IP Library Granted Patent US 10,103,892
Granted Patent B2
US 10,103,892 · App. 15/400,311 · Granted Oct 16, 2018

System and method for an endpoint hardware assisted network firewall in a security environment

Inventors: Steve Grobman (El Dorado Hills, CA); Raj Samani (Stoke Poges, GB); Ofir Arkin (Petach Tikva, IL); Sven Schrecker (San Marcos, CA)
Assignee: McAfee, LLC
H04L9/3247H04L9/14H04L9/30H04L45/74H04L63/0227H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,103,892
App. No.
15/400,311
Granted
Oct 16, 2018
Kind
B2
Abstract

A method is provided in one example embodiment and includes receiving a traffic flow at a tamper resistant environment from an application, where the tamper resistant environment is separated from a host operating system. The method also includes applying a security token to the traffic flow and sending the traffic flow to a server. In specific embodiments, a security module may add information about the application to traffic flow. A trapping module may monitor for a memory condition and identify the memory condition. The trapping module may also, responsive to identifying the memory condition, initiate a virtual environment for the application, and check the integrity of the traffic flow.

Claims (86)

1. At least one non-transitory computer-readable medium that includes code for execution and when executed by at least one processor is operable to perform operations to:

receive a traffic flow at a tamper resistant environment on a host from an application executing on the host, wherein the tamper resistant environment is separated from an operating system of the host by (a) running on a chipset that does not include a processor running the operating system of the host, or (b) running on a dedicated virtual machine within a virtualization environment on the host;

monitor, by a virtualization environment on the host, a memory of the host;

identify a memory condition;

request control of the memory;

obtain information associated with the application by accessing the memory;

send the information associated with the application from the virtualization environment to the tamper resistant environment;

receive information associated with the application at the tamper resistant environment from the virtualization environment on the host;

create a modified traffic flow by adding the information associated with the application to the received traffic flow and by adding a device identifier of the host to the received traffic flow; and

send the modified traffic flow to a server.

2. The at least one non-transitory computer-readable medium of claim 1 , wherein the memory condition is identified based on a certain memory location in the memory of the host being accessed.

3. The at least one non-transitory computer-readable medium of claim 1 , wherein the virtualization environment includes a second tamper resistant environment separated from the other tamper resistant environment.

4. At least one non-transitory computer-readable medium that includes code for execution and when executed by at least one processor, is operable to perform operations to:

receive a traffic flow at a tamper resistant environment on a host from an application executing on the host, wherein the tamper resistant environment is separated from an operating system of the host by (a) running on a chipset that does not include a processor running the operating system of the host, or (b) running on a dedicated virtual machine within a virtualization environment on the host;

derive a security token by the tamper resistant environment, wherein the security token is derived from an enhanced privacy identification to attest that the tamper resistant environment is trusted;

create a modified traffic flow by adding information associated with the application to the received traffic flow, adding a device identifier of the host, and applying the security token to the traffic flow; and

send the modified traffic flow to a server.

5. At least one non-transitory computer-readable medium that includes code for execution and when executed by at least one processor is operable to perform operations to:

receive a traffic flow at a tamper resistant environment on a host from an application executing on the host, wherein the tamper resistant environment is separated from an operating system of the host by (a) running on a chipset that does not include a processor running the operating system of the host, or (b) running on a dedicated virtual machine within a virtualization environment on the host;

derive a security token by the tamper resistant environment;

create a modified traffic by:

adding information, including metadata, associated with the application to the received traffic flow;

adding a device identifier of the host;

applying the security token to the received traffic flow; and

digitally signing the metadata using public key cryptography; and

send the modified traffic flow to a server.

6. At least one non-transitory computer-readable medium that includes code for execution and when executed by at least one processor is operable to perform operations to:

receive a traffic flow at a tamper resistant environment on a host from an application executing on the host, wherein the tamper resistant environment is separated from an operating system of the host by (a) running on a chipset that does not include a processor running the operating system of the host, or (b) running on a dedicated virtual machine within a virtualization environment on the host;

create a modified traffic flow by adding information associated with the application to the received traffic flow and by adding a device identifier of the host to the received traffic flow;

send the modified traffic flow to a server;

monitor a memory of the host for a memory condition;

identify the memory condition;

assign the application to a virtual machine in the virtualization environment based, at least in part, on identifying the memory condition;

trap, in the virtualization environment, process events associated with the traffic flow; and

check the integrity of the traffic flow before the traffic flow is delivered to the tamper resistant environment.

7. The at least one non-transitory computer-readable medium of claim 6 , wherein the code for monitoring for the memory condition, when executed by the at least one processor, is operable to perform further operations to:

monitor regions of the memory associated with buffers used to send data for the memory condition.

8. The at least one non-transitory computer-readable medium of claim 6 , wherein the code, when executed by the at least one processor, is operable to perform further operations to:

initiate the virtualization environment for the application by assigning the application to the virtual machine randomly based, at least in part, on identifying the memory condition.

9. The at least one non-transitory computer-readable medium of claim 6 , wherein the code, when executed by the processor, is operable to perform further operations to:

fire a virtualization trap based on a condition being asserted according to a configured probabilistic configuration.

10. An apparatus comprising:

at least one processor:

a security engine including a tamper resistant environment coupled to the at least one processor to:

receive a traffic flow from an application executing on the apparatus, wherein the tamper resistant environment is separated from an operating system of the apparatus by (a) running on a chipset that does not include a processor running the operating system of the host, or (b) running on a dedicated virtual machine within a virtualization environment on the host;

create a modified traffic flow by adding information associated with the application to the received traffic flow and by adding a device identifier of the apparatus to the received traffic flow; and

send the modified traffic flow to a server; and

a virtualization environment coupled to the processor to:

monitor a memory of the host;

identify a memory condition;

request control of the memory based on identifying the memory condition;

obtain the information associated with the application by accessing the memory; and

send the information to the tamper resistant environment.

11. An apparatus, comprising:

at least one processor; and

a security engine including a tamper resistant environment coupled to the at least one processor to:

receive a traffic flow from an application executing on the apparatus, wherein the tamper resistant environment is separated from an operating system of the apparatus by (a) running on a chipset that does not include a processor running the operating system of the host, or (b) running on a dedicated virtual machine within a virtualization environment on the host;

derive a security token;

create a modified traffic flow by:

adding information, including metadata, associated with the application to the received traffic flow;

adding a device identifier of the apparatus to the received traffic flow;

applying the security token to the traffic flow; and

digitally singing the metadata using public key cryptography; and

send the modified traffic flow to a server.

12. An apparatus, comprising:

at least one processor; and

a security engine including a tamper resistant environment coupled to the at least one processor to:

receive a traffic flow from an application executing on the apparatus, wherein the tamper resistant environment is separated from an operating system of the apparatus by (a) running on a chipset that does not include a processor running the operating system of the host, or (b) running on a dedicated virtual machine within a virtualization environment on the host;

create a modified traffic flow by adding information associated with the application to the received traffic flow and by adding a device identifier of the apparatus to the received traffic flow; and

send the modified traffic flow to a server; and

a trapping module configured to:

monitor a memory of the host for a memory condition;

identify the memory condition;

assign the application to a virtual machine in the virtualization environment based, at least in part, on identifying the memory condition;

trap, in the virtual environment, process events associated with the traffic flow; and

check the integrity of the traffic flow before the traffic flow is delivered to the tamper resistant environment.

13. A method comprising:

receiving a traffic flow at a tamper resistant environment on a host from an application executing on the host, wherein the tamper resistant environment is separated from an operating system of the host by (a) running on a chipset that does not include a processor running the operating system of the host, or (b) running on a dedicated virtual machine within a virtualization environment on the host;

monitoring, by a virtualization environment on the host, a memory of the host;

identifying a memory condition;

requesting control of the memory;

obtaining information associated with the application by accessing the memory;

sending the information from the virtualization environment to the tamper resistant environment;

receiving information associated with the application at the tamper resistant environment from the virtualization environment on the host;

creating a modified traffic flow by adding the information associated with the application to the received traffic flow and by adding a device identifier of the host to the received traffic flow; and

sending the modified traffic flow from the tamper resistant environment to a server.

Assignments (20)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
Continuity (2)
Continuation 13748578 · Jan 23, 2013
Related Publication 20170126413A1 · May 4, 2017
Cited By (2)
US 12,457,196 US 12,481,752