IP Library Patent Application 12957042
Patent Application
App. No. 12/957,042

Method and System for Digital Communication Security Using Computer Systems

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/957,042
Abstract

Methods and systems are provided for network security. In one embodiment, the method may involve receiving a data packet (e.g. from a firewall). The method may involve running an inspection of the received data packet within a virtual network, the virtual network duplicating at least a portion (e.g., servers(s) and/or application(s)) of a protected network. The method may involve sending the inspected data packet, or portion and/or modified version thereof, to the protected network, in response to the data packet passing the inspection within the virtual network. The method may also involve blocking passage of the data packet to the protected network, in response to the data packet failing the inspection.

Claims (43)

1 . A system for network security, comprising:

a protected network comprising at least one protected server; and

a virtual network comprising at least one virtual server;

wherein the at least one virtual server is a ghost of the at least one protected server and is configured to:

receive a data packet;

run an inspection of the received data packet; and

send at least a portion of the inspected data packet to the protected network, in response to the data packet passing the inspection.

2 . The system of claim 1 , wherein the virtual network is a virtual duplicate of the protected network.

3 . The system of claim 1 , wherein the at least one virtual server receives the data packet from a firewall.

4 . The system of claim 1 , wherein:

the at least one protected server comprises a protected application; and

the at least one virtual server comprises at least one virtual application, the least one virtual application being a virtual duplicate of the protected application.

5 . The system of claim 4 , wherein the at least one virtual server runs the inspection by applying at least one of a pre-application security utility and a post-application security utility.

6 . The system of claim 1 , wherein the at least one virtual server blocks passage of the data packet to the protected network, in response to the data packet failing the inspection.

7 . The system of claim 1 , wherein the portion comprises a modified version of the inspected data packet.

8 . A method operable by a virtual entity in a network system, comprising:

receiving a data packet;

running an inspection of the received data packet within a virtual network, the virtual network duplicating at least a portion of a protected network; and

sending at least a portion of the inspected data packet to the protected network, in response to the data packet passing the inspection within the virtual network.

9 . The method of claim 8 , wherein the virtual entity comprises one of (a) the virtual network, (b) at least one virtual server of the virtual network, and (c) at least one virtual application of the at least one virtual server.

10 . The method of claim 8 , wherein receiving comprises receiving the data packet from a firewall.

11 . The method of claim 8 , wherein:

the protected network comprises at least one protected server;

the at least one protected server comprises at least one protected application;

the virtual network comprises at least one virtual server, the at least one virtual server being a ghost of the at least one protected server; and

the at least one virtual server comprises at least one virtual application, the at least one virtual application being a virtual duplicate of the at least one protected application.

12 . The method of claim 11 , wherein running the inspection comprises applying at least one of a pre-application security utility and a post-application security utility.

13 . The method of claim 8 , further comprising blocking passage of the data packet to the protected network, in response to the data packet failing the inspection.

14 . The method of claim 8 , wherein the portion comprises a modified version of the inspected data packet.

15 . A computer program product, comprising:

a computer-readable medium comprising code for causing a computer to:

receive a data packet;

run an inspection of the received data packet within a virtual network, the virtual network duplicating at least a portion of a protected network; and

send at least a portion of the inspected data packet to the protected network, in response to the data packet passing the inspection within the virtual network.

16 . The computer program product of claim 15 , wherein the computer-readable medium further comprises code for causing the computer to receive the data packet from a firewall.

17 . The computer program product of claim 15 , wherein:

the protected network comprises at least one protected server;

the at least one protected server comprises at least one protected application;

the virtual network comprises at least one virtual server, the at least one virtual server being a ghost of the at least one protected server; and

the at least one virtual server comprises at least one virtual application, the at least one virtual application being a virtual duplicate of the at least one protected application.

18 . The computer program product of claim 17 , wherein the computer-readable medium further comprises code for causing the computer to apply at least one of a pre-application security utility and a post-application security utility.

19 . The computer program product of claim 15 , wherein the computer-readable medium further comprises code for causing the computer to block passage of the data packet to the protected network, in response to the data packet failing the inspection.

20 . The computer program product of claim 15 , wherein the portion comprises a modified version of the inspected data packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2010
From: GARGETT, CHARLES DUNELM
To: IWEBGATE TECHNOLOGY LIMITED
Reel/Frame 025538/0827 →