IP Library Granted Patent US 8,713,668
Granted Patent B2
US 8,713,668 · App. 13/275,249 · Granted Apr 29, 2014

System and method for redirected firewall discovery in a network environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,713,668
App. No.
13/275,249
Granted
Apr 29, 2014
Kind
B2
Abstract

A method is provided in one example embodiment that includes receiving metadata from a host over a metadata channel. The metadata may be correlated with a network flow and a network policy may be applied to the connection. In other embodiments, a network flow may be received from a host without metadata associated with the flow, and a discovery redirect may be sent to the host. Metadata may then be received and correlated with the flow to identify a network policy action to apply to the flow.

Claims (52)

1. A computer-readable non-transitory medium comprising one or more instructions that when executed on a processor configure the processor to perform one or more operations for redirected firewall discovery, the one or more operations comprising:

intercepting, at a first firewall in a network environment, a network flow from a source node;

when the first firewall does not have metadata associated with the network flow in a metadata cache of the first firewall or the first firewall is unable to retrieve the metadata associated with the network flow, sending a discovery redirect from a host manager to cause a firewall cache at the source node to include a second firewall;

receiving the metadata associated with the network flow at the second firewall; and

correlating, at the second firewall, the metadata with the network flow to apply a network policy at the second firewall to the network flow.

2. The computer-readable non-transitory medium of claim 1 , wherein the discovery redirect is an Internet Control Message Protocol packet.

3. The computer-readable non-transitory medium of claim 1 , wherein the discovery redirect is an Internet Control Message Protocol Destination Unreachable packet.

4. The computer-readable non-transitory medium of claim 1 , wherein the discovery redirect is an Internet Control Message Protocol Destination Unreachable packet for administratively prohibited communications.

5. The computer-readable non-transitory medium of claim 1 , wherein the discovery redirect comprises a hash-based message authentication code.

6. The computer-readable non-transitory medium of claim 1 , wherein the discovery redirect comprises a hash-based message authentication code with a shared secret.

7. The computer-readable non-transitory medium of claim 1 , wherein the discovery redirect comprises a private key encryption of a hash of the discovery redirect.

8. The computer-readable non-transitory medium of claim 1 , wherein the metadata is received on a metadata channel.

9. The computer-readable non-transitory medium of claim 1 , wherein the metadata is received using a Datagram Transport Layer Security protocol.

10. The computer-readable non-transitory medium of claim 1 , further comprising caching a first packet in the network flow.

11. A computer-readable non-transitory medium comprising one or more instructions that when executed on a processor configure the processor to perform one or more operations, the one or more operations, comprising:

intercepting a network flow from a source node to a destination node at a firewall agent of the source node;

holding a first packet of the network flow at the firewall agent of the source node;

identifying, in a firewall cache by the firewall agent, a firewall for managing a route to the destination node;

opening a metadata connection with the firewall;

sending metadata associated with the network flow from the firewall agent to the firewall over the metadata connection while holding the first packet of the network flow; and

releasing the network flow by sending the first packet of the network flow from the firewall agent to the firewall.

12. The computer-readable non-transitory medium of claim 11 , wherein the network flow uses a Transmission Control Protocol and intercepting the network flow comprises detecting a SYN packet from the source node.

13. The computer-readable non-transitory medium of claim 11 , wherein the network flow uses an unreliable protocol and intercepting the network flow comprises caching a first packet of the flow until the metadata is sent.

14. The computer-readable non-transitory medium of claim 11 , wherein the metadata is sent using a Datagram Transport Layer Security protocol.

15. The computer-readable non-transitory medium of claim 11 , wherein the operations further comprise:

receiving a discovery redirect from a second firewall; and

sending the metadata to the second firewall over a metadata channel.

16. The computer-readable non-transitory medium of claim 11 , wherein the operations further comprise:

receiving a discovery redirect from a second firewall;

updating a firewall cache to identify the second firewall for managing the route to the destination; and

sending the metadata to the second firewall over a metadata channel.

17. The computer-readable non-transitory medium of claim 11 , wherein the operations further comprise:

receiving a discovery redirect from a second firewall; and

sending the metadata to the second firewall using a Datagram Transport Layer Security protocol.

18. The computer-readable non-transitory medium of claim 11 , wherein the operations further comprise:

receiving a discovery redirect from a second firewall;

authenticating the discovery redirect with a message authentication code; and

sending the metadata to the second firewall over a metadata channel.

19. The computer-readable non-transitory medium of claim 11 , wherein the operations further comprise:

receiving a discovery redirect from a second firewall;

authenticating the discovery redirect with a public key decryption of a hash of the discovery redirect; and

sending the metadata to the second firewall over a metadata channel.

20. The computer-readable non-transitory medium of claim 11 , wherein the operations further comprise:

caching a first packet in the network flow;

receiving a discovery redirect from a second firewall;

sending the metadata to the second firewall over a metadata channel; and

sending the first packet to the second firewall.

21. The computer-readable non-transitory medium of claim 11 , wherein the operations further comprise:

receiving a discovery redirect from a second firewall;

updating a firewall cache to identify the second firewall for managing the route to the destination; and

sending the metadata to the second firewall over a metadata channel; and

wherein updating the firewall cache comprises adding a new entry for the destination node with a mask length incrementally modified over a prior entry for the destination node.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2011
From: COOPER, GEOFFREY; GREEN, MICHAEL W.; GUZIK, JOHN RICHARD
To: MCAFEE, INC.
Reel/Frame 027073/0940 →