IP Library Granted Patent US 9,258,241
Granted Patent B2
US 9,258,241 · App. 14/044,796 · Granted Feb 9, 2016

Transparent provisioning of services over a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,258,241
App. No.
14/044,796
Granted
Feb 9, 2016
Kind
B2
Abstract

An apparatus and method for enhancing the infrastructure of a network such as the Internet is disclosed. A packet interceptor/processor apparatus is coupled with the network so as to be able to intercept and process packets flowing over the network. Further, the apparatus provides external connectivity to other devices that wish to intercept packets as well. The apparatus applies one or more rules to the intercepted packets which execute one or more functions on a dynamically specified portion of the packet and take one or more actions with the packets. The apparatus is capable of analyzing any portion of the packet including the header and payload. Actions include releasing the packet unmodified, deleting the packet, modifying the packet, logging/storing information about the packet or forwarding the packet to an external device for subsequent processing. Further, the rules may be dynamically modified by the external devices.

Claims (34)

1. A method of transparently provisioning at least one service to a network, each of the at least one service being provided by at least one application service provider of a plurality of application service providers to the network via at least one application associated therewith, the network carrying a plurality of packets each being transmitted by a source to at least one intended destination intended by the source, each of the plurality of packets comprising routing data operative to cause the forwarding of the packet via the network towards the at least one intended destination, the method comprising:

interfacing between an interface to the network and a first application of the at least one application associated with a first application service provider of the plurality of application service providers, the first application operative to perform a first service of the at least one service;

interfacing between the interface to the network and a second application of the at least one application associated with a second application service provider of the plurality of application service providers, the second application operative to perform a second service of the at least one service;

intercepting, via the interface, each of the plurality of packets prior to a forwarding thereof toward the at least one intended destination;

evaluating each intercepted packet based on a first specification of a first subset of the plurality of packets with respect to which the first application is to perform the first service and a second specification of a second subset of the plurality of packets with respect to which the second application is to perform the second service, wherein at least the first specification specifies the first subset based on criteria other than only the routing data contained in the intercepted packet; and

acting on the intercepted packet, based on the evaluating, to facilitate the performance of the first service, the second service or a combination thereof with respect to the intercepted packet when the intercepted packet is included in the specified first subset, the specified second subset, or a combination thereof,

wherein the acting comprises acting on the intercepted packet, based on the evaluating, to facilitate the performance of the first service, the second service, or a combination thereof, such that the source, the at least one intended destination, a service provider, or a combination thereof is unaware of the performance of the first service, the second service, or the combination thereof.

2. The method of claim 1 wherein the acting comprises acting, responsive to the first application, the second application, or a combination thereof, on the intercepted packet, based on the evaluating, to facilitate the performance of the first service, the second service, or a combination thereof with respect to the intercepted packet when the intercepted packet is included in the specified first subset, the specified second subset, or a combination thereof.

3. The method of claim 2 wherein the acting further comprises arbitrating, between the first application and the second application, when the intercepted packet is included in both the specified first subset and the specified second subset.

4. The method of claim 3 wherein the arbitrating comprises providing the intercepted packet only to the first application when the intercepted packet is included in both the specified first subset and the specified second subset.

5. The method of claim 1 wherein the interfacing between the first application and the interface to the network comprises interfacing between the first application and the interface to the network such that the first application is unaware that the first application is indirectly connected with the network, and

wherein the interfacing between the second application and the interface to the network comprises interfacing between the second application and the interface to the network such that the second application is unaware that the second application is indirectly connected with the network.

6. The method of claim 1 wherein the acting comprises providing at least a copy of at least a portion of the intercepted packet to the first application, the second application, or a combination thereof.

7. The method of claim 1 wherein the acting comprises deleting the intercepted packet.

8. The method of claim 1 wherein the acting comprises modifying the intercepted packet.

9. The method of claim 1 wherein the acting comprises substituting a modified intercepted packet for the intercepted packet.

10. The method of claim 1 wherein the acting comprises substituting a new packet for the intercepted packet.

11. The method of claim 1 wherein the acting comprises allowing the intercepted packet to continue to the at least one intended destination.

12. A system for transparently provisioning at least one service to a network, each service of the at least one service being provided by at least one application service provider of a plurality of application service providers to the network via at least one application associated therewith, the network carrying a plurality of packets each being transmitted by a source to at least one intended destination intended by the source, each of the plurality of packets comprising routing data operative to cause the forwarding of the packet via the network towards the at least one intended destination, the system comprising:

a packet processor coupled between the network and a first application of the at least one application associated with a first application service provider of the plurality of application service providers, and a second application of the at least one application associated with a second application service provider of the plurality of application service providers, the first application operative to perform a first service of the at least one service, the second application operative to perform a second service of the at least one service, and operative to intercept a packet of the plurality of packets prior to a forwarding of the intercepted packet toward the at least one intended destination, evaluate the intercepted packet based on a first specification of a first subset of the plurality of packets with respect to which the first application is to perform the first service and a second specification of a second subset of the plurality of packets with respect to which the second application is to perform the second service, and act on the intercepted packet to facilitate the performance of the first service, the second service, or a combination thereof with respect to the intercepted packet when the intercepted packet is included in the specified first subset, the specified second subset, or a combination thereof,

wherein at least the first specification specifies the first subset based on criteria other than only the routing data contained in the intercepted packet, and

wherein the packet processor is further operative to act on the intercepted packet, based on the evaluation, to facilitate the performance of the first service, the second service, or a combination thereof, such that the source, the at least one intended destination, a service provider, or a combination thereof is unaware of the performance of the first service, the second service, or the combination thereof.

13. The system of claim 12 wherein the packet processor is further operative to receive a result of the performance of the first service, the second service, or a combination thereof on the intercepted packet from the first application, the second applications, or a combination thereof, and

wherein the result comprises an instruction to delete the intercepted packet, an instruction to modify the intercepted packet, an instruction to substitute a modified intercepted packet for the intercepted packet, an instruction to substitute a new packet for the intercepted packet, an instruction to allow the intercepted packet to continue to the at least one intended destination, an instruction to respond to the source, or combinations thereof, the packet processor being further operative to execute the instruction.

14. The system of claim 12 wherein the packet processor is further operative to act, responsive to the first application, the second application, or a combination thereof, on the intercepted packet, based on the evaluation, to facilitate the performance of the first service, the second service, or a combination thereof with respect to the intercepted packet when the intercepted packet is included in the specified first subset, the specified second subset, or a combination thereof.

15. The system of claim 14 wherein the packet processor is further operative to arbitrate, between the first application and the second application, when the intercepted packet is included in both the specified first subset and the specified second subset.

16. The system of claim 15 wherein the arbitration comprises provision of the intercepted packet only to the first application when the intercepted packet is one of the first subset and one of the second subset.

17. A system for transparently provisioning at least one service to a network, each of the at least one service being provided by at least one application service provider of a plurality of application service providers to the network via at least one application associated therewith, the network carrying a plurality of packets each being transmitted by a source to at least one intended destination intended by the source, each of the plurality of packets comprising routing data operative to cause the forwarding of the packet via the network towards the at least one intended destination, the system comprising a processor, a memory coupled with the processor, a network interface operative to couple the processor with the network, and an application interface operative to couple the processor with a first application of the at least one application associated with a first application service provider of the plurality of application service providers and a second application of the at least one application associated with a second application service provider of the plurality of application service providers, the first application operative to perform a first service of the at least one service, the second application operative to perform a second service of the at least one service, the system further comprising:

first logic stored in the memory and executable by the processor to cause the processor to intercept a packet of the plurality of packets prior to a forwarding of the packet toward the at least one intended destination;

second logic, coupled with the first logic, stored in the memory and executable by the processor to cause the processor to evaluate the intercepted packet based on a first specification of a first subset of the plurality of packets with respect to which the first application is to perform the first service and a second specification of a second subset of the plurality of packets with respect to which the second application is to perform the second service, wherein at least the first specification specifies the first subset based on criteria other than only the routing data contained in the intercepted packet; and

third logic, coupled with the second logic, stored in the memory and executable by the processor to cause the processor to act on the intercepted packet to facilitate the performance of the first service, the second service, or a combination thereof with respect to the intercepted packet when the intercepted packet is included in the specified first subset, the specified second subset, or a combination thereof,

wherein the third logic is executable by the processor to cause the processor to act on the intercepted packet, based on the evaluation, to facilitate the performance of the first service, the second service, or a combination thereof, such that the source, the at least one intended destination, a service provider, or a combination thereof is unaware of the performance of the first service, the second service, or the combination thereof.

18. The system of claim 17 wherein the third logic is executable by the processor to cause the processor to act, responsive to the first application, the second application, or a combination thereof, on the intercepted packet, based on the evaluation, to facilitate the performance of the first service, the second service, or a combination thereof with respect to the intercepted packet when the intercepted packet is included in the specified first subset, the specified second subset, or a combination thereof.

19. The system of claim 18 further comprising fourth logic, coupled with the third logic, stored in the memory and executable by the processor to cause the processor to arbitrate, between the first application and the second application, when the intercepted packet is included in both the specified first subset and the specified second subset.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: LOOKINGGLASS CYBER SOLUTIONS, LLC
Reel/Frame 067429/0361 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0803 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0715 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2023
From: SILICON VALLEY BANK
To: CLOUDSHIELD TECHNOLOGIES, LLC
Reel/Frame 062872/0851 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2023
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 062847/0569 →
SECURITY INTEREST Recorded May 11, 2022
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: EASTWARD FUND MANAGEMENT, LLC
Reel/Frame 059892/0963 →
SECURITY INTEREST Recorded Aug 24, 2021
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: SILICON VALLEY BANK
Reel/Frame 057274/0638 →
SECURITY INTEREST Recorded Jul 12, 2021
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: EASTWARD FUND MANAGEMENT
Reel/Frame 056823/0269 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2018
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 047205/0192 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2017
From: JUNGCK, PEDER J.; DROWN, MATTHEW D.; GOLLER, SEAN M.
To: CLOUDSHIELD TECHNOLOGIES, INC.
Reel/Frame 043103/0182 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2016
From: PACIFIC WESTERN BANK
To: CLOUDSHIELD TECHNOLOGIES, LLC
Reel/Frame 039214/0024 →
SECURITY INTEREST Recorded Nov 19, 2015
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: PACIFIC WESTERN BANK
Reel/Frame 037094/0199 →