IP Library Granted Patent US 7,536,715
Granted Patent B2
US 7,536,715 · App. 10/304,469 · Granted May 19, 2009

Distributed firewall system and method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,536,715
App. No.
10/304,469
Granted
May 19, 2009
Kind
B2
Abstract

A system and method for restricting packet transfer to a computer across a network, wherein the computer includes a network interface device coupled to the network and wherein the network interface device includes a packet filter. A security server is connected to the network. A packet is received at the network interface device and the network interface device determines if the packet is an authorized transaction. If the packet is not an authorized transaction, the packet is routed to the security server, where the security server determines whether the packet is an authorized transaction. If the security server determines that the packet is an authorized transaction, the network interface device is configured to accept similar transactions.

Claims (90)

1. A method of restricting packet transfer to a computer across a network, wherein the computer includes a network interface device coupled to the network and wherein the network interface device includes a packet filter, the method comprising:

providing a security server connected to the network;

receiving a packet at the network interface device;

determining, at the network interface device, whether the packet is a previously authorized transaction;

if the packet is not a previously authorized transaction, routing the packet to the security server;

determining, at the security server, whether the packet is an authorized transaction; and

if the security server determines that the packet is an authorized transaction, configuring the network interface device to accept similar transactions.

2. The method according to claim 1 , wherein determining whether the packet is an authorized transaction at the security server includes authenticating the source of the packet.

3. The method according to claim 1 , wherein configuring includes filtering the packet using a packet filter.

4. The method according to claim 3 , wherein filtering includes applying quality of service policies to the packet.

5. The method according to claim 1 , wherein configuring includes initiating end-to-end IPSEC for similar transactions.

6. The method according to claim 1 , wherein configuring includes encrypting a packet to be transferred to the network interface device, transferring the encrypted packet to the network interface device, decrypting the encrypted packet at the network interface device, and configuring the network interface device as a function of the decrypted packet.

7. The method according to claim 1 , wherein determining whether the packet is an authorized transaction at the security server includes configuring the network interface device to reject similar transactions if the packet is not an authorized transaction.

8. The method according to claim 1 , wherein determining whether the packet is an authorized transaction at the security server further includes configuring other network interface devices to reject similar transactions if the packet is not an authorized transaction.

9. An article comprising a computer readable medium having instructions thereon, wherein the instructions, when executed in a computer, create a system for executing the method of claim 1 .

10. A method of restricting packet transfer from a computer across a network, wherein the computer includes a network interface device coupled to the network and wherein the network interface device includes a packet filter, the method comprising:

providing a security server connected to the network;

receiving a packet at the network interface device;

determining, at the network interface device, whether the packet is a previously authorized transaction;

if the packet is not a previously authorized transaction, routing the packet to the security server;

determining, at the security server, whether the packet is an authorized transaction; and

if the security server determines that the packet is an authorized transaction, configuring the network interface device to permit similar transactions.

11. The method according to claim 10 , wherein determining, at the network interface device, whether the packet is a previously authorized transaction includes comparing the source address to the host address.

12. The method according to claim 10 , wherein determining whether the packet is an authorized transaction at the security server includes authenticating the source of the packet.

13. The method according to claim 10 , wherein configuring includes filtering the packet using a packet filter.

14. The method according to claim 13 , wherein filtering includes applying quality of service policy to the packet.

15. The method according to claim 10 , wherein configuring includes initiating end-to-end IPSEC for similar transactions.

16. The method according to claim 10 , wherein configuring includes encrypting a packet to be transferred to the network interface device, transferring the encrypted packet to the network interface device, decrypting the encrypted packet at the network interface device, and configuring the network interface device as a function of the decrypted packet.

17. The method according to claim 10 , wherein determining whether the packet is an authorized transaction at the security server includes configuring the network interface device to reject similar transactions if the packet is not an authorized transaction.

18. The method according to claim 10 , wherein determining whether the packet is an authorized transaction at the security server further includes configuring other network interface devices to reject similar transactions if the packet is not an authorized transaction.

19. An article comprising a computer readable medium having instructions thereon, wherein the instructions, when executed in a computer, create a system for executing the method of claim 10 .

20. A method of limiting source spoofing in the transfer of packets from a computer across a network, wherein the computer includes a processor and a network interface device coupled between the processor and the network, wherein the computer has a computer address and wherein the network interface device includes a packet filter, the method comprising:

preparing a packet having a source address and a destination;

transferring the packet from the processor to the network interface device;

examining the packet within the network interface device, wherein examining includes comparing the source address to the computer address;

if the source address matches the computer address, transferring the packet across the network to the destination;

if the source address does not match the computer address, preventing the packet from being transferred across the network to the destination and, instead, forwarding the packet to a security server;

receiving, at the network interface device, a message from the security server, wherein the message includes authorization information corresponding to a packet previously sent from the network interface device to the security server; and

wherein the authorization information configures the network interface device to accept transactions similar to the packet previously sent from the network interface device to the security server.

21. The method of claim 20 , wherein forwarding includes encrypting the packet and transferring the encrypted packet to the security server.

22. An article comprising a computer readable medium having instructions thereon, wherein the instructions, when executed in a computer, create a system for executing the method of claim 20 .

23. A computer system, comprising:

a network;

a computer connected to the network through a network interface device; and

a security server;

wherein the network interface device includes logic for transmitting information from the network interface device to the security server independent of the computer and wherein the security server configures the network interface device as a function of the transmitted information.

24. The system of claim 23 , wherein the logic includes an encryption circuit for encrypting data to be transferred from the network interface device to the security server.

25. The system of claim 23 , wherein the security server includes means for authenticating a user to the system.

26. The system of claim 23 , wherein the security server includes audit analysis.

27. A computer system, comprising:

a network;

a computer connected to the network;

a router connected to the network, wherein the router includes a packet filter; and

a security server connected to the router over the network;

wherein the router receives packets from the network, filters the packets using the packet filter to detect unauthorized packets and transmits unauthorized packets over the network to the security server independent of the computer; and

wherein the security server configures the router packet filter after analysis of the unauthorized packets.

28. The system of claim 27 , wherein the router includes an encryption circuit for decrypting encrypted packets and for encrypting the decrypted packets before forwarding them to their destination.

29. The system of claim 28 , wherein the security server includes an encryption circuit and wherein communication from the security server to the router can be encrypted by the security server's encryption circuit.

30. The system of claim 27 , wherein the security server includes means for authenticating a user to the system.

31. The system of claim 27 , wherein the security server includes audit analysis.

32. A computer system, comprising:

a network;

a computer connected to the network through a network interface device; and

a security server capable of communicating with the network interface device;

wherein the network interface device includes a packet filter, wherein the packet filter includes quality of service control for managing traffic flowing through the network interface device; and

wherein the security server transfers configuration information to the network interface device to modify quality of service parameters on the network interface device as a function of changing security conditions within the computer system.

33. The system of claim 32 , wherein the network interface device further includes an encryption circuit for encrypting data to be transferred from the network interface device to the security server.

34. The system of claim 32 , wherein the security server includes means for authenticating a user to the system.

35. The system of claim 32 , wherein the computer system further comprises a router having a packet filter, wherein the packet filter includes quality of service control for managing traffic flowing through the router and wherein the security server transfers configuration information to the router to modify quality of service parameters on the router as a function of changing security conditions within the computer system.

36. A distributed firewall system, comprising:

a plurality of computers, including a first computer, wherein the plurality of computers are connected through network interface cards to a network; and

a security server connected to the network;

wherein the network interface card for the first computer includes logic which selectively forwards packets addressed to the first computer from the network interface card to the security server;

wherein the security server determines whether the packet is an authorized transaction; and

wherein if the server determines that the packet is an authorized transaction, the security server configures the network interface device to accept similar transactions.

37. The system according to claim 36 , wherein the network interface card for the first computer includes encryption and decryption logic.

38. The system according to claim 37 , wherein the security server includes encryption and decryption logic, wherein the encryption and decryption logic encrypts packets to be transferred to the network interface card for the first computer.

39. The system according to claim 36 , wherein the network interface card for the first computer includes a packet filter and wherein the packet filter detects packets to be forwarded to the security server.

40. The system according to claim 36 , wherein the network interface card for the first computer includes encryption and decryption logic and wherein the packets to be forwarded to the security server are encrypted on the network interface card before being transmitted to the security server.

41. A method of providing computer security services to the computer of a remote user, comprising:

providing a security server;

installing a network interface device in the computer, wherein the network interface device includes logic for transmitting information from the network interface device to the security server independent of the computer;

transmitting information from the network interface device to the security server; and

configuring the network interface device as a function of the information transmitted from the network interface device to restrict packet transfer through the network interface device.

42. The method of claim 41 , wherein transmitting includes initiating a session, wherein initiating a session includes authenticating the user to the security server; and

wherein configuring the network interface device includes restricting packet transfer as a function of the user.

43. The method of claim 41 , wherein the network interface device includes a packet filter and wherein configuring the network interface device includes transferring packet filtering rules from the security server to the network interface device, wherein transferring includes modifying the packet filtering rules as a function of changing security conditions.

44. The method of claim 41 , wherein the network interface device includes a packet filter, wherein the packet filter includes quality of service control for managing traffic flowing through the network interface device; and

wherein configuring the network interface device includes transferring information from the security server to the network interface device modifying quality of service parameters on the network interface device as a function of changing security conditions.

45. An article comprising a computer readable medium having instructions thereon, wherein the instructions, when executed in a computer, create a system for executing the method of claim 41 .

Assignments (15)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 024456/0724 →
CHANGE OF NAME Recorded Mar 25, 2010
From: SECURE COMPUTING CORPORATION
To: SECURE COMPUTING, LLC
Reel/Frame 024128/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2008
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 021523/0713 →
SECURITY AGREEMENT Recorded Sep 14, 2006
From: SECURE COMPUTING CORPORATION; CIPHERTRUST, INC.
To: CITICORP USA, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 018247/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2003
From: MARKHAM, THOMAS R.
To: SECURE COMPUTING CORPORATION
Reel/Frame 013806/0276 →