IP Library Granted Patent US 9,973,472
Granted Patent B2
US 9,973,472 · App. 14/677,827 · Granted May 15, 2018

Methods and systems for orchestrating physical and virtual switches to enforce security boundaries

Inventors: Marc Woolward (Bude, GB); Choung-Yaw Shieh (Palo Alto, CA)
Assignee: vArmour Networks, Inc.
H04L63/0236H04L63/0263H04L63/1491H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,973,472
App. No.
14/677,827
Granted
May 15, 2018
Kind
B2
Abstract

Some embodiments include methods comprising: writing entries in a forwarding table of a switch through an application programming interface (API) of the switch, such that first data packets from a first host and directed to a second host are forwarded by the switch to an enforcement point; receiving the first data packets; forwarding the first data packets to the enforcement point using the forwarding table; determining whether the first data packets violate a high-level security policy using a low-level rule set; configuring the forwarding table through the API such that second data packets are forwarded by the switch to the second host, in response to determining the first data packets do not violate the security policy; configuring the forwarding table through the API such that the second data packets are dropped or forwarded to a security function by the switch, in response to the determining.

Claims (22)

1. A method comprising:

writing, by a policy engine, entries in a forwarding table of a switch through an application programming interface (API) of the switch, such that first data packets from a first host and directed to a second host are forwarded by the switch to an enforcement point;

receiving, by the switch, the first data packets;

forwarding, by the switch, the first data packets to the enforcement point using the forwarding table;

determining, by the enforcement point, whether the first data packets violate a high-level security policy using a low-level rule set;

configuring, by the enforcement point, the forwarding table through the API such that second data packets are forwarded by the switch to the second host, in response to determining the first data packets do not violate the security policy;

configuring, by the enforcement point, the forwarding table through the API such that the second data packets are dropped or forwarded to a security function by the switch, in response to determining the first data packets violate the security policy;

receiving, by the switch, the second data packets; and

selectively dropping or forwarding the second data packets, by the switch, in accordance with the configuration.

2. The method of claim 1 further comprising:

receiving, by the enforcement point, a re-compiled rule set from a distributed security processor;

receiving, by the enforcement point, a third data packet;

identifying, by the enforcement point, a trigger in the third data packet, the trigger being at least one of a: received Transmission Control Protocol (TCP) header, flag, and timer-based trigger; and

writing, by the enforcement point, entries in the forwarding table through the API, such that fourth data packets from the first host and directed to the second host are forwarded by the switch to the enforcement point, in response to identifying the trigger.

3. The method of claim 2 further comprising:

receiving, by the switch, the fourth data packets;

forwarding, by the switch, the fourth data packets to the enforcement point using the forwarding table; and

determining, by the enforcement point, whether the fourth data packets violate the re-compiled rule set or pre-configured protocol behavior requirements.

4. The method of claim 1 wherein at least one of the writing and the configuring of the forwarding table is performed using a software development kit (SDK).

5. The method of claim 1 wherein the security function is at least one of a: honeypot, tarpit, and intrusion detection system.

6. The method of claim 1 wherein at least one of the first host and the second host are a physical host and the switch is a physical switch.

7. The method of claim 1 wherein at least one of the first host and the second host are a virtual machine and the switch is a virtual switch.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Jul 18, 2025
From: GRYPHO5, LLC
To: EVP CREDIT SPV I LP
Reel/Frame 072053/0141 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: VARMOUR NETWORKS, INC.
To: GRYPHO5, LLC
Reel/Frame 070287/0007 →
SECURITY INTEREST Recorded Feb 22, 2024
From: VARMOUR NETWORKS, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 066530/0399 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2018
From: SHIEH, CHOUNG-YAW
To: VARMOUR NETWORKS, INC.
Reel/Frame 045436/0066 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR CHOUNG-YAW SHIEH'S NAME PREVIOUSLY RECORDED ON REEL 035550 FRAME 0953. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNORS' INTEREST. Recorded Sep 30, 2016
From: SHIEH, CHOUNG-YAW; WOOLWARD, MARC
To: VARMOUR NETWORKS, INC.
Reel/Frame 040192/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2015
From: SHIEH, CHOUNG-YAW MICHAEL; WOOLWARD, MARC
To: VARMOUR NETWORKS, INC.
Reel/Frame 035550/0953 →
Continuity (1)
Related Publication 20160294774A1 · Oct 6, 2016