IP Library Granted Patent US 9,231,973
Granted Patent B1
US 9,231,973 · App. 14/245,966 · Granted Jan 5, 2016

Automatic intervention

Inventor: David Van (Franklin Park, NJ)
Assignee: Xceedium, Inc.
H04L63/1466G06F21/30H04L63/10H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,231,973
App. No.
14/245,966
Granted
Jan 5, 2016
Kind
B1
Abstract

Securing a network is disclosed. A monitored session between a client and a network resource is provided. It is determined whether the client is attempting an authorized command. If the command is determined to be unauthorized, the command is intercepted. Optionally, remedial action is taken if it is determined that the client is attempting an unauthorized command.

Claims (33)

1. A gatekeeper appliance, comprising:

one or more processors; and

a memory coupled with the one or more processors, wherein the memory is configured to provide the one or more processors with instructions which when executed cause the one or more processors to:

provide a monitored session between a client and a first remote network device, wherein a user of the client has been authorized to access the first remote network device;

monitor for indications that the user of the client is attempting to use authorized access to the first remote network device to execute a command to obtain unauthorized access to a second remote network device reachable from the first remote network device, wherein the command is associated with an attempt to roam out from the first remote network device to the second remote network device, wherein a set of authorized commands is defined for the user of the client, and wherein a different set of authorized commands is defined for a different user; and

in response to detecting the command, intercept the detected command and perform one or more actions, wherein performing the one or more actions includes preventing the user of the client from roaming from the first remote network device to the second remote network device, wherein preventing the user of the client from roaming from the first remote network device to the second remote network device includes preventing the detected command from being executed.

2. The gatekeeper appliance of claim 1 , wherein the first remote network device is a router.

3. The gatekeeper appliance of claim 1 , wherein the second remote network device is a server.

4. The gatekeeper appliance of claim 1 , wherein providing the session includes serving one or more applets to the client.

5. The gatekeeper appliance of claim 1 , wherein the command is detected at least in part by evaluating at least one of a black list and a white list.

6. The gatekeeper appliance of claim 1 , wherein the monitoring is bidirectional.

7. The gatekeeper appliance of claim 1 , wherein the memory is further configured to provide the one or more processors with instructions which when executed cause the one or more processors to capture the session.

8. The gatekeeper appliance of claim 7 , wherein capturing the session includes logging the data stream between the client and the first remote network device.

9. The gatekeeper appliance of claim 7 , wherein capturing the session includes capturing keystrokes.

10. The gatekeeper appliance of claim 7 , wherein capturing the session includes capturing output of the first remote network device.

11. The gatekeeper appliance of claim 1 , wherein the one or more actions includes issuing a warning message.

12. The gatekeeper appliance of claim 11 , wherein the issued warning message indicates that an unauthorized attempt to roam has been detected.

13. The gatekeeper appliance of claim 1 , wherein the one or more actions includes sending a notification alert.

14. The gatekeeper appliance of claim 1 , wherein identification information associated with a user of the client is collected in response to detecting the command.

15. The gatekeeper appliance of claim 1 , wherein preventing the detected command from being executed includes dropping the detected command.

16. The gatekeeper appliance of claim 1 , wherein preventing the detected command from being executed includes replacing the detected command with a bogus command.

17. A method, comprising:

providing a monitored session between a client and a first remote network device, wherein a user of the client has been authorized to access the first remote network device;

monitoring, using one or more processors, for indications that the user of the client is attempting to use authorized access to the first remote network device to execute a command to obtain unauthorized access to a second remote network device reachable from the first remote network device, wherein the command is associated with an attempt to roam out from the first remote network device to the second remote network device, wherein a set of authorized commands is defined for the user of the client, and wherein a different set of authorized commands is defined for a different user; and

in response to detecting the command, intercepting the detected command and performing one or more actions, wherein performing the one or more actions includes preventing the user of the client from roaming from the first remote network device to the second remote network device, wherein preventing the user of the client from roaming from the first remote network device to the second remote network device includes preventing the detected command from being executed.

18. The method of claim 17 , wherein preventing the detected command from being executed includes dropping the detected command.

19. The method of claim 17 , wherein preventing the detected command from being executed includes replacing the detected command with a bogus command.

20. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

providing a monitored session between a client and a first remote network device, wherein a user of the client has been authorized to access the first remote network device;

monitoring, using a set of one or more processors, for indications that the user of the client is attempting to use authorized access to the first remote network device to execute a command to obtain unauthorized access to a second remote network device reachable from the first remote network device, wherein the command is associated with an attempt to roam out from the first remote network device to the second remote network device, wherein a set of authorized commands is defined for the user of the client, and wherein a different set of authorized commands is defined for a different user; and

in response to detecting the command, intercepting the detected command and performing one or more actions, wherein performing the one or more actions includes preventing the user of the client from roaming from the first remote network device to the second remote network device, wherein preventing the user of the client from roaming from the first remote network device to the second remote network device includes preventing the detected command from being executed.

21. The computer program product of claim 20 , wherein preventing the detected command from being executed includes dropping the detected command.

22. The computer program product of claim 20 , wherein preventing the detected command from being executed includes replacing the detected command with a bogus command.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2016
From: XCEEDIUM, INC.
To: CA, INC.
Reel/Frame 037830/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2015
From: VAN, DAVID
To: XCEEDIUM, INC.
Reel/Frame 036276/0918 →
SECURITY INTEREST Recorded May 31, 2015
From: XCEEDIUM, INC.
To: HORIZON TECHNOLOGY FINANCE CORPORATION
Reel/Frame 035750/0371 →
Continuity (3)
Continuation 11786908 · Apr 13, 2007
Provisional Application 60857659 · Nov 7, 2006
Provisional Application 60792160 · Apr 13, 2006