IP Library Granted Patent US 9,560,056
Granted Patent B2
US 9,560,056 · App. 14/926,566 · Granted Jan 31, 2017

Cloud-based gateway security scanning

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,560,056
App. No.
14/926,566
Granted
Jan 31, 2017
Kind
B2
Abstract

Some embodiments of cloud-based gateway security scanning have been presented. In one embodiment, some data packets are received sequentially at a gateway device. The data packets constitute at least a part of a file being addressed to a client machine coupled to the gateway device. The gateway device forwards an identification of the file to a remote datacenter in parallel with forwarding the data packets to the client machine. The datacenter performs signature matching on the identification and returns a result of the signature matching to the gateway device. The gateway device determining whether to block the file from the client machine based on the result of the signature matching from the datacenter.

Claims (34)

1. A system for security scanning, the system comprising:

memory used to store security-related information, wherein the stored security-related information includes signatures indicative of previously screened content;

a user interface that:

receives a request for a content file over a communication network from a user device, and

begins transmission of the requested content file to the user device, wherein less than all of the data packets associated with the requested content file has been transmitted to the user device; and

a processor that executes instructions to:

generate identification for the requested content file using the transmitted data packets associated with the requested content file, wherein the identification corresponds to the less than all of the data packets currently being transmitted, and wherein the identification is a partial hash,

perform security screening of the requested content file using the generated identification, wherein the security screening includes performing content rating of the requested content file based on the generated identification, and

determine a status for transmission of the requested content file to the user device based on the security screening and the stored security-related information.

2. The system of claim 1 , wherein the processor executes further instructions to block the requested content file based on the determined status.

3. The system of claim 2 , wherein the processor executes further instructions to discard remaining data packets associated with the requested content file and not yet transmitted so that transmission of the requested content file is not completed.

4. The system of claim 1 , wherein the processor determines the status for transmission by comparing the content rating of the requested content file with a list of non-allowed content.

5. The system of claim 4 , wherein the list of non-allowed content includes pornographic content or violent content.

6. The system of claim 4 , wherein the list of non-allowed content is based on a predetermined policy associated with the system.

7. The system of claim 1 , wherein the processor executes further instructions to allow the transmission to be completed based on the determined status.

8. The system of claim 1 , wherein the processor performs security screening of the requested content file by evaluating the requested content file for matching signatures associated with malware.

9. The system of claim 1 , wherein the security-related information stored in memory includes content ratings.

10. The system of claim 1 , wherein the security-related information stored in memory includes known signatures for malware.

11. The system of claim 1 , wherein the determined status indicates that the requested content file matches at least one signature of a previously screened content characterized as being malware, and wherein the processor executes further instructions to stop transmission of the content file before all the data packets are completely transmitted to the user device based on the determined status.

12. A method for security scanning, the method comprising:

storing security-related information in memory, wherein the stored security-related information includes signatures indicative of previously screened content;

receiving a request for a content file over a communication network from a user device;

beginning transmission of the requested content file, wherein less than all the data packets associated with the requested content file has been transmitted to the user device;

executing instructions stored in memory by a processor to:

generate identification for the requested content file using the transmitted data packets associated with the requested content file, wherein the identification corresponds to the less than all of the data packets currently being transmitted, and wherein the identification is a partial hash,

perform security screening of the requested content file using the generated identification, wherein the security screening includes performing content rating of the requested content file based on the generated identification, and

determine a status for transmission of the requested content file to a user device based on the security screening and the stored security-related information.

13. A non-transitory computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method for security scanning, the method comprising:

storing security-related information, wherein the stored security-related information includes signatures indicative of previously screened content;

receiving a request for a content file over a communication network from a user device;

beginning transmission of the requested content file to the user device, wherein less than all of the data packets associated with the requested content file has been transmitted to the user device;

generating identification for the requested content file using the transmitted data packets associated with the requested content file, wherein the identification corresponds to the less than all of the data packets currently being transmitted, and wherein the identification is a partial hash;

performing security screening of the requested content file using the generated identification, wherein the security screening includes performing content rating of the requested content file based on the generated identification; and

determining a status for transmission of the requested content file to the user device based on the security screening and the stored security-related information.

Assignments (14)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Apr 2, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045818/0566 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →