IP Library Granted Patent US 8,543,710
Granted Patent B2
US 8,543,710 · App. 11/076,591 · Granted Sep 24, 2013

Method and system for controlling network access

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,543,710
App. No.
11/076,591
Granted
Sep 24, 2013
Kind
B2
Abstract

Systems and methods intended to control a network devices access to a network are disclosed. Embodiments of the current invention expose a method for confining a network client's network access to a specific logical region of the network. A network communication may be received and the client that originated this communication determined. This client is associated with a set of rules or walled garden that specifies the access allowed by that client. The destination of the communication may also be determined and if the destination is allowed by the set of rules associated with the client and access to the destination allowed if access to the destination is allowed by the set of rules.

Claims (49)

1. A method of network traffic quarantine control, comprising:

at a network access gateway device between a local network and the Internet, selecting a client device in a first network segment of the network;

at the network access gateway device, performing a plurality of quarantine control functions over the client device, wherein the plurality of quarantine control functions comprises:

a) restricting all network traffic emanating from the client device to one or more network destination addresses that are not in or subordinate to the first network segment;

b) restricting all network traffic emanating from the client device to an allowed network destination address to selected one or more network protocols; and

rendering a web page to display on the client device from the network access gateway device, wherein the web page contains an offer for a user of the client device to perform an action in order to obtain unrestricted access to the Internet responsive to implementation of one of the plurality of quarantine control function of the client device.

2. The method according to claim 1 , wherein the action requires the user to obtain and execute abnormal behavior scanning software from a server machine running at one of the one or more allowed network destination addresses.

3. The method according to claim 1 , further comprising:

evaluating network traffic emanating from the client device after the client device has been scanned and abnormal behavior has been removed, mitigated or rendered inert.

4. The method according to claim 1 , further comprising:

filtering the network traffic emanating from the client device to limit network packet flow by the client device.

5. The method according to claim 1 , further comprising:

routing the network traffic emanating from the client device to limit network packet traversal by the client device.

6. The method according to claim 1 , wherein the plurality of quarantine control functions further comprises:

restricting all network traffic emanating from the client device to one or more network destination addresses in one or more network segments that are not in or subordinate to the first network segment.

7. The method according to claim 1 , further comprising:

performing all of the plurality of quarantine control functions over the client device.

8. A computer program product comprising at least one non-transitory computer readable medium storing instructions translatable by at least one processor to perform:

a plurality of quarantine control functions over a client device coupled to the network access gateway device, wherein the network access gateway device is between a local network and the Internet, wherein the client device is in a first network segment of the network, and wherein the plurality of quarantine control functions comprises:

a) restricting all network traffic emanating from the client device to one or more network destination addresses that are not in or subordinate to the first network segment;

b) restricting all network traffic emanating from the client device to an allowed network destination address to selected one or more network protocols; and

rendering a web page to display on the client device from the network access gateway device, wherein the web page contains an offer for a user of the client device to perform an action in order to obtain unrestricted access to the Internet responsive to the implementation of one of the plurality of quarantine control function of the client device.

9. The computer program product of claim 8 , wherein the action requires the user to obtain and execute abnormal behavior scanning software from a server machine running at one of the one or more allowed network destination addresses.

10. The computer program product of claim 8 , wherein the instructions are further translatable by the at least one processor to perform:

evaluating network traffic emanating from the client device after the client device has been scanned and abnormal behavior has been removed, mitigated or rendered inert.

11. The computer program product of claim 8 , wherein the instructions are further translatable by the at least one processor to perform:

filtering the network traffic emanating from the client device to limit network packet flow by the client device.

12. The computer program product of claim 8 , wherein the instructions are further translatable by the at least one processor to perform:

routing the network, traffic emanating from the client device to limit network packet traversal by the client device.

13. The computer program product of claim 8 , wherein the plurality of quarantine control functions further comprises:

restricting all network traffic emanating from the client device to one or more network destination addresses in one or more network segments that are not in or subordinate to the first network segment.

14. The computer program product of claim 8 , wherein the instructions are further translatable by the at least one processor to perform:

all of the plurality of quarantine control functions over the client device.

15. A network access gateway device, comprising:

at least one processor; and

at least one non-transitory computer readable medium storing instructions translatable by the at least one processor to perform:

a plurality of quarantine control functions over a client device coupled to the network access gateway device, wherein the network access gateway device is between a local network and the Internet, wherein the client device is in a first network segment of the network, and wherein the plurality of quarantine control functions comprises:

a) restricting all network traffic emanating from the client device to one or more network destination addresses that are not in or subordinate to the first network segment;

b) restricting all network traffic emanating from the client device to an allowed network destination address to selected one or more network protocols; and

rendering a web page to display on the client device from the network access gateway device, wherein the web page contains an offer for a user of the client device to perform an action in order to obtain unrestricted access to the Internet responsive to implementation of one of the plurality of quarantine control function of the client device.

16. The system of claim 15 , wherein the action requires the user to obtain and execute abnormal behavior scanning software from a server machine running at one of the one or more allowed network destination addresses.

17. The system of claim 15 , wherein the instructions are further translatable by the at least one processor to perform:

evaluating network traffic emanating from the client device after the client device has been scanned and abnormal behavior has been removed, mitigated or rendered inert.

18. The system of claim 15 , wherein the instructions are further translatable by the at least one processor to perform:

filtering the network traffic emanating from the client device to limit network packet flow by the client device.

19. The system of claim 15 , wherein the instructions are further translatable by the at least one processor to perform:

routing the network traffic emanating from the client device to limit network packet traversal by the client device.

20. The system of claim 15 , wherein the plurality of quarantine control functions further comprises:

restricting all network traffic emanating from the client device to one or more network destination addresses in one or more network segments that are not in or subordinate to the first network segment.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2024
From: RPX CORPORATION
To: NETSKOPE, INC.
Reel/Frame 067918/0690 →
RELEASE OF SECURITY INTEREST IN SPECIFIED PATENTS Recorded May 31, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 067596/0606 →
RELEASE OF SECURITY INTEREST Recorded Oct 26, 2020
From: JEFFERIES FINANCE LLC
To: RPX CORPORATION
Reel/Frame 054486/0422 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054244/0566 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054198/0029 →
SECURITY INTEREST Recorded Jun 29, 2018
From: RPX CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 046486/0433 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2012
From: ROCKSTEADY TECHNOLOGIES LLC
To: RPX CORPORATION
Reel/Frame 028774/0036 →
CONFIRMATORY ASSIGNMENT Recorded Jun 28, 2012
From: WHITE, ERIC
To: ROCKSTEADY TECHNOLOGIES, LLC
Reel/Frame 028457/0012 →