IP Library Patent Application 14242768
Patent Application
App. No. 14/242,768

Method And Technique for Automated Collection, Analysis, and Distribution of Network Security Threat Information

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/242,768
Abstract

A Method and Technique for Automated Collection, Analysis, and Distribution of Network Security Threat Information. A new and modern threat distribution system be able to update a large number of distributed firewall devices with threat information without impacting performance. The network of firewall devices collects analysis data from all firewall devices in the network, and transmits it to a central server system. The central server system will continually distribute new threat and update information to the networked firewall devices. This feedback and update operation within the network is automated in order to result in drastic improvements in the performance, scalability and security of a modern network infrastructure.

Claims (46)

1 . An automated distributed wide area computer network firewall system, comprising:

a central threat server computing device in communication with a wide area computer network;

a first firewall device in communication with said wide area computer network on an external side and a local area computer network on an internal side;

a second firewall device in communication with said wide area computer network on an external side and a local area computer network on an internal side; and

wherein each said firewall device comprises:

an internal IP Host subsystem in communication with said central threat server computing device via said wide area computer network to receive threat reports from said central threat server computing device;

an internal Management subsystem in communication with said internal IP Host subsystem, said Management subsystem configured to create a blocklist responsive to said threat reports; and

an internal Firewall subsystem configured to redirect data packages emanating from said wide area computer network and destined for said local area computer network, said redirecting responsive to said blocklist.

2 . The system of claim 1 , wherein:

each said firewall device further comprises an internal Analysis subsystem in communication with said Firewall subsystem and said Management subsystem, said Analysis subsystem configured to record data related to said redirected data packages and periodically generate activity reports, said activity reports transmitted to said Management subsystem; and

said Management subsystem is further configured to transmit said activity reports to said central threat server computing device.

3 . The system of claim 2 , wherein said central threat server computing device is configured to generate a said threat report responsive to an activity report received from said first firewall device and to further transmit said threat report to said second firewall device.

4 . The system of claim 3 , wherein said central threat server computing device is further configured to generate a said threat report responsive to an activity report received from said second firewall device and to further transmit said threat report to said first firewall device.

5 . The system of claim 4 , wherein said firewall devices further comprise an internal Isolation server computing device configured to store some or all of said redirected data packages.

6 . The system of claim 5 , wherein said internal Firewall systems of said firewall devices is further configured to redirect data packages emanating from said local area computer network and destined for said wide area computer network, said redirecting responsive to said blocklist.

7 . The system of claim 6 , wherein said Management modules of said firewall devices are further configured to receive said threat reports from a direct connection to a data storage device.

8 . A method for redirecting data packages transmitted between a wide area computer network and a local area computer network, comprising the steps of:

installing a firewall device between said wide area computer network and said local area computer network, said firewall device configured to redirect data packages arriving at said firewall device addressed for a location within said local area computer network, said redirecting responsive to an internal blocklist;

installing a central server computing device in communication with said wide area computing network;

sending a threat report from said central server computing device to said firewall device; and

revising said internal blocklist within said firewall device responsive to said received threat report.

9 . The method of claim 8 , further comprising the steps of:

generating an activity report within said firewall device responsive to said redirectings;

transmitting said activity report from said firewall device to said central server computing device; and

sending another said threat report responsive to said received activity report.

10 . The method of claim 9 , wherein said redirecting comprises redirecting said arriving packages to an internal Isolation server computing device in communication with said local area computer network, said Isolation server computing configured to store some or all of said redirected data packages.

11 . The method of claim 10 , further comprising the step of installing a second said firewall device between said wide area computer network and a second said local area computer network, said firewall device configured to redirect data packages arriving at said second firewall device addressed for a location within said second local area computer network, said redirecting responsive to a second said internal blocklist;

sending a threat report from said central server computing device to said second firewall device; and

revising said second internal blocklist within said second firewall device responsive to said received threat report.

12 . The method of claim 11 , wherein said revising of said second internal blocklist is responsive to an activity report transmitted by said first firewall device.

13 . A distributed firewall system, comprising:

a central threat server computing device in communication with a wide area computer network;

a plurality of firewall devices, with each said firewall device in communication with said wide area computer network on an external side and a local area computer network on an internal side; and

wherein each said firewall device comprises:

an internal IP Host subsystem in communication with said central threat server computing device via said wide area computer network to receive threat reports from said central threat server computing device;

an internal Management subsystem in communication with said internal IP Host subsystem, said Management subsystem configured to create a blocklist responsive to said threat reports; and

an internal Firewall subsystem configured to redirect data packages emanating from said wide area computer network and destined for a computing device in communication with said local area computer network, said redirecting responsive to said blocklist.

14 . The system of claim 13 , wherein:

each said firewall device further comprises an internal Analysis subsystem in communication with said Firewall subsystem and said Management subsystem, said Analysis subsystem configured to record data related to said redirected data packages and periodically generate activity reports, said activity reports transmitted to said Management subsystem; and

said Management subsystem is further configured to transmit said activity reports to said central threat server computing device.

15 . The system of claim 14 , wherein said central threat server computing device is configured to generate a said threat report responsive to an activity report received from said first firewall device and to further transmit said threat report to said second firewall device.

16 . The system of claim 15 , wherein said central threat server computing device is further configured to generate a said threat report responsive to an activity report received from one said firewall device and to further transmit said threat report to another said firewall device.

17 . The system of claim 16 , wherein said firewall devices further comprise an internal Isolation server computing device configured to store some or all of said redirected data packages.

18 . The system of claim 17 , wherein said internal Firewall systems of said firewall devices is further configured to redirect data packages emanating from said local area computer network and destined for said wide area computer network, said redirecting responsive to said blocklist.

19 . The system of claim 18 , wherein said Management modules of said firewall devices are further configured to receive said threat reports from a direct connection to a data storage device.

20 . The system of claim 13 , wherein said firewall devices further comprise an internal Isolation server computing device configured to store some or all of said redirected data packages.

Assignments (2)
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded May 17, 2023
From: SPECTRANETIX, INC.
To: PACIFIC DEFENSE STRATEGIES, INC.
Reel/Frame 063694/0902 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2014
From: BANFIELD, BRET
To: SPECTRANETIX, INC.
Reel/Frame 032577/0335 →