IP Library Granted Patent US 9,253,154
Granted Patent B2
US 9,253,154 · App. 12/190,536 · Granted Feb 2, 2016

Configuration management for a capture/registration system

Inventor: Jitendra B. Gaitonde (Cupertino, CA)
Assignee: McAfee, Inc.
H04L63/0236H04L41/0813H04L63/0245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,253,154
App. No.
12/190,536
Granted
Feb 2, 2016
Kind
B2
Abstract

A method, apparatus, and system is described for distributing a rule to a distributed capture system and storing the rule in a global configuration database, wherein the rule defines an action for the distributed capture system to perform regarding packets intercepted by the distributed capture system.

Claims (54)

1. A non-transitory computer-implemented method comprising:

distributing a rule to a distributed capture system, wherein the rule defines an action for the distributed capture system to perform regarding packets intercepted by the distributed capture system;

storing the rule in a global configuration database, which includes registered documents, each of the registered documents including a respective signature and a respective document identifier that collectively form a primary key, which can be searched within the global configuration database; and

distributing a plurality of crawler tasks to the capture system, wherein the crawler tasks are configured to search for rule violations within resting documents that are not being transmitted over a network connection, wherein the action is based on a particular document registered with the capture system and content of an object provided in the packets, and wherein the particular document is identified by one or more signatures, which can be compared against signatures derived from the object.

2. The method of claim 1 , wherein the rule is distributed within a policy, and wherein the policy includes one or more rules and a designation as to which of a plurality of distributed capture systems should apply the policy.

3. The method of claim 2 , wherein the policy further includes a policy state of either active or passive and each of the one or more rules within the policy are individually set to inherit or not to inherit the policy state.

4. The method of claim 1 , wherein the action is based upon one or more of the following:

the source or destination of the packets.

5. The method of claim 1 , wherein the rule defines an action of the distributed capture system regarding files stored on a network or a portion of a network associated with the distributed capture system.

6. The method of claim 5 , wherein the rule defines what objects stored on a network or a portion of a network associated with the distributed capture system should be registered by the capture system.

7. The method of claim 1 , wherein the rule is based upon a user-defined template.

8. The method of claim 1 , wherein the defined action is one or more of the following: an email notification, a syslog notification, and prevention of the transmittal of the intercepted packets.

9. The method of claim 1 , wherein the rule further defines exceptions to the defined action.

10. The method of claim 1 , further comprising:

storing, in the global configuration database, a plurality of versions of the rule and which version of the rule applies to the distributed capture system.

11. The method of claim 10 , further comprising:

identifying an additional distributed capture system in a network;

distributing a default version of a rule to the additional distributed capture system, wherein the rule defines an action for the additional distributed capture system to perform regarding packets intercepted by the additional distributed computer system.

12. The method of claim 1 , wherein the rule is distributed in response to one or more of the following: the addition of a capture system to a network, a capture system reestablishing a connection to a network, a periodic update, the creation of a new rule, a change made to an existing rule, and the deletion of a rule.

13. A non-transitory machine-readable storage medium having executable instructions that when executed, cause a machine to perform operations comprising:

distributing a rule to a distributed capture system, wherein the rule defines an action for the distributed capture system to perform regarding packets intercepted by the distributed capture system;

storing the rule in a global configuration database, which includes registered documents, each of the registered documents including a respective signature and a respective document identifier that collectively form a primary key, which can be searched within the global configuration database; and

distributing a plurality of crawler tasks to the capture system, wherein the crawler tasks are to search for rule violations within resting documents that are not being transmitted over a network connection, wherein the action is based on a particular document registered with the capture system and content of an object provided in the packets, and wherein the particular document is to be identified by one or more signatures, which can be compared against signatures derived from the object.

14. The machine-readable storage medium of claim 13 , wherein the rule is distributed within a policy, and wherein the policy includes one or more rules and a designation as to which of a plurality of distributed capture systems should apply the policy.

15. The machine-readable storage medium of claim 14 , wherein the policy further includes a policy state of either active or passive and each of the one or more rules within the policy are individually set to inherit or not to inherit the policy state.

16. The machine-readable storage medium of claim 13 , wherein the defined action is based upon one or more of the following:

the source or destination of the intercepted packets.

17. The machine-readable storage medium of claim 13 , wherein the rule defines an action of the distributed capture system regarding files stored on a network or a portion of a network associated with the distributed capture system.

18. The machine-readable storage medium of claim 17 , wherein the rule defines what objects stored on a network or a portion of a network associated with the distributed capture system should be registered by the capture system.

19. The machine-readable storage medium of claim 13 , wherein the rule is based upon a user-defined template.

20. The machine-readable storage medium of claim 13 , wherein the defined action is one or more of the following: an email notification, a syslog notification, and prevention of the transmittal of the intercepted packets.

21. The machine-readable storage medium of claim 13 , wherein the rule further defines exceptions to the defined action.

22. The machine-readable storage medium of claim 13 , wherein the executable instructions, when executed, further cause the machine to perform operations comprising:

storing, in the global configuration database, a plurality of versions of the rule and which version of the rule applies to the distributed capture system.

23. The machine-readable storage medium of claim 22 , wherein the executable instructions, when executed, further cause the machine to perform operations comprising:

identifying an additional distributed capture system in a network;

distributing a default version of a rule to the additional distributed capture system, wherein the rule defines an action for the additional distributed capture system to perform regarding packets intercepted by the additional distributed capture system.

24. The machine-readable storage medium of claim 13 , wherein the rule is distributed in response to one or more of the following:

the addition of a capture system to a network, a capture system reestablishing a connection to a network, a periodic update, the creation of a new rule, a change made to an existing rule, and the deletion of a rule.

25. A system comprising:

a memory including a global configuration database to store a rule;

a configuration manager coupled to the global configuration database to distribute the rule; and

a distributed capture system to receive the rule and store the rule in a local configuration database, wherein the rule defines an action for the distributed capture system to perform regarding packets intercepted by the distributed capture system, wherein the global configuration database is configured to store registered documents, each of the registered documents including a respective signature and a respective document identifier that collectively form a primary key, which can be searched within the global configuration database, wherein the configuration manager is configured to distribute a plurality of crawler tasks to the distributed capture system, wherein the crawler tasks are configured to search for rule violations within resting documents that are not being transmitted over a network connection, wherein the action is based on a particular document registered with the capture system and content of an object provided in the packets, and wherein the particular document is identified by one or more signatures, which can be compared against signatures derived from the object.

26. The system of claim 25 , wherein the rule is distributed within a policy, and wherein the policy includes one or more rules and a designation as to which of a plurality of distributed capture systems should apply the policy.

27. The system of claim 26 , wherein the policy further includes a policy state of either active or passive and each of the one or more rules within the policy are individually set to inherit or not to inherit the policy state.

28. The system of claim 25 , wherein the global configuration database further stores a plurality of versions of the rule and which version of the rule applies to the distributed capture system.

29. The system of claim 25 , wherein the configuration manager distributes the rule in response to one or more of the following: the addition of a capture system to a network, a capture system reestablishing a connection to a network, a periodic update, the creation of a new rule, a change made to an existing rule, and the deletion of a rule.

30. An apparatus comprising:

a memory including a global configuration database to store a rule; and

a configuration manager coupled to the global configuration database to distribute the rule to a distributed capture system, wherein the rule defines an action for the distributed capture system to perform regarding packets intercepted by the distributed capture system, wherein the global configuration database is configured to store registered documents, each of the registered documents including a respective signature and a respective document identifier that collectively form a primary key, which can be searched within the global configuration database, and wherein the configuration manager is configured to distribute a plurality of crawler tasks to the capture system, and wherein the crawler tasks are configured to search for rule violations within resting documents that are not being transmitted over a network connection, wherein the action is based on a particular document registered with the capture system and content of an object provided in the packets, and wherein the particular document is identified by one or more signatures, which can be compared against signatures derived from the object.

31. The apparatus of claim 30 , wherein the rule is distributed within a policy, and wherein the policy includes one or more rules and a designation as to which of a plurality of distributed capture systems should apply the policy.

32. The apparatus of claim 31 , wherein the policy further includes a policy state of either active or passive and each of the one or more rules within the policy are individually set to inherit or not to inherit the policy state.

33. The apparatus of claim 30 , wherein the global configuration database further stores a plurality of versions of the rule and which version of the rule applies to the distributed capture system.

34. The apparatus of claim 30 , wherein the configuration manager distributes the rule in response to one or more of the following: the addition of a capture system to a network, a capture system reestablishing a connection to a network, a periodic update, the creation of a new rule, a change made to an existing rule, and the deletion of a rule.

Assignments (22)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Jan 26, 2009
From: RECONNEX CORPORATION
To: MCAFEE, INC.
Reel/Frame 022214/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2008
From: GAITONDE, JITENDRA B.
To: RECONNEX CORPORATION
Reel/Frame 021475/0699 →
Continuity (1)
Related Publication 20130246377A1 · Sep 19, 2013