IP Library Granted Patent US 11,943,297
Granted Patent B2
US 11,943,297 · App. 18/472,709 · Granted Mar 26, 2024

Distributed network security system providing isolation of customer data

Inventor: Paul Michael Martini (Boston, MA)
Assignee: iboss, Inc.
H04L67/1097G06F9/45533G06F9/45558H04L12/4641H04L63/0209H04L63/20H04L67/10H04L67/52G06F2009/4557G06F2009/45579G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,943,297
App. No.
18/472,709
Granted
Mar 26, 2024
Kind
B2
Abstract

Techniques for delivering a distributed network security service providing isolation of customer data are described. One example method includes assigning a first node in a distributed network to a first customer; assigning a second node in the distributed network to a second customer; configuring the assigned first node to process network traffic only from the first customer; configuring the assigned second node to process network traffic only from the second customer; processing, by the assigned first node, network traffic associated with the first customer; and processing, by the assigned second node, network traffic associated with the second customer, wherein the network traffic of the first customer is isolated from the network traffic of the second customer, wherein the network traffic of the customers is kept isolated from one another.

Claims (47)

1. A computer-implemented method executed by one or more processors comprising:

maintaining a distributed network security service, the security service configured to perform operations comprising:

generating, for each of a plurality of client organizations, an associated node container;

executing, in each node container, one or more nodes that are each configured to act as an intermediary between clients of the associated client organization and sources outside the distributed network, and to examine i) traffic addressed to the clients of the associated client organization and originating from sources outside the distributed network; and ii) traffic addressed to the sources outside the distributed network and originating from the clients of the associated client organization;

maintaining, for each client organization, an associated unique node address that is not shared by any other client organization;

assigning each unique node address to at least one security container associated with the corresponding client organization;

receiving a Domain Name System (DNS) request from a requesting-client;

determining to which of the client organizations the requesting-client belongs; and

returning a selected unique node address that has been selected out of the unique node addresses based on the determined client organization to which the requesting-client belongs.

2. The method of claim 1 , wherein returning the selected unique node address that has been selected out of the unique node addresses based on the determined client organization to which the requesting-client belongs comprises:

selecting by a load balancer, one of a plurality of possible unique node addresses associated with different nodes of the same security container.

3. The method of claim 2 , wherein the load balancer selects one of the plurality of possible unique node addresses based on current loads of the different nodes of the same security container.

4. The method of claim 1 , wherein at least some of the nodes executing in a single node container are copies of the same virtual machine.

5. The method of claim 1 , wherein at least some of the nodes executing in a single node container are executing on a network operated by the associated client organization.

6. The method of claim 1 , where none of the nodes executing in a single node container are executing on a network operated by the associated client organization.

7. A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:

maintaining a distributed network security service, the security service configured to perform operations comprising:

generating, for each of a plurality of client organizations, an associated node container;

executing, in each node container, one or more nodes that are each configured to act as an intermediary between clients of the associated client organization and sources outside the distributed network, and to examine i) traffic addressed to the clients of the associated client organization and originating from sources outside the distributed network; and ii) traffic addressed to the sources outside the distributed network and originating from the clients of the associated client organization;

maintaining, for each client organization, an associated unique node address that is not shared by any other client organization;

assigning each unique node address to at least one security container associated with the corresponding client organization;

receiving a Domain Name System (DNS) request from a requesting-client;

determining to which of the client organizations the requesting-client belongs; and

returning a selected unique node address that has been selected out of the unique node addresses based on the determined client organization to which the requesting-client belongs.

8. The non-transitory, computer-readable medium of claim 7 , wherein returning the selected unique node address that has been selected out of the unique node addresses based on the determined client organization to which the requesting-client belongs comprises:

selecting by a load balancer, one of a plurality of possible unique node addresses associated with different nodes of the same security container.

9. The non-transitory, computer-readable medium of claim 8 , wherein the load balancer selects one of the plurality of possible unique node addresses based on current loads of the different nodes of the same security container.

10. The non-transitory, computer-readable medium of claim 7 , wherein at least some of the nodes executing in a single node container are copies of the same virtual machine.

11. The non-transitory, computer-readable medium of claim 7 , wherein at least some of the nodes executing in a single node container are executing on a network operated by the associated client organization.

12. The non-transitory, computer-readable medium of claim 7 , where none of the nodes executing in a single node container are executing on a network operated by the associated client organization.

13. A system comprising:

one or more processors; and

computer memory storing instructions operable when executed by the processors to cause the processors to perform operations comprising:

maintaining a distributed network security service, the security service configured to perform operations comprising:

generating, for each of a plurality of client organizations, an associated node container;

executing, in each node container, one or more nodes that are each configured to act as an intermediary between clients of the associated client organization and sources outside the distributed network, and to examine i) traffic addressed to the clients of the associated client organization and originating from sources outside the distributed network; and ii) traffic addressed to the sources outside the distributed network and originating from the clients of the associated client organization;

maintaining, for each client organization, an associated unique node address that is not shared by any other client organization;

assigning each unique node address to at least one security container associated with the corresponding client organization;

receiving a Domain Name System (DNS) request from a requesting-client;

determining to which of the client organizations the requesting-client belongs; and

returning a selected unique node address that has been selected out of the unique node addresses based on the determined client organization to which the requesting-client belongs.

14. The system of claim 13 , wherein returning the selected unique node address that has been selected out of the unique node addresses based on the determined client organization to which the requesting-client belongs comprises:

selecting by a load balancer, one of a plurality of possible unique node addresses associated with different nodes of the same security container.

15. The system of claim 14 , wherein the load balancer selects one of the plurality of possible unique node addresses based on current loads of the different nodes of the same security container.

16. The system of claim 13 , wherein at least some of the nodes executing in a single node container are copies of the same virtual machine.

17. The system of claim 13 , wherein at least some of the nodes executing in a single node container are executing on a network operated by the associated client organization.

18. The system of claim 13 , where none of the nodes executing in a single node container are executing on a network operated by the associated client organization.

Assignments (2)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2023
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 065242/0175 →
Continuity (4)
Continuation 17189082 · Mar 1, 2021
Continuation 16666296 · Oct 28, 2019
Continuation 15233894 · Aug 10, 2016
Related Publication 20240015219A1 · Jan 11, 2024