IP Library Granted Patent US 8,898,276
Granted Patent B1
US 8,898,276 · App. 11/622,398 · Granted Nov 25, 2014

Systems and methods for monitoring network ports to redirect computing devices to a protected network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,898,276
App. No.
11/622,398
Granted
Nov 25, 2014
Kind
B1
Abstract

A method for redirecting a computing device from a first network to a second network is described. A plurality of network ports is monitored. A communication from a computing device is detected at one of the network ports. Information is sent to a first server and a second server regarding the identity of the computing device. A command is sent to the first server to send a request to the computing device to renew the connection with the second server. The computing device is redirected to a second network from a first network.

Claims (46)

1. A method for redirecting a computing device from a first network to a second network comprising:

monitoring, by a monitoring device, a plurality of network ports;

detecting, by the monitoring device, a communication from a computing device at one of the network ports;

sending information from the monitoring device to a first server and a second server regarding the identity of the computing device;

sending a command from the monitoring device to the first server to send a request to the computing device to renew the connection with the second server, wherein the command is sent after the information regarding the identity of the computing device is sent from the monitoring device to the first server and the second server;

receiving a request from the computing device to renew its connection with the second server;

determining whether the request was sent from the computing device where an attack by a worm originated, wherein the determining occurs after the request to renew its connection was received; and

redirecting the computing device to a second network from a first network;

wherein the monitoring device comprises the ports and is configured to appear to possess characteristics of a server and wherein the monitoring device configured to appear to possess characteristics of the server acts as bait for the worm to attack the monitoring device.

2. The method of claim 1 , further comprising determining if the communication detected at one of the plurality of network ports includes a harmful element.

3. The method of claim 2 , wherein the harmful element comprises the worm.

4. The method of claim 2 , wherein the harmful element comprises a computer virus.

5. The method of claim 1 , further comprising monitoring a subset of network ports.

6. The method of claim 5 , wherein the subset of ports includes ports 135, 137, 138, 139, 161, 162, 389, and 445.

7. The method of claim 1 , wherein a monitoring application on the monitoring device monitors the plurality of network ports.

8. The method of claim 1 , wherein the second server redirects the computing device from the first network to the second network.

9. The method of claim 1 , wherein a monitoring application on the monitoring device monitors a plurality of ports, wherein the monitoring application detects a communication comprising a harmful element at one of the ports, wherein the monitoring application sends the identity of the computing device to the first server and the second server, wherein the computing device renews the connection with the second server, and wherein the second server redirects the computing device to the second network.

10. A computer system that is configured to redirect a computing device from a first network to a second network, the computer system comprising:

a second server; and

a monitoring device having:

a processor;

memory in electronic communication with the processor;

instructions stored in the memory, the instructions being executable to:

monitor, by the monitoring device, a plurality of network ports;

detect, by the monitoring device, a communication from a computing device at one of the network ports;

send information from the monitoring device to a first server and the second server regarding the identity of the computing device;

send a command from the monitoring device to the first server to send a request to the computing device to renew the connection with the second server, wherein the command is sent after the information regarding the identity of the computing device is sent from the monitoring device to the first server and the second server;

determine whether the request was sent from the computing device where an attack by a worm originated, wherein the determining occurs after the request to renew its connection was received; and

the ports, wherein the monitoring device is configured to appear to possess characteristics of a server and wherein the monitoring device configured to appear to possess characteristics of the server acts as bait for the worm to attack the monitoring device;

wherein the second server receives a request from the computing device to renew its connection with the second server, wherein the second server redirects the computing device to a second network from a first network.

11. The system of claim 10 , wherein the instructions detect a harmful element within the communication detected at one of the network ports.

12. The system of claim 11 , wherein the harmful element comprises the worm.

13. The system of claim 11 , wherein the harmful element comprises a computer virus.

14. The system of claim 10 , wherein the instructions monitor a subset of the plurality of network ports.

15. The system of claim 14 , wherein the subset of ports comprises ports 135, 137, 138, 139, 161, 162, 389, and 445.

16. A non-transitory computer-readable medium comprising executable instructions to redirect a computing device from a first network to a second network, the instructions being executable to:

monitor, by a monitoring device, a plurality of network ports;

detect, by the monitoring device, a communication from a computing device at one of the network ports;

send information from the monitoring device to a first server and a second server regarding the identity of the computing device;

send a command from the monitoring device to the first server to send a request to the computing device to renew the connection with the second server, wherein the command is sent after the information regarding the identity of the computing device is sent from the monitoring device to the first server and the second server;

determine whether the request was sent from the computing device where an attack by a worm originated, wherein the determining occurs after the request to renew its connection was received; and

receive a request from the computing device to renew its connection with the second server, wherein the second server redirects the computing device to a second network from a first network;

wherein the monitoring device comprises the ports and is configured to appear to possess characteristics of a server and wherein the monitoring device configured to appear to possess characteristics of the server acts as bait for the worm to attack the monitoring device.

17. The non-transitory computer-readable medium of claim 16 , wherein the instructions are further executable to detect a harmful element in the communication received at one of the network ports.

18. The non-transitory computer-readable medium of claim 16 , wherein the instructions are further executable to monitor a subset of the plurality of network ports.

19. The non-transitory computer-readable medium of claim 18 , wherein the subset of ports comprises ports 135, 137, 138, 139, 161, 162, 389, and 445.

Assignments (27)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: IVANTI, INC.
Reel/Frame 071958/0203 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded May 5, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; CHERWELL SOFTWARE, LLC
Reel/Frame 071176/0289 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
2025-1 SECOND LIEN SECURITY AGREEMENT Recorded May 5, 2025
From: IVANTI SECURITY INTERMEDIATE HOLDINGS LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0498 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: IVANTI, INC.
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071180/0690 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0164 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2025
From: ALTER DOMUS (US) LLC
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071162/0130 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: CRIMSON CORPORATION
Reel/Frame 030993/0644 →
PATENT SECURITY AGREEMENT Recorded Jul 26, 2012
From: CRIMSON CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028643/0847 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC
To: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
Reel/Frame 028413/0913 →