IP Library Granted Patent US 8,015,611
Granted Patent B2
US 8,015,611 · App. 11/852,932 · Granted Sep 6, 2011

Integrated firewall, IPS, and virus scanner system and method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,015,611
App. No.
11/852,932
Granted
Sep 6, 2011
Kind
B2
Abstract

A system, method and computer program product are provided including a router and a security sub-system coupled to the router. Such security sub-system includes a plurality of virtual firewalls, a plurality of virtual intrusion prevention systems (IPSs), and a plurality of virtual virus scanners. Further, each of the virtual firewalls, IPSs, and virus scanners is assigned to at least one of a plurality of user and is configured in a user-specific.

Claims (42)

1. A security system, comprising:

a router; and

a security sub-system component of the router;

wherein the security sub-system includes a plurality of virtual firewalls, a plurality of virtual intrusion prevention systems (IPSs), and a plurality of virtual virus scanners all integrated into a single sub-system;

wherein each of the virtual firewalls, IPSs, and virus scanners is assigned to at least one of a plurality of users and is configured a user-specific manner;

wherein the user-specific configuration is provided utilizing a plurality of user-specific policies selected by each user such that a first user of the single sub-system is capable of specifying a first policy and a second user of the single sub-system is capable of specifying a second policy different than the first policy;

wherein the security sub-system component of the router exchanges state information, which includes an active or a standby status per port, with another security sub-system component of another router;

wherein if the exchanged state information indicates that the security sub-system component and the other security sub-system component are both active for a port, then the security sub-system component and the other security sub-system component renegotiate a respective status of each security sub-system component for the port.

2. The system as recited in claim 1 , wherein the security sub-system further includes a plurality of anti-spam modules and each of the anti-spam modules is assigned to at least one of the plurality of the users and is configured in the user-specific manner.

3. The system as recited in claim 1 , wherein the security sub-system further includes a plurality of content filtering modules and each of the content filtering modules is assigned to at least one of the plurality of the users and is configured in the user-specific manner.

4. The system as recited in claim 1 , wherein the security sub-system further includes a plurality of uniform resource locator (URL) filtering modules and each of the URL filtering modules is assigned to at least one of the plurality of the users and is configured in the user-specific manner.

5. The system as recited in claim 1 , wherein the security sub-system further includes a plurality of virtual private network (VPN) modules and each of the VPN modules is assigned to at least one of the plurality of the users and is configured in the user-specific manner.

6. The system as recited in claim 1 , wherein the security sub-system further includes a plurality of spyware filtering modules and each of the spyware filtering modules is assigned to at least one of the plurality of the users and is configured in the user-specific manner.

7. The system as recited in claim 1 , wherein the security sub-system further includes a plurality of adware filtering modules and each of the adware filtering modules is assigned to at least one of the plurality of the users and is configured in the user-specific manner.

8. The system as recited in claim 1 , wherein the user-specific policies are selected utilizing a graphical user interface.

9. The system as recited in claim 8 , wherein the graphical user interface includes a virtual firewall interface, a virtual IPS interface, and a virtual virus scanner interface.

10. The system as recited in claim 1 , wherein the system is used to counter terrorism.

11. The system as recited in claim 1 , wherein the security sub-system is equipped with a failover function.

12. The system as recited in claim 1 , wherein the security sub-system requires the first user and the second user to log-in before specifying the first policy and the second policy.

13. The system as recited in claim 1 , wherein the first user is required to log-in to a first subscriber portal and the second user is required to log-in to a second subscriber portal.

14. The system as recited in claim 13 , wherein upper domain information is hidden in the first subscriber portal and the second subscriber portal.

15. The system as recited in claim 14 , wherein the upper domain information that is hidden in the first subscriber portal and the second subscriber portal includes details on policies applied to a first domain that is above or parallel with a second domain of the first user and the second user.

16. The system as recited in claim 1 , wherein for each one of the plurality of users, functionality of each of the virtual firewalls, the IPSs, and the virus scanners assigned to the user is provided upon subscription by the user.

17. The system as recited in claim 16 , wherein for the functionality of each of the virtual firewalls, the IPSs, and the virus scanners, configuration of the functionality only appears in a subscriber user interface if the functionality is provisioned to the user by a reseller utilizing a reseller user interface separate from the subscriber user interface.

18. The system as recited in claim 17 , wherein the functionality is provisioned by the reseller only if the functionality is subscribed to by the user.

19. The system as recited in claim 1 , wherein the user-specific configuration includes a maximum number of ACL entries, a maximum number of NAT/PAT entries, a maximum number of routes, a maximum number of TCP flows at one time, a maximum number of content filtering rules, a maximum number of Sub-Admin domains that can be created, and a maximum number of SSL keys.

20. A security method, comprising:

receiving data utilizing a router; and

processing the data utilizing a security system component of the router;

wherein the security system includes a plurality of virtual firewalls, a plurality of virtual intrusion prevention systems (IPSs), and a plurality of virtual virus scanners all integrated into a single system;

wherein each of the virtual firewalls, IPSs, and virus scanners is assigned to at least one of a plurality of users and is configured in a user-specific manner;

wherein the user-specific configuration is provided utilizing a plurality of user-specific policies selected by each user such that a first user of the single system is capable of specifying a first policy and a second user of the single system is capable of specifying a second policy different than the first policy;

wherein the security system component of the router exchanges state information, which includes an active or a standby status per port, with another security system component of another router;

wherein if the exchanged state information indicates that the security system component and the other security system component are both active for a port, then the security system component and the other security system component renegotiate a respective status of each security system component for the port.

21. A security computer program product embodied on a computer readable non-transitory medium, comprising:

computer code for receiving data utilizing a router; and

computer code for processing the data utilizing a security system component of the router;

wherein the security system includes a plurality of virtual firewalls, a plurality of virtual intrusion prevention systems (IPSs), and a plurality of virtual virus scanners all integrated into a single system;

wherein each of the virtual firewalls, IPSs, and virus scanners is assigned to at least one of a plurality of users and is configured in a user-specific manner;

wherein the user-specific configuration is provided utilizing a plurality of use policies selected by each user such that a first user of the single system is capable of specifying a first policy and a second user of the single system is capable of specifying a second policy different than the first policy;

wherein the security system component of the router exchanges state information, which includes an active or a standby status per port, with another security system component of another router;

wherein if the exchanged state information indicates that the security system component and the other security system component are both active for a port, then the security system component and the other security system component renegotiate a respective status of each security system component for the port.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2007
From: HAEFFELE, STEVEN M.; GUPTA, RAMESH M.; RAMAN, ANANTH; VISSAMSETTI, SRIKANT
To: MCAFEE, INC.
Reel/Frame 019812/0820 →