IP Library Granted Patent US 11,722,521
Granted Patent B2
US 11,722,521 · App. 17/667,111 · Granted Aug 8, 2023

Application firewall

Inventors: Andrew J. Thomas (Oxfordshire, GB); Karl Ackerman (Topsfield, MA); James Douglas Bean (Portland, OR); Kenneth D. Ray (Seattle, WA); Daniel Stutz (Karlsruhe, DE)
Assignee: Sophos Limited
H04L63/1483G06F11/00G06F21/40G06F21/43G06F21/44G06F21/45G06F21/554G06F21/566G06F21/57G06F21/64H04L9/3213H04L41/0631H04L41/142H04L43/10H04L51/212H04L63/02H04L63/0209H04L63/0227H04L63/0236H04L63/0254H04L63/0428H04L63/08H04L63/0807H04L63/10H04L63/14H04L63/1408H04L63/1416H04L63/1425H04L63/1441H04L63/1466H04L63/1491H04L63/164H04L63/20H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,521
App. No.
17/667,111
Granted
Aug 8, 2023
Kind
B2
Abstract

A firewall uses information about an application that originates a network request to determine whether and how to forward the request over a network. The firewall may more generally rely on the identity of the originating application, the security state of the originating application, the security state of the endpoint, and any other information that might provide an indication of malicious activity, to make routing and forwarding decisions for endpoint-originated network traffic.

Claims (35)

1. A computer program product for operating a firewall to selectively forward network communications between a first network interface of the firewall operable to couple to an endpoint and a second network interface of the firewall operable to couple to a remote resource hosted at a server, the computer program product comprising computer executable code embodied in a non-transitory memory of the firewall that, when executing on the firewall, responds to a request from the endpoint to the remote resource by performing the steps of:

detecting indicia of maliciousness in the request;

in response to the indicia, determining an identity of an application that originated the request on the endpoint based on a packet carrying the request;

determining a security state of the application that originated the request by querying a security data recorder on the endpoint to identify previous events associated with the application; and

conditionally forwarding the request from the firewall to the server only when the identity of the application is recognized and the security state of the application is uncompromised.

2. The computer program product of claim 1 , wherein determining the security state of the application that originated the request includes determining the security state based on a secure heartbeat included in the packet.

3. The computer program product of claim 1 , wherein determining the security state of the application includes traversing a causal chain of events on the endpoint to identify a root cause of the request.

4. The computer program product of claim 1 , wherein conditionally forwarding the request to the server includes conditionally forwarding the request to the server only when a security state of the endpoint is uncompromised.

5. A firewall configured to selectively forward network communications, the firewall comprising:

a first network interface operable to couple to an endpoint;

a second network interface operable to couple to a remote resource hosted at a server; and

a processor configured to respond to a request from the endpoint to the remote resource for a service by performing the steps of:

detecting indicia of maliciousness in the request;

in response to the indicia determining an identity of an application that originated the request on the endpoint based on a packet carrying the request;

determining a security state of the application by querying a security data recorder on the endpoint to identify previous events associated with the application; and

conditionally forwarding the request to the server only when the identity of the application is recognized and the security state of the application is uncompromised.

6. The firewall of claim 5 , wherein determining the identity of the application includes following a causal chain from a nominal originating application to identify a root cause of the request.

7. The firewall of claim 5 , wherein the indicia of maliciousness includes an indication of compromise of the endpoint in a secure heartbeat included in the request.

8. The firewall of claim 5 , wherein querying the security data recorder includes querying the security data recorder to identify a root cause of the request.

9. The firewall of claim 5 , wherein the endpoint and the remote resource are peers coupled together through a peer-to-peer network.

10. The firewall of claim 5 , wherein the indicia of maliciousness includes access to external resources in violation of a security policy.

11. The firewall of claim 5 , wherein the indicia of maliciousness includes use of corporate credentials in violation of a security policy.

12. The firewall of claim 5 , wherein the indicia of maliciousness includes web traffic in violation of a security policy.

13. The firewall of claim 5 , wherein the indicia of maliciousness includes attempted communications through the firewall in violation of a security policy.

14. The firewall of claim 5 , wherein determining the security state of the application includes querying the endpoint from the firewall for indicia of compromise.

15. The firewall of claim 5 , wherein determining the identity of the application includes querying the endpoint from the firewall for the identity.

16. The firewall of claim 5 , wherein the processor is further configured to perform the steps of monitoring a pattern of traffic to the remote resource from a plurality of endpoints and automatically developing a rule for acceptable connections to the server based on the pattern of traffic.

17. The firewall of claim 5 , wherein determining the security state of the application includes querying the endpoint for at least one of credentials authenticating the application to the server, credentials authenticating a user of the endpoint to the server, or an encrypted heartbeat containing information about a state of the endpoint.

18. The firewall of claim 5 , wherein the processor is further configured to transmit a notification to the endpoint when an indication of compromise is detected for the application.

19. A method for operating a firewall to selectively forward network communications between a first network interface of the firewall operable to couple to an endpoint and a second network interface of the firewall operable to couple to a remote resource hosted at a server, the method including responding to a request from the endpoint to the remote resource by performing the steps of:

detecting indicia of maliciousness in the request;

in response to the indicia, determining an identity of an application that originated the request on the endpoint based on a packet carrying the request;

determining a security state of the application by querying a security data recorder on the endpoint to identify previous events associated with the application; and

conditionally forwarding the request to the server only when the identity of the application is recognized and the security state of the application is uncompromised.

20. The method of claim 19 , wherein querying the security data recorder includes querying the security data recorder to identify a root cause of the request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2022
From: THOMAS, ANDREW J.; ACKERMAN, KARL; BEAN, JAMES DOUGLAS; RAY, KENNETH D.; STUTZ, DANIEL
To: SOPHOS LIMITED
Reel/Frame 058935/0398 →
Continuity (3)
Continuation 16224258 · Dec 18, 2018
Continuation PCTUS2016040397 · Jun 30, 2016
Related Publication 20220166794A1 · May 26, 2022