IP Library Granted Patent US 9,560,014
Granted Patent B2
US 9,560,014 · App. 13/748,578 · Granted Jan 31, 2017

System and method for an endpoint hardware assisted network firewall in a security environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,560,014
App. No.
13/748,578
Granted
Jan 31, 2017
Kind
B2
Abstract

A method is provided in one example embodiment and includes receiving a traffic flow at a tamper resistant environment from an application, where the tamper resistant environment is separated from a host operating system. The method also includes applying a security token to the traffic flow and sending the traffic flow to a server. In specific embodiments, a security module may add information about the application to traffic flow. A trapping module may monitor for a memory condition and identify the memory condition. The trapping module may also, responsive to identifying the memory condition, initiate a virtual environment for the application, and check the integrity of the traffic flow.

Claims (69)

1. A method comprising:

receiving, at a tamper resistant environment on a host from a virtualization environment of the host, information associated with an application executing on the host;

receiving a traffic flow at the tamper resistant environment from the application, wherein the tamper resistant environment is separated from an operating system of the host;

creating a modified traffic flow by applying a security token to the received traffic flow and by adding the information to the received traffic flow; and

sending the modified traffic flow to a server.

2. The method of claim 1 , where the security token is derived from an enhanced privacy identification to attest that the tamper resistant environment is trusted.

3. The method of claim 1 , wherein the security token is derived by the tamper resistant environment, wherein the information added to the received traffic flow includes metadata and wherein applying the security token to the received traffic flow comprises:

digitally signing the metadata using public key cryptography.

4. The method of claim 1 , further comprising:

monitoring a memory of the host for a memory condition;

identifying the memory condition;

assigning the application to a virtual machine in the virtualization environment based, at least in part, on identifying the memory condition;

trapping, in the virtualization environment, process events associated with the traffic flow; and

checking the integrity of the traffic flow before the traffic flow is delivered to the tamper resistant environment.

5. The method of claim 1 , further comprising:

monitoring a memory of the host for a memory condition;

identifying the memory condition; and

scanning the memory for integrity based, at least in part, on identifying the memory condition.

6. The method of claim 4 , wherein monitoring for the memory condition comprises:

monitoring regions of the memory associated with buffers used to send data for the memory condition.

7. The method of claim 4 , wherein initiating the virtual environment for the application comprises:

assigning the application to the virtual machine randomly based, at least in part, on identifying the memory condition.

8. The method of claim 4 , wherein the checking the integrity of the traffic flow before the traffic flow is delivered to the tamper resistant environment comprises:

checking the integrity of the traffic flow randomly.

9. At least one non-transitory computer-readable medium that includes code for execution and when executed by a processor is operable to perform operations comprising:

receiving, at a tamper resistant environment on a host from a virtualization environment on the host, information associated with an application executing on the host;

receiving a traffic flow at the tamper resistant environment from the application, wherein the tamper resistant environment is separated from an operating system of the host;

creating a modified traffic flow by applying a security token to the received traffic flow and by adding the information to the received traffic flow; and

sending the modified traffic flow to a server.

10. The computer-readable medium of claim 9 , wherein the security token is derived from an enhanced privacy identification to attest that the tamper resistant environment is trusted.

11. The computer-readable medium of claim 9 , wherein the security token is derived by the tamper resistant environment, wherein the information added to the received traffic flow includes metadata and wherein the code applying the security token to the received traffic flow comprises code for:

digitally signing the metadata using public key cryptography.

12. The computer-readable medium of claim 9 , wherein the code, when executed by the processor, is operable to perform further operations comprising:

monitoring a memory of the host for a memory condition;

identifying the memory condition;

assigning the application to a virtual machine in the virtualization environment based, at least in part, on identifying the memory condition;

trapping, in the virtualization environment, process events associated with the traffic flow; and

checking the integrity of the traffic flow before the traffic flow is delivered to the tamper resistant environment.

13. The computer-readable medium of claim 9 , wherein the code, when executed by the processor, is operable to perform further operations comprising:

monitoring a memory of the host for a memory condition;

identifying the memory condition; and

scanning the memory for integrity based, at least in part, on identifying the memory condition.

14. The computer-readable medium of claim 12 , wherein the code for monitoring for the memory condition, when executed by the processor, is operable to perform further operations comprising:

monitoring regions of the memory associated with buffers used to send data for the memory condition.

15. An apparatus, comprising:

a memory element configured to store data;

a processor operable to execute instructions associated with the data; and

a security engine configured to interface with the memory element and the processor to:

receive, from a virtualization environment of a host, information associated with an application executing on the host;

receive a traffic flow at the tamper resistant environment from the application, wherein the tamper resistant environment is separated from an operating system of the host;

create a modified traffic flow by applying a security token to the received traffic flow and by adding the information to the received traffic flow; and

send the modified traffic flow to a server.

16. The apparatus of claim 15 , further comprising:

a trapping module configured to:

monitor a memory of the host for a memory condition;

identify the memory condition;

assign the application to a virtual machine in the virtualization environment based, at least in part, on identifying the memory condition;

trap, in the virtual environment, process events associated with the traffic flow; and

check the integrity of the traffic flow before the traffic flow is delivered to the tamper resistant environment.

17. The apparatus of claim 15 , wherein the security engine is further configured to:

monitor a memory of the host for a memory condition;

identify the memory condition; and

scan the memory for integrity based, at least in part, on identifying the memory condition.

18. The computer-readable medium of claim 12 , wherein the code, when executed by the processor, is operable to perform further operations comprising:

initiating the virtual environment for the application by assigning the application to the virtual machine randomly based, at least in part, on identifying the memory condition.

19. The computer-readable medium of claim 12 , wherein the code, when executed by the processor, is operable to perform further operations comprising:

firing a virtualization trap only when a condition is asserted based on a configured probabilistic configuration.

20. The computer-readable medium of claim 12 , wherein the checking the integrity of the traffic flow before the traffic flow is delivered to the tamper resistant environment comprises:

checking the integrity of the traffic flow randomly.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2014
From: GROBMAN, STEVE; SAMANI, RAJ; ARKIN, OFIR; SCHRECKER, SVEN
To: MCAFEE INC.
Reel/Frame 032400/0457 →