IP Library Granted Patent US 8,356,089
Granted Patent B1
US 8,356,089 · App. 13/531,248 · Granted Jan 15, 2013

Network services platform

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,356,089
App. No.
13/531,248
Granted
Jan 15, 2013
Kind
B1
Abstract

A network services platform provides services to remote enterprise networks. The services platform provides a control module to a computer in the enterprise network. The control module executes on the computer and interacts with the services platform to establish an Internet Protocol (IP) tunnel between the services platform and the computer. The control module also establishes a bridge between the IP tunnel and the enterprise network. The services platform allocates a unique private IP address space to the enterprise network, and translates IP addresses in network communications between enterprise network addresses and corresponding services platform addresses in the allocated unique private address space. The services platform provides network services to the enterprise network via the IP tunnel and bridge.

Claims (42)

1. A computer-implemented method of using a services platform to provide a network service to a remote enterprise network, comprising:

using a computer to perform steps comprising:

providing a control module to an endpoint of the remote enterprise network responsive to a request for the network service from a user of the endpoint;

establishing an Internet Protocol (IP) tunnel between the services platform and the endpoint responsive to execution of the control module on the endpoint;

establishing a bridge between the IP tunnel and the enterprise network responsive to the execution of the control module on the endpoint, wherein establishing the bridge comprises the control module using packet injection at the endpoint to inject packets from the IP tunnel to the enterprise network, the packets injected to the enterprise network appearing to originate from the endpoint, and the control module sending packets from the enterprise network received by the endpoint through the IP tunnel; and

providing the network service to the enterprise network via the IP tunnel and bridge.

2. The computer-implemented method of claim 1 , wherein the tunnel is formed at a layer of an Open Systems Interconnection model.

3. The computer-implemented method of claim 1 , further comprising:

allocating a unique private IP address space to the enterprise network;

inventorying the enterprise network to identify a plurality of endpoints on the enterprise network, ones of the plurality of endpoints identified with enterprise network IP addresses in an enterprise address space; and

assigning service platform IP addresses within the unique private IP address space to identified ones of the plurality of endpoints.

4. The computer-implemented method of claim 3 , further comprising:

translating IP addresses in network traffic received by the services platform from the enterprise network via the IP tunnel from enterprise network IP addresses to corresponding service platform IP addresses; and

translating IP addresses in network traffic destined from the services platform to the enterprise network via the IP tunnel from services platform IP addresses to corresponding IP enterprise network addresses.

5. The computer-implemented method of claim 3 , wherein the services platform provides network services to a plurality of remote enterprise networks and wherein a different unique private IP address space is allocated to each of the plurality of enterprise networks.

6. The computer-implemented method of claim 1 , wherein providing the network service to the enterprise network comprises providing one or more network services from the set consisting of:

vulnerability management, configuration auditing, file integrity monitoring, and compliance auditing.

7. A services platform for providing a network service to a remote enterprise network comprising:

a non-transitory computer-readable storage medium storing executable computer program modules; and

a computer processor for executing the computer program modules for performing steps comprising:

providing a control module to an endpoint of the remote enterprise network responsive to a request for the network service from a user of the endpoint;

establishing an Internet Protocol (IP) tunnel between the services platform and the endpoint responsive to execution of the control module on the endpoint;

establishing a bridge between the IP tunnel and the enterprise network responsive to the execution of the control module on the endpoint, wherein establishing the bridge comprises the control module using packet injection at the endpoint to inject packets from the IP tunnel to the enterprise network, the packets injected to the enterprise network appearing to originate from the endpoint, and the control module sending packets from the enterprise network received by the endpoint through the IP tunnel; and

providing the network service to the enterprise network via the IP tunnel and bridge.

8. The services platform of claim 7 , wherein the tunnel is formed at a layer of an Open Systems Interconnection model.

9. The services platform of claim 7 , further comprising:

allocating a unique private IP address space to the enterprise network;

inventorying the enterprise network to identify a plurality of endpoints on the enterprise network, ones of the plurality of endpoints identified with enterprise network IP addresses in an enterprise space; and

assigning service platform IP addresses within the unique private IP address space to identified ones of the plurality of endpoints.

10. The services platform of claim 9 , further comprising:

translating IP addresses in network traffic received by the services platform from the enterprise network via the IP tunnel from enterprise network IP addresses to corresponding service platform IP addresses; and

translating IP addresses in network traffic destined from the services platform to the enterprise network via the IP tunnel from services platform IP addresses to corresponding IP enterprise network addresses.

11. The services platform of claim 9 , wherein the services platform provides network services to a plurality of remote enterprise networks and wherein a different unique private IP address space is allocated to each of the plurality of enterprise networks.

12. The services platform of claim 7 , wherein providing the network service to the enterprise network comprises providing one or more network services from the set consisting of:

vulnerability management, configuration auditing, file integrity monitoring, and compliance auditing.

13. A non-transitory computer-readable storage medium storing executable computer program modules for enabling a services platform to provide a network service to a remote enterprise network, the modules comprising:

an interaction module for interacting with a user of an endpoint of the enterprise network to enable the user to request the network service from the services platform;

a tunnel creation module for creating an IP tunnel between the endpoint and the services platform responsive to the request for the network service from the user of the endpoint; and

a bridging module for bridging the IP tunnel with the enterprise network, wherein bridging the IP tunnel with the enterprise network comprises using packet injection at the endpoint to inject packets from the IP tunnel to the enterprise network, the packets injected to the enterprise network appearing to originate from the endpoint, and sending packets from the enterprise network received by the endpoint through the IP tunnel;

wherein the services platform provides the requested network service via the IP tunnel bridged with the enterprise network.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the network service comprises a network service from the set consisting of:

vulnerability management, configuration auditing, file integrity monitoring, and compliance auditing.

Assignments (10)
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2021
From: QUILTER, ALEXANDER L.; LAVERY, OLIVER; MELTZER, DAVID J.; KEANINI, TIMOTHY D.
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 058309/0452 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2014
From: NCIRCLE NETWORK SECURITY, INC.
To: TRIPWIRE, INC.
Reel/Frame 032124/0592 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →