IP Library Granted Patent US 11,212,259
Granted Patent B2
US 11,212,259 · App. 15/892,581 · Granted Dec 28, 2021

Inspection offload clustering

Inventors: Mika Lansirinne (Helsinki, FI); Valtteri Rahkonen (Helsinki, FI); Pekka Riikonen (Helsinki, FI)
Assignee: Forcepoint LLC
H04L63/0245H04L63/0263G06F2209/509
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,212,259
App. No.
15/892,581
Granted
Dec 28, 2021
Kind
B2
Abstract

A method, system, and computer-usable medium are disclosed for performing packet processing of network traffic on a master security device of a plurality of security devices, such packet processing including connection tracking for the network traffic, and offloading packet inspection of the network traffic to one or more slave security devices of the plurality of security devices.

Claims (35)

1. A method for managing network communication, comprising:

performing packet processing of network traffic on a master security device of a plurality of security devices, such packet processing including connection tracking for the network traffic; and

offloading packet inspection of the network traffic to one or more slave security devices of the plurality of security devices, wherein the connection tracking is performed only by the master security device, without synchronization of connection data to the one or more slave security devices;

wherein the master security device and the one or more slave security devices are so designated from the plurality of security devices based on a rules-based determination.

2. The method of claim 1 , wherein offloading packet inspection comprises:

dispatching packets of network traffic to the one or more slave security devices for inspection; and

receiving, responsive to the dispatching, one or more security decisions rendered by the one or more slave security devices responsive to the inspection.

3. The method of claim 2 , wherein offloading packet inspection further comprises determining a slave security device from a plurality of slave security devices to dispatch an inspection.

4. The method of claim 2 , further comprising managing communication of network traffic based on the security decision.

5. The method of claim 1 , wherein the master security device and the one or more slave security devices are so designated from the plurality of security devices by an administrator of the plurality of security devices.

6. The method of claim 1 , wherein the master security device is one master security device among a plurality of master security devices within the plurality of security devices.

7. A system comprising:

a processor; and

a non-transitory, computer-readable storage medium embodying instructions executable by the processor for:

performing packet processing of network traffic on a master security device of a plurality of security devices, such packet processing including connection tracking for the network traffic; and

offloading packet inspection of the network traffic to one or more slave security devices of the plurality of security devices, wherein the connection tracking is performed only by the master security device, without synchronization of connection data to the one or more slave security devices;

wherein the master security device and the one or more slave security devices are so designated from the plurality of security devices based on a rules-based determination.

8. The system of claim 7 , wherein offloading packet inspection comprises:

dispatching packets of network traffic to the one or more slave security devices for inspection; and

receiving, responsive to the dispatching, one or more security decisions rendered by the one or more slave security devices responsive to the inspection.

9. The system of claim 8 , wherein offloading packet inspection further comprises determining a slave security device from a plurality of slave security devices to dispatch an inspection.

10. The system of claim 8 , the instructions for further managing communication of network traffic based on the security decision.

11. The system of claim 7 , wherein the master security device and the one or more slave security devices are so designated from the plurality of security devices by an administrator of the plurality of security devices.

12. The system of claim 7 , wherein the master security device is one master security device among a plurality of master security devices within the plurality of security devices.

13. A non-transitory, computer-readable storage medium embodying computer executable instructions configured for:

performing packet processing of network traffic on a master security device of a plurality of security devices, such packet processing including connection tracking for the network traffic; and

offloading packet inspection of the network traffic to one or more slave security devices of the plurality of security devices, wherein the connection tracking is performed only by the master security device, without synchronization of connection data to the one or more slave security devices;

wherein the master security device and the one or more slave security devices are so designated from the plurality of security devices based on a rules-based determination.

14. The storage medium of claim 13 , wherein offloading packet inspection comprises:

dispatching packets of network traffic to the one or more slave security devices for inspection; and

receiving, responsive to the dispatching, one or more security decisions rendered by the one or more slave security devices responsive to the inspection.

15. The storage medium of claim 14 , wherein offloading packet inspection further comprises determining a slave security device from a plurality of slave security devices to dispatch an inspection.

16. The storage medium of claim 14 , the instructions for further managing communication of network traffic based on the security decision.

17. The storage medium of claim 13 , wherein the master security device and the one or more slave security devices are so designated from the plurality of security devices by an administrator of the plurality of security devices.

18. The storage medium of claim 13 , wherein the master security device is one master security device among a plurality of master security devices within the plurality of security devices.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055492/0266 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 6, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 046495/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2018
From: LANSIRINNE, MIKA; RAHKONEN, VALTTERI; RIIKONEN, PEKKA
To: FORCEPOINT LLC
Reel/Frame 044879/0061 →
Continuity (1)
Related Publication 20190253391A1 · Aug 15, 2019