IP Library Granted Patent US 8,732,476
Granted Patent B1
US 8,732,476 · App. 11/786,908 · Granted May 20, 2014

Automatic intervention

Inventor: David Van (Somerset, NJ)
Assignee: Xceedium, Inc.
G06F21/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,732,476
App. No.
11/786,908
Granted
May 20, 2014
Kind
B1
Abstract

Securing a network is disclosed. A monitored session between a client and a network resource is provided. It is determined whether the client is attempting an authorized command. If the command is determined to be unauthorized, the command is intercepted. Optionally, remedial action is taken if it is determined that the client is attempting an unauthorized command.

Claims (35)

1. A method of securing a network comprising:

providing, by a gatekeeper device, a monitored session between a first client in a first network and a first network resource in a second network, wherein the gatekeeper device monitors keystrokes entered at the first client and wherein the first client is authorized to communicate with the first network resource;

determining, using a processor, and at least in part by evaluating at least one of a black list of prohibited commands and a white list of permitted commands, that the monitored keystrokes indicate an attempt by the first client to execute an unauthorized command, wherein the unauthorized command, when executed, attempts to cause an access, from the first network resource, of a second network resource; and

taking, by the gatekeeper device, a remedial action, wherein the remedial action includes at least one of substituting the unauthorized command with a bogus command and preventing the first client from transmitting the unauthorized command to the first network resource.

2. The method of claim 1 wherein the first network resource is a router.

3. The method of claim 1 wherein the first network resource is a server.

4. The method of claim 1 wherein providing the session includes serving one or more applets to the first client.

5. The method of claim 1 wherein the black list of prohibited commands is evaluated to determine that the monitored keystrokes indicate an attempt by the first client to execute a command included in the black list.

6. The method of claim 1 wherein the white list of permitted commands is evaluated to determine that the monitored keystrokes indicate an attempt by the first client to execute a command that is not included in the white list.

7. The method of claim 1 wherein determining that the first client is attempting an unauthorized command includes monitoring for socket open attempts.

8. The method of claim 1 further comprising capturing the session.

9. The method of claim 1 wherein the remedial action includes issuing a warning message.

10. The method of claim 1 wherein the monitoring is bidirectional.

11. The method of claim 1 wherein a second client is authorized to execute the unauthorized command to access the second network resource from the first network resource.

12. A system for securing a network, including:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

provide, at a gatekeeper device, a monitored session between a first client in a first network and a first network resource in a second network, wherein the gatekeeper device monitors keystrokes entered at the first client and wherein the first client is authorized to communicate with the first network resource;

determine, at least in part by evaluating at least one of black list of prohibited commands and a white list of permitted commands, that the monitored keystrokes indicate an attempt by the first client to execute an unauthorized command, wherein the unauthorized command, when executed, attempts to cause an access, from the first network resource, of a second network resource; and

take a remedial action, wherein the remedial action includes at least one of substituting the unauthorized command with a bogus command and preventing the first client from transmitting the unauthorized command to the first network resource.

13. The system of claim 12 wherein the first network resource is a router.

14. The system of claim 12 wherein the first network resource is a server.

15. The system of claim 12 wherein determining that the first client is attempting an unauthorized command includes monitoring for socket open attempts.

16. The system of claim 12 wherein a second client is authorized to execute the unauthorized command to access the second network resource from the first network resource.

17. The system of claim 12 wherein providing the session includes serving one or more applets to the first client.

18. The system of claim 12 wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to capture the session.

19. The system of claim 12 wherein the remedial action includes issuing a warning message.

20. The system of claim 12 wherein the black list of prohibited commands is evaluated to determine that the monitored keystrokes indicate an attempt by the first client to execute a command included in the black list.

21. The system of claim 12 wherein the white list of permitted commands is evaluated to determine that the monitored keystrokes indicate an attempt by the first client to execute a command not included in the white list.

22. A computer program product for securing a network, the computer program product being embodied in a non-transitory computer readable medium and comprising computer instructions for:

providing, by a gatekeeper device, a monitored session between a first client in a first network and a first network resource in a second network, wherein the gatekeeper device monitors keystrokes entered at the first client and wherein the first client is authorized to communicate with the first network resource;

determining, at least in part by evaluating at least one of black list of prohibited commands and a white list of permitted commands, that the monitored keystrokes indicate an attempt by the first client to execute an unauthorized command, wherein the unauthorized command, when executed, attempts to cause an access, from the first network resource, of a second network resource; and

taking a remedial action, wherein the remedial action includes at least one of substituting the unauthorized command with a bogus command and comprising preventing the first client from transmitting the unauthorized command to the first network resource.

23. The computer program product of claim 22 wherein the black list of prohibited commands is evaluated to determine that the monitored keystrokes indicate an attempt by the first client to execute a command included in the black list.

24. The computer program product of claim 22 wherein the white list of permitted commands is evaluated to determine that the monitored keystrokes indicate an attempt by the first client to execute a command not included in the white list.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2016
From: XCEEDIUM, INC.
To: CA, INC.
Reel/Frame 037830/0705 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2015
From: VENTURE LENDING & LEASING VI, INC.
To: XCEEDIUM, INC.
Reel/Frame 035787/0202 →
SECURITY INTEREST Recorded May 31, 2015
From: XCEEDIUM, INC.
To: HORIZON TECHNOLOGY FINANCE CORPORATION
Reel/Frame 035750/0371 →
SECURITY AGREEMENT Recorded Feb 24, 2014
From: XCEEDIUM, INC.
To: HARMONY PARTNERS II, L.P.; ARROWPATH FUND II LP; ARROWPATH ENTREPRENEUR FUND LP
Reel/Frame 032332/0001 →
SECURITY AGREEMENT Recorded Jun 21, 2012
From: XCEEDIUM, INC.
To: VENTURE LENDING & LEASING VI, INC.
Reel/Frame 028418/0354 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2007
From: VAN, DAVID
To: XCEEDIUM, INC.
Reel/Frame 019243/0387 →
Continuity (2)
Provisional Application 60792160 · Apr 13, 2006
Provisional Application 60857659 · Nov 7, 2006