IP Library Granted Patent US 9,553,895
Granted Patent B2
US 9,553,895 · App. 14/472,256 · Granted Jan 24, 2017

System and method for building intelligent and distributed L2-L7 unified threat management infrastructure for IPv4 and IPv6 environments

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,553,895
App. No.
14/472,256
Granted
Jan 24, 2017
Kind
B2
Abstract

A security gateway appliance is configured to evaluate network traffic according to security rules that classify traffic flows according to specifically identified application programs responsible for producing and/or consuming the network traffic and to enforce policies in accordance with network traffic classifications. The appliance includes an on-box anti-virus/anti-malware engine, on-box data loss prevention engine and on-box authentication engine. One or more of these engines is informed by an on-box dynamic real tie rating system that allows for determined levels of scrutiny to be paid to the network traffic. Security gateways of this type can be clustered together to provide a set of resources for one or more networks, and in some instances as the backbone of a cloud-based service.

Claims (48)

1. A security gateway, comprising a memory and a computer processing unit communicatively coupled to the memory wherein the memory stores computer-executable instructions which, when executed by the processing unit, cause the processing unit to:

log, by the computer processing unit, user access histories associated with the security gateway;

analyze, by the computer processing unit, the logged user access histories;

determine, by the computer processing unit, a level of data loss scrutiny according to the analysis of the logged user access histories;

apply, by the computer processing unit, the determined level of data loss prevention scrutiny to network traffic received at the security gateway;

evaluate, by the computer processing unit, network traffic according to a dynamic real time rating scheme that provides categorization of content represented in the network traffic, wherein the dynamic real time rating scheme is provided by a real time rating service that is external to the security gateway when the security gateway is unable to process the content;

update, dynamically by the computer processing unit, a firewall engine in accordance with a new traffic classification based on the evaluation of the network traffic;

determine, by the computer processing unit, a level of anti-virus, anti-malware scanning to the network traffic based on results of the dynamic real time rating; and

apply, by the computer processing unit, the determined level of anti-virus, anti-malware scanning to the network traffic.

2. The security gateway in claim 1 , wherein the instructions, when executed by the computer processing unit, communicate the dynamic real time rating to a second security gateway.

3. The security gateway in claim 1 , wherein the instructions, when executed by the computer processing unit:

discover a malicious attack; and

communicate information pertaining to the malicious attack to a second security gateway.

4. The security gateway in claim 1 , wherein the instructions, when executed by the computer processing unit, perform network acceleration by byte caching information with a second security gateway.

5. A method, comprising:

logging, by a computer processor, user access histories associated with a security gateway;

analyzing, by the computer processor, the logged user access histories;

determining, by the computer processor, a level of data loss scrutiny according to the analysis of the logged user access histories;

applying, by the computer processor, the determined level of data loss prevention scrutiny to network traffic received at the security gateway;

evaluating, by the computer processor, the network traffic according to a dynamic real time rating scheme that provides categorization of content represented in the network traffic, wherein the dynamic real time rating scheme is provided by a real time rating service that is external to the security gateway when the security gateway is unable to process the content;

updating, dynamically by the computer processor, a firewall engine in accordance with a new traffic classification based on the evaluation of the network traffic;

determining, by the computer processor, a level of anti-virus, anti-malware scanning to the network traffic based on results of the dynamic real time rating; and

applying the determined level of anti-virus, anti-malware scanning to the network traffic.

6. The method of claim 5 , further comprising communicating the dynamic real time rating to a second security gateway.

7. The method of claim 5 , further comprising:

discovering a malicious attack; and

communicating information pertaining to the malicious attack to a second security gateway.

8. The method of claim 5 , further comprising performing network acceleration by byte caching information with a second security gateway.

9. A security gateway, comprising a memory and a computer processing unit communicatively coupled to the memory wherein the memory stores computer-executable instructions which, when executed by the processing unit, cause the processing unit to:

log, by the computer processing unit, user access histories associated with the security gateway;

analyze, by the computer processing unit, the logged user access histories;

determine, by the computer processing unit, a level of data loss scrutiny according to the analysis of the logged user access histories;

apply, by the computer processing unit, the determined level of data loss prevention scrutiny to network traffic received at the security gateway;

evaluate, by the computer processing unit, the network traffic according to a dynamic real time rating scheme that provides categorization of content represented in the network traffic;

update, dynamically by the computer processing unit, a firewall engine in accordance with a new traffic classification based on the evaluation of the network traffic;

determine, by the computer processing unit, a level of anti-virus, anti-malware scanning to the network traffic based on results of the dynamic real time rating;

apply the determined level of anti-virus, anti-malware scanning to the network traffic; and

perform network acceleration by byte caching the network traffic to a second security gateway.

10. A method, comprising:

logging, by a computer processor, user access histories associated with a security gateway;

analyzing, by the computer processor, the logged user access histories;

determining, by the computer processor, a level of data loss scrutiny according to the analysis of the logged user access histories;

applying, by the computer processor, the determined level of data loss prevention scrutiny to network traffic received at the security gateway;

evaluating, by the computer processor, the network traffic according to a dynamic real time rating scheme that provides categorization of content represented in the network traffic;

updating, dynamically by the computer processor, a firewall engine in accordance with a new traffic classification based on the evaluation of the network traffic;

determining, by the computer processor, a level of anti-virus, anti-malware scanning to the network traffic based on results of the dynamic real time rating;

applying the determined level of anti-virus, anti-malware scanning to the network traffic; and

performing network acceleration by byte caching the network traffic to a second security gateway.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2016
From: LI, QING; FREDERICK, RONALD ANDREW; CLARE, THOMAS A.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 038997/0923 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 34010/0009 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0385 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 34009/0946 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0921 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SUPPLEMENTAL SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 16, 2014
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 034010/0009 →
SUPPLEMENTAL FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 16, 2014
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 034009/0946 →