IP Library Granted Patent US 8,429,736
Granted Patent B2
US 8,429,736 · App. 12/116,347 · Granted Apr 23, 2013

Named sockets in a firewall

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,429,736
App. No.
12/116,347
Granted
Apr 23, 2013
Kind
B2
Abstract

A proxy device such as a firewall uses an internal socket namespace such as a text string such that connection requests must be explicitly redirected to a listening socket in the alternate namespace in order to connect to a service. Because external connections cannot directly address the listening socket or service, greater security is provided than with traditional firewall or proxy devices. To receive a redirected proxy connection, a service process creates a listening socket and binds a name in an alternate namespace to the socket before listening for connections.

Claims (24)

1. A computer network proxy device, comprising:

a computerized firewall comprising a processor and a mapping module operable to map an incoming connection on a first port or socket in a first namespace to a listening socket within the firewall identified in an alternate socket namespace by redirecting the incoming connection to the socket listening in the alternate namespace and from the socket listening in the alternate namespace to a first service external to the firewall to connect to the first service external to the firewall,

wherein redirecting comprises forwarding an incoming connection to a second service via a socket the process of the second service creates by binding a name in an alternate namespace to the socket before listening for connections,

wherein the listening socket identified in the alternate namespace comprises a named listening socket associated with two or more service providers, such that the two or more service providers each have a socket associated with a name of the named listening socket in the alternate namespace and provide a service associated with the name of the named listening socket, and

wherein connections provided through the named listening socket are load balanced across the two or more service providers associated with the named listening socket.

2. The computer network proxy device of claim 1 , wherein names in the alternate socket namespace are associated with one or more types of services associated with the incoming connections.

3. The computer network proxy device of claim 1 , wherein the mapping module prevents incoming connections from directly addressing a service or socket via port or socket number.

4. The computer network proxy device of claim 1 , wherein the alternate socket namespace comprises user-readable text strings.

5. A method of operating a computer network proxy device, comprising:

mapping in a firewall an incoming connection on a first port or socket in a first namespace to a listening socket within the firewall identified in an alternate socket namespace by redirecting the incoming connection to the socket listening in the alternate namespace and from the socket listening in the alternate namespace to a first service external to the firewall to connect to the first service external to the firewall,

wherein redirecting comprises forwarding an incoming connection to a second service via a socket the process of the second service creates by binding a name in an alternate namespace to the socket before listening for connections,

wherein the listening socket identified in the alternate namespace comprises a named listening socket associated with two or more service providers, such that the two or more service providers each have a socket associated with a name of the named listening socket in the alternate namespace and provide a service associated with the name of the named listening socket, and

wherein connections provided through the named listening socket are load balanced across the two or more service providers associated with the named listening socket.

6. The method of operating a computer network proxy device of claim 5 , wherein names in the alternate socket namespace are associated with one or more types of services associated with the incoming connections.

7. The method of operating a computer network proxy device of claim 5 , further comprising preventing incoming connections from directly addressing a service or socket via port or socket number.

8. The method of operating a computer network proxy device of claim 5 , wherein the alternate socket namespace comprises user-readable text strings.

9. A machine-readable non-transitory medium with instructions stored thereon, the instructions when executed operable to cause a computerized firewall device to:

map in a firewall an incoming connection on a first port or socket in a first namespace to a listening socket within the firewall identified in an alternate socket namespace by redirecting the incoming connection to the socket listening in the alternate namespace and from the socket listening in the alternate namespace to a first service external to the firewall to connect to the first service external to the firewall,

wherein redirecting comprises forwarding an incoming connection to a second service via a socket the process of the second service creates by binding a name in an alternate namespace to the socket before listening for connections,

wherein the listening socket identified in the alternate namespace comprises a named listening socket associated with two or more service providers, such that the two or more service providers each have a socket associated with a name of the named listening socket in the alternate namespace and provide a service associated with the name of the named listening socket, and

wherein connections provided through the named listening socket are load balanced across the two or more service providers associated with the named listening socket.

10. The machine-readable non-transitory medium of claim 9 , wherein the instructions when executed are further operable to prevent incoming connections from directly addressing a service or socket via port or socket number.

11. The machine-readable non-transitory medium of claim 9 , wherein names in the alternate socket namespace are associated with one or more types of services associated with the incoming connections.

12. The machine-readable non-transitory medium of claim 9 , wherein the alternate socket namespace comprises user-readable text strings.

Assignments (12)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 024456/0724 →
CHANGE OF NAME Recorded Mar 25, 2010
From: SECURE COMPUTING CORPORATION
To: SECURE COMPUTING, LLC
Reel/Frame 024128/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2008
From: GREEN, MICHAEL W.; DIEHL, DAVID; KARELS, MICHAEL J.
To: SECURE COMPUTING CORPORATION
Reel/Frame 021027/0688 →