IP Library Granted Patent US 9,521,113
Granted Patent B2
US 9,521,113 · App. 13/931,075 · Granted Dec 13, 2016

Self-configuring local area network security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,521,113
App. No.
13/931,075
Granted
Dec 13, 2016
Kind
B2
Abstract

Technologies for providing electronic security to a first network are disclosed. The system may include a user equipment, a gateway device configured to mediate communication between a first network and a second network for the user equipment, and an electronic security device communicatively coupled to the gateway device. The electronic security device may include a gateway interface module configured to assume an identity associated with the gateway device, a network interface module configured to present the identity to the second network, and a traffic inspection module configured to monitor traffic without substantially affecting a topology of the first network, wherein the electronic security device is configured to identify undesirable traffic; and implement a security policy.

Claims (43)

1. An electronic security device for providing electronic security to a first network, the electronic security device comprising:

a processor;

a gateway interface module comprising instructions, when loaded and executed by the processor, configured to assume an identity of a gateway device communicatively coupled to the electronic security device and configured to mediate communication between the first network and a second network, wherein assuming the identity of the gateway device is performed by altering an Address Resolution Protocol;

a network interface module comprising instructions, when loaded and executed by the processor, configured to present the identity to the second network;

a traffic inspection module comprising instructions, when loaded and executed by the processor, configured to:

monitor traffic from the first network to the second network without substantially affecting a topology of the first network, wherein the electronic security device is configured to identify undesirable traffic; and

implement a security policy, the security policy comprising instructions for handling the undesirable traffic;

wherein the electronic security device is:

communicatively coupled to the first network and to the second network through the gateway device;

resident in the first network with the gateway device; and

configured to, through the gateway device, present the identity to the second network, monitor traffic from the first network to the second network, and implement the security policy.

2. The electronic security device of claim 1 , wherein the gateway interface module is further configured to alter an Address Resolution Protocol (“ARP”) request.

3. The electronic security device of claim 1 , wherein the gateway interface module is configured to assume the identity of the gateway device by obtaining a public IP address associated with the gateway device.

4. The electronic security device of claim 3 , wherein:

the gateway interface module is further configured to obtain a local IP address associated with the first network; and

the network interface module is further configured to communicate data associated with the local IP address and data associated with the public IP address to a user equipment associated with the first network.

5. The electronic security device of claim 4 , wherein the electronic security device further comprises a web service, wherein the web service is configured to provide the user equipment with access to the data associated with the local IP address and the data associated with the public IP address.

6. At least one non-transitory machine readable storage medium, comprising computer-executable instructions carried on the machine readable storage medium, the instructions readable by a processor incorporated by an electronic security device, the instructions, when read and executed, causing the electronic security device to:

assume an identity of a gateway device communicatively coupled to the electronic security device and resident in a same first network as the electronic security device, the gateway device configured to mediate communication between the first network and a second network, wherein assuming the identity of the gateway device is performed by altering an Address Resolution Protocol;

present the identity to the second network;

monitor traffic from the first network to the second network without substantially affecting a topology of the first network, wherein the electronic security device is configured to identify undesirable traffic; and

implement a security policy, the security policy comprising instructions for handling the undesirable traffic;

wherein the electronic security device is communicatively coupled to the first network and to the second network through the gateway device; and

wherein the electronic security device is caused to, through the gateway device, present the identity to the second network, monitor traffic from the first network to the second network, and implement the security policy.

7. The medium of claim 6 , further comprising machine executable instructions for causing the processor to alter an Address Resolution Protocol (“ARP”) request.

8. The medium of claim 6 , wherein assuming the identity of the gateway device comprises obtaining a public IP address associated with the gateway device.

9. The medium of claim 8 , further comprising machine executable instructions for causing the processor to:

obtain a local IP address associated with the first network; and

communicate data associated with the local IP address and data associated with the public IP address to a user equipment associated with the first network.

10. The medium of claim 9 , further comprising machine executable instructions for causing the processor to provide the user equipment with access to the data associated with the local IP address and the data associated with the public IP address.

11. A method for providing electronic security to a first network, the method comprising:

assuming, by an electronic security device, an identity of a gateway device communicatively coupled to the electronic security device and resident in the same first network as the electronic security device, the gateway device configured to mediate communication between the first network and a second network, wherein assuming the identity of the gateway device is performed by altering an Address Resolution Protocol;

presenting, by the electronic security device, the identity to the second network;

monitoring, by the electronic security device, traffic from the first network to the second network without substantially affecting a topology of the first network, wherein the electronic security device is configured to identify undesirable traffic; and

implementing, by the electronic security device, a security policy, the security policy comprising instructions for handling the undesirable traffic;

wherein the electronic security device is communicatively coupled to the first network and to the second network through the gateway device; and

wherein presenting the identity to the second network, monitoring traffic from the first network to the second network, and implementing the security policy is performed through the gateway device.

12. The method of claim 11 , further comprising altering an Address Resolution Protocol (“ARP”) request.

13. The method of claim 11 , wherein assuming the identity of the gateway device comprises obtaining a public IP address associated with the gateway device.

14. The method of claim 13 , further comprising

obtaining a local IP address associated with the first network; and

communicating data associated with the local IP address and data associated with the public IP address to a user equipment associated with the first network.

15. The method of claim 14 , further comprising providing the user equipment with access to the data associated with the local IP address and the data associated with the public IP address.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME AND STREET ADDRESS PREVIOUSLY RECORDED ON REEL 030878 FRAME 0283. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNEE NAME AND STREET ADDRESS TO READ "MCAFEE, INC., 3965 FREEDOM CIRCLE". Recorded Sep 27, 2013
From: NAIR, JAYAKRISHNAN K.; HUNT, SIMON; VENKATESWARAN, PRASANNA; RAMANAN, VENKATA
To: MCAFEE, INC.
Reel/Frame 031305/0673 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2013
From: NAIR, JAYAKRISHNAN K.; HUNT, SIMON; VENKATESWARAN, PRASANNA; RAMANAN, VENKATA
To: INTEL IP CORPORATION
Reel/Frame 030878/0283 →