IP Library Granted Patent US 8,832,833
Granted Patent B2
US 8,832,833 · App. 12/592,580 · Granted Sep 9, 2014

Integrated data traffic monitoring system

Inventors: Robert James Demopoulos (Champlin, MN); David James Fladebo (Clear Lake, MN)
Assignee: The Barrier Group
H04L63/0209H04L41/16H04L63/0263H04L63/1458H04L63/1416H04L63/1425H04L63/1466H04L63/0245H04L63/0281H04L63/0254H04L63/1475H04L63/1408H04L12/585H04L63/0236H04L63/145H04L51/12G06F21/552H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,832,833
App. No.
12/592,580
Granted
Sep 9, 2014
Kind
B2
Abstract

The present invention includes an integrated data traffic monitoring system monitoring data traffic received from a communication network and destined for a protected network. The monitoring system includes a security appliance and one or more security and monitoring technologies such as hardware and open source and proprietary software products. The security appliance and the security and monitoring technologies may be implemented as separate and distinct modules or combined into a single security appliance. The security and monitoring technologies monitor network data traffic on, or directed to, the protected network. The monitoring system collects data from each of the technologies into an event database and, based on the data, automatically generates rules directing one or more of the technologies to prevent subsequent communications traffic from specific sources from entering the protected network.

Claims (20)

1. A method of screening packets received from a communication network comprising:

receiving a packet associated with one of an e-mail message, a VPN connection, and a web page response, the packet having a source;

performing an intrusion detection analysis on the packet using a set of intrusion detection rules;

if the packet passes the intrusion detection analysis, performing a firewall analysis on the packet using a set of firewall rules;

if the packet passes the firewall analysis, determining if the packet is associated with an e-mail message, a VPN connection or a web page response;

if the packet is associated with an e-mail message, performing a virus analysis on the packet using a set of virus definitions;

if the packet is associated with a VPN connection, performing an authentication analysis on the packet using a set of authentication criteria; and

if the packet fails any of the intrusion detection analysis, the firewall analysis, the virus analysis, or the authentication analysis, automatically generating a new intrusion detection rule to delete any subsequent packets received from the same source as the packet.

2. The method of claim 1 , further comprising:

if the packet fails any of the intrusion detection analysis, the firewall analysis, the virus analysis, or the authentication analysis, deleting the packet.

3. The method of claim 1 , wherein automatically generating a new intrusion detection rule comprises:

generating event data based on the packet; and

storing at least some of the event data in a new event record associated with the packet in an event database having a plurality of event records associated with previously received packets.

4. The method of claim 1 , wherein automatically generating a new intrusion detection rule further comprises:

automatically generating a new intrusion detection rule if one or more of the plurality of event records are associated with previously received packets from the source.

5. The method of claim 3 , wherein the event data comprises a priority associated with the packet and automatically generating further comprises:

assigning an initial priority to the event data; and

automatically increasing a priority associated with the packet if one or more of the plurality of event records are associated with previously received packets from the source and the priority is less than a highest priority.

6. The method of claim 5 , further comprising:

storing the priority assigned to the event data with the event data.

Assignments (13)
SECURITY INTEREST Recorded Jun 8, 2026
From: CLOUDCOVER IP, LLC
To: MONTGOMERY CAPITAL PARTNERS V, LP
Reel/Frame 074885/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2025
From: TEGO CYBER INC.
To: CLOUDCOVER, LTD.
Reel/Frame 070997/0648 →
SECURITY INTEREST Recorded Apr 15, 2025
From: CLOUDCOVER, LTD
To: TROUDT, JOHN
Reel/Frame 070841/0512 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: CLOUDCOVER LTD
To: TEGO CYBER INC.
Reel/Frame 069665/0653 →
RELEASE OF SECURITY INTEREST Recorded Apr 16, 2024
From: MONTGOMERY CAPITAL PARTNERS V, LP.
To: CLOUDCOVER IP, LLC
Reel/Frame 067126/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2023
From: CLOUDCOVER IP, LLC
To: CLOUDCOVER, LTD.
Reel/Frame 065968/0843 →
SECURITY INTEREST Recorded Nov 11, 2022
From: CLOUDCOVER IP, LLC
To: MONTGOMERY CAPITAL PARTNERS V, LP
Reel/Frame 061741/0940 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2020
From: CLOUDCOVER USA, INC.
To: CLOUDCOVER IP, LLC
Reel/Frame 053284/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2020
From: THE B1 GROUP, INC.
To: CLOUDCOVER USA, INC.
Reel/Frame 052978/0873 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2020
From: THE BARRIER GROUP, LLC
To: THE B1 GROUP, INC.
Reel/Frame 052978/0927 →
EXCHANGE Recorded Jul 15, 2019
From: THE BARRIER GROUP, LLC
To: THE B1 GROUP, INC.
Reel/Frame 049752/0009 →
MERGER Recorded Jul 15, 2019
From: THE B1 GROUP, INC.
To: CLOUDCOVER USA, INC.
Reel/Frame 049751/0391 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2012
From: DEMOPOULOS, ROBERT JAMES; FLADEBO, DAVID JAMES
To: THE BARRIER GROUP
Reel/Frame 027569/0409 →
Continuity (4)
Continuation 11042493 · Jan 24, 2005
Continuation 10768931 · Jan 29, 2004
Provisional Application 60538960 · Jan 23, 2004
Related Publication 20100257598A1 · Oct 7, 2010