IP Library Granted Patent US 8,881,258
Granted Patent B2
US 8,881,258 · App. 13/216,516 · Granted Nov 4, 2014

System, method, and computer program for preventing infections from spreading in a network environment using dynamic application of a firewall policy

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,881,258
App. No.
13/216,516
Granted
Nov 4, 2014
Kind
B2
Abstract

A method for containing a threat in network environment using dynamic firewall policies is provided. In one example embodiment, the method can include detecting a threat originating from a first node having a source address in a network, applying a local firewall policy to block connections with the source address, and broadcasting an alert to a second node in the network. In more particular embodiments, an alert may be sent to a network administrator identifying the source address and providing remedial information. In yet other particular embodiments, the method may also include applying a remote firewall policy to the first node blocking outgoing connections from the first node.

Claims (35)

1. A method, comprising:

detecting, at a first node having a security-as-a-service (SaaS) agent, a threat originating from a source node having a source address in a network, wherein the network includes at least the first node and a plurality of nodes each having a respective SaaS agent;

applying a local firewall policy on the first node to block incoming connections associated with the source address;

broadcasting, from the first node, an alert to the respective SaaS agents of the plurality of nodes in the network, wherein the broadcast alert comprises the source address of the source node from which the threat originated, wherein broadcasting the alert comprises broadcasting the local firewall policy;

identifying, by the first node, a presence of an SaaS firewall module of the source node; and

responsive to identifying the presence of the SaaS firewall module on the source node, communicating to the source node to apply a remote firewall policy to block outgoing connections from the source node to the plurality of nodes in the network.

2. The method of claim 1 , further comprising alerting a network administrator.

3. The method of claim 1 , wherein the threat is malware on the source node.

4. The method of claim 1 , wherein the network is an intranet.

5. The method of claim 1 , further comprising:

alerting a network administrator;

wherein broadcasting the alert comprises broadcasting the source address and instructions for applying the local firewall policy.

6. The method of claim 1 , wherein the plurality of nodes of the network comprises an SaaS platform, wherein the SaaS platform includes a combination of at least one SaaS antivirus module and at least one SaaS firewall module in each node of the plurality of nodes.

7. Logic encoded in one or more non-transitory media that includes code for execution and when executed by one or more processors is operable to perform operations comprising:

detecting, at a first node having a security-as-a-service (SaaS) agent, a threat originating from a source node having a source address in a network, wherein the network includes at least the first node and a plurality of nodes each having a respective SaaS agent;

applying a local firewall policy on the first node to block incoming connections associated with the source address;

broadcasting, from the first node, an alert to the respective SaaS agents of the plurality of nodes in the network, wherein the broadcast alert comprises the source address of the source node from which the threat originated, wherein broadcasting the alert comprises broadcasting the local firewall policy;

identifying, by the first node, a presence of an SaaS firewall module of the source node; and

responsive to identifying the presence of the SaaS firewall module on the source node, communicating to the source node to apply a remote firewall policy to block outgoing connections from the source node to the plurality of nodes in the network.

8. The encoded logic of claim 7 , further comprising alerting a network administrator.

9. The encoded logic of claim 7 , wherein the threat is malware on the source node.

10. The encoded logic of claim 7 , wherein the plurality of nodes of the network comprises an SaaS platform, wherein the SaaS platform includes a combination of at least one SaaS antivirus module and at least one SaaS firewall module in each node of the plurality of nodes.

11. A first node, comprising:

an antivirus module;

a local firewall module;

a dynamic policy module; and

one or more processors operable to execute instructions associated with the antivirus module, the local firewall module, and the dynamic policy module such that the first node is configured for:

detecting, at a first node having a security-as-a-service (SaaS) agent, a threat originating from a source node having a source address in a network, wherein the network includes at least the first node and a plurality of nodes each having a respective SaaS agent;

applying a local firewall policy on the first node to block incoming connections associated with the source address;

broadcasting, from the first node, an alert to the respective SaaS agents of the plurality of nodes in the network, wherein the broadcast alert comprises the source address of the source node from which the threat originated, wherein broadcasting the alert comprises broadcasting the local firewall policy;

identifying, by the first node, a presence of an SaaS firewall module of the source node; and

responsive to identifying the presence of the SaaS firewall module on the source node, communicating to the source node to apply a remote firewall policy to block outgoing connections from the source node to the plurality of nodes in the network.

12. The first node of claim 11 , further comprising alerting a network administrator.

13. The first node of claim 11 , wherein the threat is ma ware on the source node.

14. The first node of claim 11 , wherein the SaaS agent includes the antivirus module, the local firewall module, and the dynamic policy module.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2011
From: PAUL, MANABENDRA; SUDHARMA, PRAVEEN RAVICHANDRAN
To: MCAFEE, INC.
Reel/Frame 026799/0191 →