IP Library Granted Patent US 8,874,707
Granted Patent B1
US 8,874,707 · App. 14/140,388 · Granted Oct 28, 2014

Network services platform

Inventors: Alexander L. Quilter (Cary, NC); Oliver Lavery (Toronto, CA); David J. Meltzer (Roswell, CA); Timothy D. Keanini (Novato, CA)
Assignee: Tripwire, Inc.
H04L41/50H04L61/2007H04L61/2503H04L61/6068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,874,707
App. No.
14/140,388
Granted
Oct 28, 2014
Kind
B1
Abstract

A network services platform provides services to remote enterprise networks. The services platform provides a control module to a computer in the enterprise network. The control module executes on the computer and interacts with the services platform to establish an Internet Protocol (IP) tunnel between the services platform and the computer. The control module also establishes a bridge between the IP tunnel and the enterprise network. The services platform allocates a unique private IP address space to the enterprise network, and translates IP addresses in network communications between enterprise network addresses and corresponding services platform addresses in the allocated unique private address space. The services platform provides network services to the enterprise network via the IP tunnel and bridge.

Claims (40)

1. A computer-implemented method of using a services platform to provide a network service to a remote enterprise network, comprising:

establishing an Internet Protocol (IP) tunnel between the services platform and an endpoint of the remote enterprise network;

establishing a bridge between the IP tunnel and the remote enterprise network, wherein establishing the bridge comprises using packet injection to inject packets to the remote enterprise network, the packets injected to the remote enterprise network appearing to originate from the endpoint, the bridge being further configured to transfer packets from the remote enterprise network received by the endpoint through the IP tunnel;

translating IP addresses in network traffic received by the services platform from the remote enterprise network via the IP tunnel from enterprise network IP addresses to corresponding service platform IP addresses;

translating IP addresses in network traffic from the services platform to the remote enterprise network via the IP tunnel from services platform IP addresses to corresponding enterprise network IP addresses; and

providing the network service to the remote enterprise network via the IP tunnel and bridge;

wherein the providing the network service to the remote enterprise network comprises providing one or more of the following network services: vulnerability management, configuration auditing, file integrity monitoring, or compliance auditing.

2. The computer-implemented method of claim 1 , wherein the tunnel is formed at a layer of an Open Systems Interconnection model.

3. The computer-implemented method of claim 1 , wherein the network service is provided via the internet.

4. The computer-implemented method of claim 1 , further comprising providing a web page that displays the results of the network service.

5. The computer-implemented method of claim 1 , further comprising providing a web page that provides functionality for downloading modules to the enterprise network for implementing the tunnel and bridge.

6. The computer-implemented method of claim 1 , wherein the tunnel is formed at the data link layer.

7. The computer-implemented method of claim 1 , further comprising:

allocating a unique private IP address space to the enterprise network;

inventorying the enterprise network to identify a plurality of endpoints on the enterprise network, ones of the plurality of endpoints identified with enterprise network IP addresses in an enterprise address space; and assigning service platform IP addresses within the unique private IP address space to identified ones of the plurality of endpoints.

8. The computer-implemented method of claim 1 , wherein the services platform provides network services to a plurality of remote enterprise networks and wherein a different unique private IP address space is allocated to each of the plurality of enterprise networks.

9. A non-transitory computer-readable storage medium storing computer-executable instructions which when executed by a computer cause the computer to perform a method of using a services platform to provide a network service to a remote enterprise network, the method comprising:

establishing an Internet Protocol (IP) tunnel between the services platform and an endpoint of the remote enterprise network;

establishing a bridge between the IP tunnel and the remote enterprise network, wherein establishing the bridge comprises using packet injection to inject packets to the remote enterprise network, the packets injected to the remote enterprise network appearing to originate from the endpoint, the bridge being further configured to transfer packets from the remote enterprise network received by the endpoint through the IP tunnel;

translating IP addresses in network traffic received by the services platform from the remote enterprise network via the IP tunnel from enterprise network IP addresses to corresponding service platform IP addresses;

translating IP addresses in network traffic from the services platform to the remote enterprise network via the IP tunnel from services platform IP addresses to corresponding enterprise network IP addresses; and

providing the network service to the remote enterprise network via the IP tunnel and bridge;

wherein the providing the network service to the remote enterprise network comprises providing one or more of the following network services: vulnerability management, configuration auditing, file integrity monitoring, or compliance auditing.

10. The non-transitory computer-readable storage medium of claim 9 , wherein the tunnel is formed at a layer of an Open Systems Interconnection model.

11. The non-transitory computer-readable storage medium of claim 9 , wherein the network service is provided via the internet.

12. The non-transitory computer-readable storage medium of claim 9 , wherein the method further comprises providing a web page that displays the results of the network service.

13. The non-transitory computer-readable storage medium of claim 9 , wherein the method further comprises:

allocating a unique private IP address space to the enterprise network;

inventorying the enterprise network to identify a plurality of endpoints on the enterprise network, ones of the plurality of endpoints identified with enterprise network IP addresses in an enterprise space; and

assigning service platform IP addresses within the unique private IP address space to identified ones of the plurality of endpoints.

14. The non-transitory computer-readable storage medium of claim 9 , wherein the services platform provides network services to a plurality of remote enterprise networks and wherein a different unique private IP address space is allocated to each of the plurality of enterprise networks.

15. A system, comprising:

a processor;

memory storing computer-executable instructions which when executed by the processor cause the processor to perform a method of using a services platform to provide a network service to a remote enterprise network, the method comprising:

establishing an Internet Protocol (IP) tunnel between the services platform and an endpoint of the remote enterprise network;

establishing a bridge between the IP tunnel and the remote enterprise network, wherein establishing the bridge comprises using packet injection to inject packets to the remote enterprise network, the packets injected to the remote enterprise network appearing to originate from the endpoint, the bridge being further configured to transfer packets from the remote enterprise network received by the endpoint through the IP tunnel;

translating IP addresses in network traffic received by the services platform from the remote enterprise network via the IP tunnel from enterprise network IP addresses to corresponding service platform IP addresses;

translating IP addresses in network traffic from the services platform to the remote enterprise network via the IP tunnel from services platform IP addresses to corresponding enterprise network IP addresses; and

providing the network service to the remote enterprise network via the IP tunnel and bridge;

wherein the providing the network service to the remote enterprise network comprises providing one or more of the following network services: vulnerability management, configuration auditing, file integrity monitoring, or compliance auditing.

Assignments (12)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2021
From: QUILTER, ALEXANDER L.; LAVERY, OLIVER; MELTZER, DAVID J.; KEANINI, TIMOTHY D.
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 058309/0557 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2021
From: NCIRCLE NETWORK SECURITY, INC.
To: TRIPWIRE, INC.
Reel/Frame 058311/0824 →
Continuity (3)
Continuation 13714022 · Dec 13, 2012
Continuation 13531248 · Jun 22, 2012
Continuation 12825305 · Jun 28, 2010