IP Library Granted Patent US 8,751,787
Granted Patent B2
US 8,751,787 · App. 12/331,912 · Granted Jun 10, 2014

Method and device for integrating multiple threat security services

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,751,787
App. No.
12/331,912
Granted
Jun 10, 2014
Kind
B2
Abstract

A method and device for integrating multiple threat security services are disclosed. The method may comprise parsing an incoming packet at a current layer and analyzing the packet with respect to multiple threat security services and so that one or more threat security services needed by the packet may be determined. According to an exemplary embodiment, the current layer may be a layer in a protocol stack constructed based on the multiple threat security services. With this method, integrated multiple threat security services may filter application data and parse network packet data via a single integrated entity, and thus the efficacy of filtering application data may be improved while computation overhead may be reduced.

Claims (27)

1. A method for integrating multiple threat security services, said method comprising:

generating parsed packet data by parsing an incoming packet at each layer of an integrated security service stack;

analyzing said generated parsed packet data at each layer of the integrated security service stack with respect to one or more patterns, wherein each of said one or more patterns corresponds to one of said multiple threat security services; and

consequent to analyzing said parsed packet data with respect to said one or more patterns, determining one or more of said multiple threat security services needed by said parsed packet data by forming a matching algorithm for each layer of said integrated security service stack, wherein forming said matching algorithm comprises assigning a tag to each of said one or more patterns, and wherein each tag identifies one of said multiple threat security services.

2. The method according to claim 1 , wherein said integrated security service stack is a protocol stack constructed based on said multiple threat security services.

3. The method according to claim 1 , wherein each of said one or more patterns corresponds to a layer of said integrated security service stack.

4. The method according to claim 1 , wherein forming said matching algorithm for each layer of said integrated security service stack comprises merging all of said one or more patterns corresponding to the layer into a pattern set.

5. The method according to claim 1 , wherein said matching algorithm is a string matching algorithm.

6. The method according to claim 1 , wherein determining one or more of said multiple threat security services needed by said parsed packet data further comprises:

for each layer of said integrated security service stack:

filtering parsed packet data at the layer by invoking a matching algorithm for the layer; and

returning one or more tagged results identifying one or more of said multiple threat security services.

7. The method according to claim 1 , wherein said multiple threat security services include at least one of an anti virus service, an anti spam service, an intrusion detection/protection system, a firewall, or a worm filter.

8. The method according to claim 1 , wherein generating parsed packet data comprises parsing said incoming packet via at least one of an Internet Protocol (IP) parser, a Transmission Control Protocol (TCP) parser, an application layer protocol parser, or a file parser.

9. A device for integrating multiple threat security services, said device comprising:

a plurality of parsers, loaded in a computer, wherein each of said plurality of parsers is configured for generating parsed packet data by parsing an incoming packet at each layer of an integrated security service stack; and

an analyzer, also loaded in said computer, configured for analyzing said generated parsed packet data at each layer of the integrated security service stack with respect to one or more patterns and determining one or more of said multiple threat security services needed by said parsed packet data by forming a matching algorithm for each layer of said integrated security service stack consequent to analyzing said parsed packet data with respect to said one or more patterns, wherein each of said one or more patterns corresponds to one of said multiple threat security services, wherein forming said matching algorithm comprises assigning a tag to each of said one or more patterns, and wherein each tag identifies one of said multiple threat security services.

10. The device according to claim 9 , wherein said integrated security service stack is a protocol stack constructed based on said multiple threat security services.

11. The device according to claim 9 , wherein each of said one or more patterns corresponds to a layer of said integrated security service stack.

12. The device according to claim 9 , wherein said analyzer is configured for forming a matching algorithm for each layer of said integrated security service stack by merging all of said one or more patterns corresponding to the layer into a pattern set.

13. The device according to claim 9 , wherein said matching algorithm is a string matching algorithm.

14. The device according to claim 9 , wherein said analyzer is further configured for determining one or more of said multiple threat security services needed by said parsed packet data by:

for each layer of said integrated security service stack:

filtering parsed packet data at the layer by invoking a matching algorithm for the layer; and

returning one or more tagged results identifying one or more of said multiple threat security services.

15. The device according to claim 9 , wherein said multiple threat security services include at least one of an anti virus service, an anti spam service, an intrusion detection/protection system, a firewall, or a worm filter.

16. The device according to claim 9 , wherein said plurality of filters include at least one of an Internet Protocol (IP) parser, a Transmission Control Protocol (TCP) parser, an application layer protocol parser, or a file parser.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2014
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: LENOVO INTERNATIONAL LIMITED
Reel/Frame 034194/0291 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2008
From: WANG, BAI LING
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 021956/0191 →