IP Library Granted Patent US 10,574,482
Granted Patent B2
US 10,574,482 · App. 15/563,261 · Granted Feb 25, 2020

Multi-perimeter firewall in the cloud

Inventors: Carlos Eduardo Oré (Saint-Herblain, FR); Joseph E. Rubenstein (Beijing, CN)
Assignee: UMBRA TECHNOLOGIES LTD.
H04L12/465H04L12/4633H04L45/22H04L45/28H04L45/302H04L45/64H04L63/02H04L63/0218H04L63/0236H04L63/0254H04L63/0263H04L63/0272H04L12/4641
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,574,482
App. No.
15/563,261
Filed
Sep 29, 2017
Granted
Feb 25, 2020
Kind
B2
Art Unit
2438
USPC
726/11
Abstract

Systems and methods for providing multi-perimeter firewalls via a virtual global network are disclosed. In one embodiment the network system may comprise an egress ingress point in communication with a first access point server, a second access point server in communication with the first access point server, an endpoint device in communication with the second access point server, a first firewall in communication with the first access point server, and a second firewall in communication with the second access point server. The first and second firewalls may prevent traffic from passing through their respective access point servers. The first and second may be in communication with each other and exchange threat information.

Claims (42)

1. A multi-perimeter firewall system located in a cloud and forming part of a global virtual network, comprising:

an egress ingress point device;

a first access point server in communication with the egress ingress point device;

a second access point server in communication with the first access point sever;

an endpoint device in communication with the second access point server;

a first perimeter firewall in communication with the first access point server, wherein the first perimeter firewall performs stateful packet inspection to prevent at least some traffic from passing from the first access point server to the second access point server; and

a second perimeter firewall in communication with the second access point server, wherein the second perimeter firewall performs deep packet inspection to prevent at least some traffic from passing from the second access point server to the end point device,

wherein at least one of the egress ingress point device, the first access point server, the second access point server, the endpoint device, the first perimeter firewall, or the second perimeter firewall comprises hardware,

wherein the deep packet inspection is performed on a cloned copy of traffic that flows through the second perimeter firewall.

2. The multi-perimeter firewall system according to claim 1 , wherein at least one of the access point servers is configured to perform firewall services.

3. The multi-perimeter firewall system according to claim 1 , wherein the first perimeter firewall is in communication with the second perimeter firewall through a communication path.

4. The multi-perimeter firewall system according to claim 3 , wherein the communication path between the first perimeter firewall and the second perimeter firewall is a network path.

5. The multi-perimeter firewall system according to claim 3 , wherein the communication path between the first perimeter firewall and the second perimeter firewall is a network back channel.

6. The multi-perimeter firewall system according to claim 3 , wherein the first perimeter firewall and the second perimeter firewall share threat information including at least one of heuristic patterns, signatures of known threats, known malicious source IP addresses, or attack vectors.

7. The multi-perimeter firewall system according to claim 6 , wherein the first perimeter firewall and the second perimeter firewall share threat information with a central control server.

8. The multi-perimeter firewall system according to claim 1 , wherein the deep packet inspection is performed on flow through traffic.

9. The multi-perimeter firewall system according to claim 1 , wherein at least one of the firewalls includes a cloud firewall load balancer and wherein the cloud firewall load balancer can allocate cloud firewall resources on demand.

10. The multi-perimeter firewall system according to claim 1 , wherein the egress ingress point device receives traffic directly from the Internet.

11. The multi-perimeter firewall system according to claim 1 , wherein the first perimeter firewall is coupled to a multi-honed backbone.

12. The multi-perimeter firewall system according to claim 1 , wherein the at least some traffic prevented from passing from the first access point server to the second access point server includes traffic with recognized malicious headers.

13. A multi-perimeter firewall system located in a cloud and forming part of a global virtual network, comprising:

an egress ingress point device;

a first access point server in communication with the egress ingress point device;

a second access point server in communication with the first access point sever;

an endpoint device in communication with the second access point server;

a first perimeter firewall in communication with the first access point server, wherein the first perimeter firewall performs stateful packet inspection to prevent at least some traffic from passing from the first access point server to the second access point server using a first firewall mechanism; and

a second perimeter firewall in communication with the second access point server, wherein the second perimeter firewall performs deep packet inspection to prevent at least some traffic from passing from the second access point server to the end point device using a second, different firewall mechanism,

wherein at least one of the egress ingress point device, the first access point server, the second access point server, the endpoint device, the first perimeter firewall, or the second perimeter firewall comprises hardware,

wherein the deep packet inspection is performed on a cloned copy of traffic that flows through the second perimeter firewall.

14. The multi-perimeter firewall system according to claim 13 , wherein at least one of the access point servers is configured to perform firewall services.

15. The multi-perimeter firewall system according to claim 13 , wherein the first perimeter firewall is in communication with the second perimeter firewall through a communication path.

16. The multi-perimeter firewall system according to claim 15 , wherein the communication path between the first perimeter firewall and the second perimeter firewall is a network path.

17. The multi-perimeter firewall system according to claim 15 , wherein the communication path between the first perimeter firewall and the second perimeter firewall is a network back channel.

18. The multi-perimeter firewall system according to claim 15 , wherein the first perimeter firewall and the second perimeter_firerewall share threat information including at least one of heuristic patterns, signatures of known threats, known malicious source IP addresses, or attack vectors.

19. The multi-perimeter firewall system according to claim 18 , wherein the first perimeter firewall and the second perimeter firewall share threat information with a central control server.

20. The multi-perimeter firewall system according to claim 13 , wherein the deep packet inspection is performed on flow through traffic.

21. The multi-perimeter firewall system according to claim 13 , wherein at least one of the firewalls includes a cloud firewall load balancer and wherein the cloud firewall load balancer can allocate cloud firewall resources on demand.

22. The multi-perimeter firewall system according to claim 13 , wherein the second perimeter firewall is between the endpoint device and the second access point server.

23. The multi-perimeter firewall system according to claim 13 , wherein the first perimeter firewall is between the first access point server and the second access point server.

24. The multi-perimeter firewall system according to claim 13 , wherein the egress ingress point device receives traffic directly from the Internet.

25. The multi-perimeter firewall system according to claim 13 , wherein the first perimeter firewall is coupled to a multi-honed backbone.

26. The multi-perimeter firewall system according to claim 13 , wherein the at least some traffic prevented from passing from the first access point server to the second access point server includes traffic with recognized malicious headers.

Assignments (2)
LICENSE Recorded Oct 20, 2023
From: UMBRA TECHNOLOGIES LTD. (UK)
To: UMBRA TECHNOLOGIES (US) INC.
Reel/Frame 065292/0231 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2018
From: RUBENSTEIN, JOSEPH E.; ORE, CARLOS EDUARDO
To: UMBRA TECHNOLOGIES LTD.
Reel/Frame 044667/0013 →
Cited By (40)
US 12,218,800 US 12,218,845 US 12,229,088 US 12,237,990 US 12,250,114 US 12,261,777 US 12,271,348 US 12,289,183 US 12,309,001 US 12,316,524 US 12,316,554 US 12,335,131 US 12,335,329 US 12,341,706 US 12,355,655 US 12,368,676 US 12,375,403 US 12,401,544 US 12,425,332 US 12,425,335 US 12,425,347 US 12,425,395 US 12,450,201 US 12,483,968 US 12,489,672 US 12,506,678 US 12,507,120 US 12,507,148 US 12,507,153 US 12,526,183 US 12,549,465 US 12,563,438 US 12,568,039 US 12,587,468 US 12,603,827 US 12,603,848 US 12,632,330 US 12,652,217 US 12,659,719 US 12,719,782