IP Library Granted Patent US 7,707,401
Granted Patent B2
US 7,707,401 · App. 10/459,408 · Granted Apr 27, 2010

Systems and methods for a protocol gateway

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,707,401
App. No.
10/459,408
Granted
Apr 27, 2010
Kind
B2
Abstract

A protocol management system is capable of detecting certain message protocols and applying policy rules to the detected message protocols that prevent intrusion, or abuse, of a network's resources. In one aspect, a protocol message gateway is configured to apply policy rules to high level message protocols, such as those that reside at layer 7 of the ISO protocol stack.

Claims (51)

1. A method for managing a communication protocol in a network, the method comprising:

receiving at a firewall a plurality of messages from a computer network;

intercepting with an enforcer module executing on a computing device selected messages of the plurality of messages, the selected messages comprising each of the plurality of messages associated with an instant messaging protocol;

comparing the instant messaging protocol of each of the selected messages with at least one protocol template stored by the enforcer module, the instant messaging protocol of each selected message comprising (i) a screen name of a user originating the selected message and (ii) at least one of a source internet protocol (IP) address and a port number;

based on said comparing, redirecting to a protocol message gateway within the computer network each selected message having bypassed the protocol message gateway, wherein said redirecting comprises using a content vectoring protocol;

for each redirected selected message,

identifying with an authentication module of the protocol message gateway a unique user name associated with the screen name of the user originating the redirected selected message,

based at least in part on the unique user name, selecting a policy rule for restricting the user's usage of the instant messaging protocol, and

applying the selected policy rule to the redirected selected message.

2. The method of claim 1 , wherein the policy rule comprises a rule for restricting the user from sending or receiving a predefined number of instant messages within a given time period.

3. The method of claim 1 , wherein said selecting the policy rule is based at least partly on the source of the redirected selected message.

4. The method of claim 1 , wherein said selecting the policy rule is based at least partly on the intended destination internet protocol (IP) address of the redirected selected message.

5. The method of claim 1 , wherein said selecting the policy rule is based at least partly on when the redirected selected message is sent or intended to be received.

6. The method of claim 1 , wherein said selecting the policy rule is based at least partly on the size of the redirected selected message.

7. The method of claim 1 , wherein the selection of the policy rule is based at least partly on whether the redirected selected message includes an attachment.

8. The method of claim 1 , further comprising creating a log comprising information associated with the redirected selected message.

9. The method of claim 1 , wherein said identifying further comprises:

generating the unique user name for the user;

associating the screen name with the unique user name; and

storing in a database the association between the screen name and the unique user name.

10. The method of claim 1 , wherein applying the selected policy rule comprises forcing the redirected selected message to use a defined communication connection when flowing into or out of the computer network.

11. The method of claim 1 , wherein applying the selected policy rule comprises terminating a communication connection associated with the redirected selected message.

12. The method of claim 1 , wherein applying the selected policy rule comprises resetting a communication connection associated with the redirected selected message.

13. The method of claim 1 , wherein comparing the instant messaging protocol comprises determining whether the selected message is directed to port 5190 .

14. The method of claim 1 , wherein comparing the instant messaging protocol comprises determining whether the selected message is directed to port 8080 and whether the selected message includes a string “?pword=%1”, wherein %1 represents a value maintained in a message traffic database.

15. The method of claim 1 , wherein comparing the instant messaging protocol comprises determining whether the selected message includes a string of five characters in an incoming packet header, wherein the five characters represent a signature of the instant messaging protocol.

16. The method of claim 1 , wherein comparing the instant messaging protocol comprises determining whether the selected message is directed to port 8080 and whether the selected message includes a string “?message=”.

17. The method of claim 8 , further comprising encrypting the log.

18. The method of claim 8 , further comprising restricting access to the log.

19. The method of claim 9 , wherein said generating the unique user name comprises identifying a client device using the source internet protocol (IP) address.

20. The method of claim 10 , wherein the defined communication connection is a defined port on the protocol message gateway associated with the computer network.

21. The method of claim 19 , wherein determining the unique user name further comprises determining a global user identification associated with the client device.

22. The method of claim 21 , wherein determining the global user identification comprises interrogating a registry associated with the client device.

23. A system for restricting usage of instant messaging in a network, the system comprising:

a firewall operative to receive a plurality of messages leaving a computer network coupled to the firewall;

a proxy enforcer executing on a computing device and in communication with the firewall, the proxy enforcer operative to identify one or more of the plurality of messages that are associated with an instant messaging protocol, the instant messaging protocol comprising an application layer protocol;

a plurality of protocol definition files accessible to the proxy enforcer, wherein the proxy enforcer is further operative to compare the instant messaging protocol of each of the one or more messages with at least one of the plurality of protocol definition files;

a protocol message gateway in communication with the proxy enforcer, the proxy enforcer operative to redirect to the protocol message gateway each of the one or more messages that did not previously pass through the protocol message gateway prior to being received by the firewall; the protocol message gateway further comprising

at least one protocol adapter operative to generate a data structure comprising information indicative of a communication session of each redirected message,

an authentication module operative to identify a unique user name based on a screen name associated with each redirected message, the unique user name identifying an actual user of the computer network, and

a policy enforcement module operative to select a policy rule for restricting the actual user's usage of the instant messaging protocol and to apply the selected policy rule to the redirected message.

24. The system of claim 23 , wherein the policy enforcement module of the protocol message gateway is further operative to select the policy rule based at least partly on when the redirected message is originally sent or intended to be received.

25. The system of claim 23 , wherein the policy enforcement module of the protocol message gateway is further operative to select the policy rule based at least partly on the size of the redirected message.

26. The system of claim 23 , wherein the policy enforcement module of the protocol message gateway is further operative to select the policy rule based at least partly on whether the redirected message includes an attachment.

27. The system of claim 23 , wherein the policy enforcement module of the protocol message gateway is further operative to select the policy rule based at least partly on whether the redirected message includes a virus.

28. The system of claim 23 , wherein the protocol message gateway further comprises a logging module configured to record information associated with each of the redirected messages.

29. The system of claim 23 , wherein the authentication module is further configured to

determine the unique user name for the actual user;

associate the screen name with the unique user name; and

store in a database the association between the screen name and the unique user name.

30. The system of claim 23 , wherein the firewall further comprises a content vectoring protocol application programming interface (API) operative to communicate the redirected messages to the protocol message gateway.

Assignments (28)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044800/0848 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
RELEASE OF SECURITY INTEREST Recorded Sep 20, 2013
From: MENLO VENTURES IX, L.P.; MENLO ENTREPRENEURS FUND IX, L.P.; MENLO ENTREPRENEURS FUND IX(A), L.P.; MMEF IX, L.P.; PALOMAR VENTURES II, L.P.; WINDWARD VENTURES 2000, L.P.; WINDWARD VENTURES 2000-A, L.P.; MISSION VENTURES II, L.P.; MISSION VENTURES AFFILIATES II, L.P.; GC&H INVESTMENTS, LLC; PERFORMANCE DIRECT INVESTMENTS I, L.P.; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-127; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-128; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-129; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-130
To: AKONIX SYSTEMS, INC.
Reel/Frame 031247/0495 →
CHANGE OF NAME Recorded Aug 20, 2013
From: QUEST SOFTWARE, INC.
To: DELL SOFTWARE INC.
Reel/Frame 031043/0281 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Sep 28, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC (FORMERLY KNOWN AS WELLS FARGO FOOTHILL, LLC)
To: QUEST SOFTWARE, INC.; AELITA SOFTWARE CORPORATION; SCRIPTLOGIC CORPORATION; VIZIONCORE, INC.; NETPRO COMPUTING, INC.
Reel/Frame 029050/0679 →