IP Library Granted Patent US 7,818,565
Granted Patent B2
US 7,818,565 · App. 10/459,111 · Granted Oct 19, 2010

Systems and methods for implementing protocol enforcement rules

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,818,565
App. No.
10/459,111
Granted
Oct 19, 2010
Kind
B2
Abstract

A protocol management system is capable of detecting certain message protocols and applying policy rules to the detected message protocols that prevent intrusion, or abuse, of a network's resources. In one aspect, a protocol message gateway is configured to apply policy rules to high level message protocols, such as those that reside at layer 7 of the ISO protocol stack.

Claims (45)

1. A method for managing one or more communication protocols, the method comprising:

providing a protocol message gateway in an enterprise network, the protocol message gateway comprising a proxy server, the protocol message gateway operative to communicate with a firewall of the enterprise network;

receiving first messages with the protocol message gateway over the enterprise network, the protocol message gateway further operative to determine whether selected ones of the first messages use a target protocol and, in response to said determination, implement policy rules associated with the target protocol;

providing a proxy enforcer within the enterprise network operative to passively listen for second messages that bypass the protocol message gateway;

detecting a selected second message with the proxy enforcer, said detecting comprising determining that a message protocol associated with the selected second message matches an instant messaging protocol definition file;

in response to detecting the selected second message, using the proxy enforcer to force the selected second message to use a defined port on the protocol message gateway; and

using the protocol message gateway to implement at least one of the policy rules in association with the selected second message.

2. The method of claim 1 , wherein using the protocol message gateway to implement at least one of the policy rules comprises terminating a communication connection associated with the selected second message.

3. The method of claim 1 , wherein using the protocol message gateway to implement at least one of the policy rules comprises resetting a communication connection associated with the selected second message.

4. The method of claim 1 , wherein determining that a message protocol associated with the selected second message matches an instant messaging protocol definition file comprises determining whether the selected second message includes a string of five characters in an incoming packet header, wherein the five characters represent a signature of the instant messaging protocol.

5. The method of claim 1 , wherein using the protocol message gateway to implement at least one of the policy rules comprises creating a log comprising information associated with the selected second message and any related messages.

6. The method of claim 1 , wherein determining that a message protocol associated with the selected second message matches an instant messaging protocol definition file comprises determining whether the selected second message is directed to port 8080 or port 5190 .

7. The method of claim 1 , wherein determining that a message protocol associated with the selected second message matches an instant messaging protocol definition file comprises determining whether the selected second message includes a string “?message=”.

8. The method of claim 1 , wherein determining that a message protocol associated with the selected second message matches an instant messaging protocol definition file comprises determining whether the selected second message includes a string “?pword=%1”.

9. A protocol enforcer, comprising:

a protocol definition file, the protocol definition file being associated with an instant messaging protocol; and

a network interface configured to interface the protocol enforcer with an enterprise network, the protocol enforcer configured for:

passively listening, via the network interface, for messages that bypass a protocol message gateway within the enterprise network,

detecting a selected message in response to said passive listening, said detecting comprising determining when the message protocol matches the protocol definition file, and

in response to detecting the selected message, performing at least one of:

forcing the selected message to use a defined communication connection on a protocol message gateway, and

applying a policy enforcement rule associated with the protocol definition file that terminates a communication connection associated with the selected message.

10. The protocol enforcer of claim 9 , wherein determining when the message protocol matches the protocol definition file comprises determining if the selected message includes a string of five characters in an incoming packet header, wherein the five characters represent a signature of the instant messaging protocol.

11. The protocol enforcer of claim 9 , wherein determining when the message protocol matches the protocol definition file comprises determining if the selected message is directed to port 5190 .

12. The protocol enforcer of claim 9 , wherein determining when the message protocol matches the protocol definition file comprises determining if the selected message includes a string ?message=.

13. The protocol enforcer of claim 9 , wherein applying the policy enforcement rule comprises creating a log comprising information associated with the selected message and any related messages.

14. The protocol enforcer of claim 9 , wherein determining when the message protocol matches the protocol definition file comprises determining if the selected message includes a string ?pword=%1.

15. A protocol management system, comprising:

a protocol message gateway comprising a proxy server, the protocol message gateway operative to:

receive first messages from one or more client devices over an enterprise network,

determine whether selected ones of the first messages use a first target protocol, and

in response to said determination, implement first policy rules associated with the first target protocol; and

a protocol enforcer, the protocol enforcer comprising:

a protocol definition file, and

a network interface configured to interface the protocol enforcer with the enterprise network,

the protocol enforcer configured for:

detecting a second message that bypasses the protocol message gateway, said detecting comprising inspecting a message protocol associated with the second message to determine if the message protocol is an instant messaging protocol, and

in response to detecting the second message, forcing the second message to use a defined communication connection on the protocol message gateway.

16. The protocol management system of claim 15 , wherein the protocol enforcer is further configured to apply a policy enforcement rule in association with the second message, said applying comprising terminating a communication connection associated with the second message.

17. The protocol management system of claim 15 , wherein inspecting a message protocol associated with the second message comprises determining whether the selected message includes a string of five characters in an incoming packet header, wherein the five characters represent a signature of the instant messaging protocol.

18. The protocol management system of claim 15 , wherein the protocol enforcer is further configured to apply a policy enforcement rule in association with the second message, said applying comprising recording information associated with the second message.

19. The protocol management system of claim 18 , further comprising a storage medium, and wherein applying the policy enforcement rule further comprises creating a log comprising information associated with the second message and any related messages and storing the log in the storage medium.

20. The protocol management system of claim 15 , wherein inspecting a message protocol associated with the second message comprises determining whether the selected message is directed to port 8080 or port 5190 .

21. The protocol management system of claim 15 , wherein inspecting a message protocol associated with the second message comprises determining whether the selected message includes a string “?message=”.

22. The protocol management system of claim 15 , wherein inspecting a message protocol associated with the second message comprises determining whether the selected message includes a string “?pword=%1”.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044800/0848 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →