IP Library Granted Patent US 10,701,036
Granted Patent B2
US 10,701,036 · App. 15/193,220 · Granted Jun 30, 2020

System, method, and computer program for preventing infections from spreading in a network environment using dynamic application of a firewall policy

Inventors: Manabendra Paul (Bangalore, IN); Praveen Ravichandran Sudharma (Bangalore, IN)
Assignee: McAfee, LLC
H04L63/0263H04L63/0218H04L63/0236H04L63/145H04L63/1466H04L63/20H04L41/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,701,036
App. No.
15/193,220
Granted
Jun 30, 2020
Kind
B2
Abstract

A method for containing a threat in network environment using dynamic firewall policies is provided. In one example embodiment, the method can include detecting a threat originating from a first node having a source address in a network, applying a local firewall policy to block connections with the source address, and broadcasting an alert to a second node in the network. In more particular embodiments, an alert may be sent to a network administrator identifying the source address and providing remedial information. In yet other particular embodiments, the method may also include applying a remote firewall policy to the first node blocking outgoing connections from the first node.

Claims (33)

1. One or more non-transitory computer readable media comprising code for execution, wherein the code is executable by one or more processors to:

detect, by a first node in a network protected from unauthorized external access, a threat that is received at the first node from a source node in the network, the network including at least a plurality of nodes having respective security modules, and wherein the threat is at least one of a violation of a network policy or a violation of a system policy;

create, at the first node, a first firewall policy to block incoming network requests associated with a source address of the source node and outgoing network requests to the source address of the source node, in response to the first node detecting the threat;

block incoming network requests received at the first node from the source node by applying the first firewall policy at the first node;

broadcast an alert from the first node to the respective security modules of the plurality of nodes in the network, wherein the broadcast alert comprises the first firewall policy to be applied by the plurality of nodes;

determine, by the first node, whether the source node includes a firewall module; and communicate, from the first node to the source node, based at least in part on the determination that the source node includes the firewall module, a second firewall policy to be applied by the source node to block outgoing network requests from the source node to the plurality of nodes in the network and to block network requests received at the source node from other nodes.

2. The one or more non-transitory computer readable claim 1 , wherein the threat includes malware.

3. The one or more non-transitory computer readable claim 1 , wherein the code is executable by the one or more processors to further:

identify, by the first node, the source address of the source node.

4. The one or more non-transitory computer readable media of claim 1 , wherein the broadcast alert includes an identification of the source node.

5. A first node in a network protected from unauthorized external access, the first node comprising:

a hardware processor; and

a memory storing executable instructions that when executed by the processor cause the hardware processor to:

detect a threat that is received from a source node in the network, the network including at least a plurality of nodes having respective security modules, and wherein the threat is at least one of a violation of a network policy or a violation of a system policy;

create a first firewall policy to block incoming network requests associated with a source address of the source node and outgoing network requests to the source address of the source node, in response to the first node detecting the threat;

block incoming network requests received at the first node from the source node by applying the first firewall policy at the first node; and

broadcast an alert to the respective security modules of the plurality of nodes in the network, wherein the broadcast alert comprises the first firewall policy to be applied by the plurality of nodes;

determine, by the first node, whether the source node includes a firewall module; and

communicate, from the first node to the source node, based at least in part on the determination that the source node includes the firewall module, a second firewall policy to the source node to be applied by the source node to block outgoing network requests from the source node to the plurality of nodes in the network and to block network requests received at the source node from other nodes.

6. The first node of claim 5 , wherein the threat includes malware.

7. A method, comprising:

detecting, by a first node in a network protected from unauthorized external access, a threat that is received from a source node in the network, the network including at least a plurality of nodes having respective security modules, and wherein the threat is at least one of a violation of a network policy or a violation of a system policy;

creating, at the first node, a first firewall policy to block incoming network requests associated with a source address of the source node and outgoing network requests to the source address of the source node, in response to the first node detecting the threat;

blocking incoming network requests received at the first node from the source node by applying the first firewall policy at the first node;

broadcasting an alert from the first node to the respective security modules of the plurality of nodes in the network, wherein the broadcast alert comprises the first firewall policy to be applied by the plurality of nodes;

determining, by the first node, whether the source node includes a firewall module; and communicating, from the first node to the source node, based at least in part on the determination that the source node includes the firewall module, a second firewall policy to be applied by the source node to block outgoing network requests from the source node to the plurality of nodes in the network and to block network requests received at the source node from other nodes.

8. The method of claim 7 , wherein the threat includes malware.

9. One or more non-transitory computer readable media comprising code for execution, wherein the code is executable by one or more processors to:

create, at a first node in a network, a first firewall policy to block incoming network requests associated with a source address of a source node in the network, wherein the network is protected from unauthorized external access, in response to the first node detecting a threat that is received at the first node from the source node, and wherein the threat is at least one of a violation of a network policy or a violation of a system policy;

block incoming network requests received at the first node from the source node and outgoing network requests to the source address of the source node by applying the first firewall policy at the first node;

broadcast an alert from the first node to respective security modules of a plurality of nodes in the network, the broadcast based, at least in part, on the threat received at the first node from the source node being detected by the first node, wherein the broadcast alert comprises the first firewall policy to be applied by the plurality of nodes to block incoming network requests associated with a source address of the source node, wherein the first node is a target of the received threat;

determine, by the first node, whether the source node includes a firewall module; and communicate, from the first node to the source node, based at least in part on the determination that the source node includes the firewall module, a second firewall policy to be applied by the source node to block outgoing network requests from the source node to the plurality of nodes in the network and to block network requests received at the source node from other nodes.

10. The one or more non-transitory computer readable claim 9 , wherein the threat includes malware.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
Continuity (3)
Continuation 14528155 · Oct 30, 2014
Continuation 13216516 · Aug 24, 2011
Related Publication 20170034128A1 · Feb 2, 2017