming frames. The platform can be inserted into a running network without reconfiguring devices on the network.

Claims (42)

1. A platform, comprising:

a first interface that receives a plurality of first incoming frames, each of the first incoming frames carrying a frame payload, the frame payloads of the first incoming frames together comprising a first application file, the first application file being communicated across a first TCP connection, each of the first incoming frames having an incoming source IP address and an incoming source MAC address;

an application layer program that executes on the platform;

a mechanism that terminates the first TCP connection on the platform wherein the first application file is supplied to the application layer program, the mechanism generating a plurality of first outgoing frames, each of the first outgoing frames carrying a frame payload, the frame payloads of the first outgoing frames together comprising the first application file, each of the first outgoing frames having an outgoing source IP address that is identical to the incoming source IP address, each of the first outgoing frames having an outgoing source MAC address that is identical to the incoming source MAC address; and

a second interface that outputs the first outgoing frames.

2. The platform of claim 1 , wherein the second interface has a MAC address that is different than the incoming source MAC address, and wherein the second interface has an IP address that is different than the incoming source IP address.

3. The platform of claim 1 , wherein the first application file is stored on the platform, the application layer program examines the first application file, and the first application file is used to generate the first outgoing frames.

4. The platform of claim 1 , wherein the first application file is a data accumulation representing a voice communication.

5. The platform of claim 1 , wherein the first TCP connection is defined by a first TCP source port and a first TCP destination port,

and wherein the first outgoing frames are output from the second interface across a second TCP connection, the second TCP connection being defined by the same first TCP source port and the same first TCP destination port.

6. The platform of claim 5 , wherein the first interface and the second interface are physical network connections, wherein the first TCP connection extends into the platform across the first interface, and wherein the second TCP connection extends from the platform across the second interface.

7. The platform of claim 5 , wherein the platform determines that the second TCP connection can be established before the mechanism terminates the first TCP connection.

8. The platform of claim 5 , wherein the first interface receives a plurality of second incoming frames, each of the second incoming frames carrying a frame payload, the frame payloads of the second incoming frames together comprising a second application file, the second application file being communicated across the first TCP connection, each of the second incoming frames having the incoming source IP address and the incoming source MAC address; and

wherein the second application file is supplied to the application layer program, the mechanism generates a plurality of second outgoing frames, and the second interface outputs the second outgoing frames, each of the second outgoing frames carrying a frame payload, the frame payloads of the second outgoing frames together comprising the second application file, each of the second outgoing frames having an outgoing source IP address that is identical to the incoming source IP address, each of the second outgoing frames having an outgoing source MAC address that is identical to the incoming source MAC address.

9. A method, comprising:

receiving a plurality of first incoming frames, each of the first incoming frames carrying a frame payload, the frame payloads of the first incoming frames together comprising a first application file, the first application file being communicated across a first TCP connection, each of the first incoming frames having an incoming source IP address and an incoming source MAC address; terminating the first TCP connection;

executing an application layer program on the first application file;

generating a plurality of first outgoing frames, each of the first outgoing frames carrying a frame payload, the frame payloads of the first outgoing fames together comprising the first application file, each of the first outgoing frames having an outgoing source IP address that is identical to the incoming source IP address, each of the first outgoing frames having an outgoing source MAC address that is identical to the incoming source MAC address; and

outputting the first outgoing frames.

10. The method of claim 9 , further comprising:

terminating a second TCP connection, wherein the outgoing frames are output across the second TCP connection, the first TCP connection being defined by a first TCP source port and a first TCP destination port, the second TCP connection being defined by the same first TCP source port and the same first TCP destination port.

11. The method of claim 10 , further comprising:

receiving a plurality of second incoming frames, each of the second incoming frames carrying a frame payload, the frame payloads of the second incoming frames together comprising a second application file, the second application file being communicated across the first TCP connection, each of the second incoming frames having an incoming source IP address and an incoming source MAC address;

executing the application layer program on the second application file;

generating a plurality of second outgoing frames, each of the second outgoing frames carrying a frame payload, the frame payloads of the second outgoing frames together comprising the second application file, each of the second outgoing frames having an outgoing source IP address that is identical to the incoming source IP address, each of the second outgoing frames having an outgoing source MAC address that is identical to the incoming source MAC address; and

outputting the second outgoing frames.

12. A system, comprising:

a first mechanism that receives a plurality of first incoming frames, each of the first incoming frames carrying a frame payload, the frame payloads of the first incoming frames together comprising a first application file, the first application file being communicated across a first TCP connection, each of the first incoming frames having an incoming source IP address and an incoming source MAC address; and

a second mechanism that terminates the first TCP connection, the second mechanism generating a plurality of first outgoing frames, each of the first outgoing frames carrying a frame payload, the frame payloads of the first outgoing frames together comprising the first application file, each of the first outgoing frames having an outgoing source IP address that is identical to the incoming source IP address, each of the first outgoing frames having an outgoing source MAC address that is identical to the incoming source MAC address, the first mechanism outputting the first outgoing frames.

13. The system of claim 12 , wherein the first mechanism comprises network address translation software executing on a first processor, and the second mechanism comprises TCP and IP software executing on the first processor.

14. The system of claim 12 , further comprising:

a third mechanism having an application layer program, the third mechanism receiving the first application file from the second mechanism, the application layer program executing on the first application file.

15. The system of claim 14 , wherein the application layer program executes on a second processor.

16. A platform, comprising:

a first interface that receives a plurality of incoming frames, each of the incoming frames carrying a frame payload, the frame payloads of the incoming frames together comprising a data payload, the data payload being communicated across a first TCP connection, each of the incoming frames having an incoming source IP address and an incoming source MAC address;

a program that analyzes the data payload, the program being of a network layer higher than the transport layer;

a mechanism that terminates the first TCP connection on the platform such that the data payload is supplied to the program, the mechanism generating a plurality of outgoing frames, each of the outgoing frames carrying a frame payload, the frame payloads of the outgoing frames together comprising the data payload, each of the outgoing frames having an outgoing source IP address that is identical to the incoming source IP address, each of the outgoing frames having an outgoing source MAC address that is identical to the incoming source MAC address; and

a second interface that outputs the outgoing frames.

17. The platform of claim 16 , wherein the data payload is taken from the group consisting of: streaming video data, and streaming voice data.

18. The platform of claim 16 , wherein the data payload is a file, and wherein the program is an application layer program that analyzes the file.

19. The platform of claim 16 , wherein the data payload is a web page that references a plurality of files, and wherein the program analyzes each of the plurality of files.

20. The platform of claim 16 , wherein the data payload is a voice communication, and wherein the program converts the voice communication into a stream of text data, and wherein the program then analyzes the stream of text data to identify a particular pattern of spoken words in the voice communication.

Assignments (13)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0144 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0178 →
MERGER Recorded Feb 14, 2007
From: OSITIS SOFTWARE, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 018889/0796 →
MERGER Recorded Feb 27, 2004
From: OSITIS SOFTWARE, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 015012/0497 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2002
From: HUTCHISON, PAUL; SMITH, CAMERON; OSITIS, VILIS
To: OSITIS SOFTWARE, INC.
Reel/Frame 013535/0023 →