IP Library Granted Patent US 10,326,781
Granted Patent B2
US 10,326,781 · App. 15/416,959 · Granted Jun 18, 2019

Cloud-based gateway security scanning

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,326,781
App. No.
15/416,959
Granted
Jun 18, 2019
Kind
B2
Abstract

Some embodiments of cloud-based gateway security scanning have been presented. In one embodiment, some data packets are received sequentially at a gateway device. The data packets constitute at least a part of a file being addressed to a client machine coupled to the gateway device. The gateway device forwards an identification of the file to a remote datacenter in parallel with forwarding the data packets to the client machine. The datacenter performs signature matching on the identification and returns a result of the signature matching to the gateway device. The gateway device determining whether to block the file from the client machine based on the result of the signature matching from the datacenter.

Claims (33)

1. An apparatus for scanning received data, the apparatus comprising:

a computer network interface that receives at least a portion of a set of data packets from a computing device in an external network; and

a processor that executes instructions out of memory, wherein execution of instructions by the processor:

generates an identifier from a portion of a set of data packets, wherein the generated identifier regarding the received portion of the data set is sent to a data center device that performs pattern matching based on comparing the generated identifier to a plurality of patterns stored in a memory of the data center device, and returns an indication identifying that the generated identifier does not match any of the plurality of stored patterns,

allows the set of data packets to be transmitted to a destination computing device based on the indication from the data center device identifying that the generated identifier does not match any of the plurality of stored patterns,

generates an additional identifier using at least a portion of data requested in a request received from a client device, wherein the data center device returns an indication that the additional identifier is associated with a policy of a plurality of policies, and

blocks the data related to the client request based on the policy of the plurality of policies associated with the additional identifier as indicated by the indication from the data center device.

2. The apparatus of claim 1 , wherein the identifier is generated from a file associated with the set of data.

3. The apparatus of claim 2 , wherein the file corresponds to a predetermined file type.

4. The apparatus of claim 3 , wherein the predetermined type of file is an executable file type that is associated with a software application program.

5. The apparatus of claim 1 , wherein the policy of the plurality of policies are associated with at least one prohibited category that is associated with at least one of pornography, violence, or a social networking site.

6. The apparatus of claim 1 , wherein the policy of the plurality of policies are associated with at least one prohibited category that is associated with malware.

7. A method for scanning received data, the method comprising:

generating an identifier from a received portion of a set of data packets received from a computing device in an external network;

sending the generated identifier to a data center device that returns an indication based on comparing the generated identifier to a plurality of patterns stored in a memory, the indication identifying that the generated identifier does not match any of the plurality of stored patterns;

transmitting the set of data packets to a destination computing device based on the indication from the data center device identifying that the generated identifier does not match any of the plurality of stored patterns;

generating an additional identifier using at least a portion of data requested in a request received from a client device, wherein the data center device returns an indication that the additional identifier is associated with a policy of a plurality of policies; and

blocking the data related to the client request based on the policy of the plurality of policies associated with the additional identifier as indicated by the indication from the data center device.

8. The method of claim 7 , wherein the identifier is generated from a file associated with the set of data.

9. The method of claim 8 , wherein the file corresponds to a predetermined file type.

10. The method of claim 9 , wherein the predetermined type of file is an executable file type that is associated with a software application program.

11. The method of claim 7 , wherein the policy of the plurality of policies are associated with at least one prohibited category that is associated with at least one of pornography, violence, or a social networking site.

12. The method of claim 7 , wherein the policy of the plurality of policies are associated with at least one prohibited category that is associated with malware.

13. A non-transitory computer-readable storage medium having embodied thereon a program that when executed by a processor performs a method for scanning received data, the method comprising:

generating an identifier from a received portion of a set of data packets received from a computing device in an external network;

sending the generated identifier to a data center device that performs pattern matching based on comparing the generated identifier to the plurality of patterns stored in a memory and returns an indication identifying that the generated identifier does not match any of the plurality of stored patterns;

transmitting the set of data packets to a destination computing device based on the indication from the data center device identifying that the generated identifier does not match any of the plurality of stored patterns;

generating an additional identifier using at least a portion of data requested in a request received from a client device, wherein the data center device returns an indication that the additional identifier is associated with a policy of a plurality of policies; and

blocking the data related to the client request based on the policy of the plurality of policies associated with the additional identifier as indicated by the indication from the data center device.

14. The non-transitory computer: readable storage medium of claim 13 , wherein the identifier is generated from a file associated with the set of data.

15. The non-transitory computer: readable storage medium of claim 14 , wherein the file corresponds to a predetermined file type.

16. The non-transitory computer: readable storage medium of claim 15 , wherein the predetermined type of file is an executable file type that is associated with a software application program.

17. The non-transitory computer-readable storage medium of claim 13 , wherein the policy of the plurality of policies are associated with at least one prohibited category that is associated with at least one of pornography, violence, a social networking site, and malware.

Assignments (11)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2018
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 045983/0001 →
CHANGE OF NAME Recorded Apr 2, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045818/0566 →
CONVERSION AND NAME CHANGE Recorded Feb 8, 2017
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 041663/0176 →
MERGER Recorded Feb 8, 2017
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 041205/0571 →
CHANGE OF NAME Recorded Feb 8, 2017
From: PSM MERGER SUB (DELAWARE), INC. C/O THOMA BRAVO, LLC
To: SONICWALL, INC.
Reel/Frame 041205/0032 →
MERGER Recorded Feb 8, 2017
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC. C/O THOMA BRAVO, LLC
Reel/Frame 041204/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2017
From: DUBROVSKY, ALEKSANDR; CHEETANCHERI, SENTHILKUMAR G.; YANOVSKY, BORIS
To: SONICWALL, INC.
Reel/Frame 041204/0363 →