Protection of computer networks against malicious content
Abstract
A gateway including an input for receiving communications packets, an output for outputting communications packets generally in real time with respect to receipt thereof, a policy manager determining criteria for collection and inspection of a collection of packets and a packet collection agent receiving packets from the input in accordance with criteria established by the policy manager and including a content inspector inspecting the collection of packets in accordance with criteria established by the policy manager and being operative to prevent supply of at least one packet of a collection of packets to the output when the collection of packets includes undesirable content in accordance with the criteria established by the policy manager.

Term
Term ended
Projected expiry passed 1 February 2021, 5.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
17 claims: 7 independent, 10 dependent
- 1A gateway comprising:an input for receiving communications packets;an output for outputting communications packets generally in real time with respect to receipt thereof;a policy manager determining criteria for collection and inspection of a collection of packets;a packet collection agent receiving packets from said input in accordance with criteria established by said policy manager;andat least one content inspector operated by the packet collection agent and inspecting said collection of packets in accordance with criteria established by said policy manager,said packet collection agent being operative to prevent supply of at least one packet of a collection of packets to said output when said collection of packets includes undesirable content in accordance with said criteria established by said policy manager.
- 5A gateway according to any of claims I to 4 and wherein said packet collection agent operates plural content inspectors simultaneously.
- 8A gateway comprising:an input for receiving communications packets;an output for outputting communications packets generally in real time with respect to receipt thereof;anda packet collection agent receiving packets from said input in accordance with criteria established by said policy manager;anda content inspector operated by the packet collection agent for inspecting said collection of packets and being operative to prevent supply of at least one packet of a collection of packets to said output when said collection of packets includes undesirable content.
- 11A method for protecting a computer from malicious content comprising the steps of:determining criteria for collection and inspection of a collection of packets;receiving packets from among the collection of packets in accordance with the criteria;inspecting the packets in accordance with the criteria;preventing output of at least one packet but not all packets of a collection of packets when the collection of packets includes undesirable content in accordance with the criteria;andoutputting packets other than the at least one packet generally in real time with respect to receipt thereof.
Independent claims7
27 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
The present invention relates to computer network communications generally and more particularly to apparatus and methods for providing security in computer network communications.
BACKGROUND OF THE INVENTION
There exist a large number of U.S. Patents which deal with security in computer network communications. The following U.S. Patents and the references cited therein are believed to represent the state of the art: 5,951,698; 5,918,008; 5,907,834; 5,892,904; 5,889,943; 5,881,151; 5,859,966; 5,854,916; 5,842,002; 5,832,208; 5,826,012; 5,822,517; 5,809,138; 5,802,277; 5,748,940; 5,684,875; 5,679,525; 5,675,711; 5,666,411; 5,657,473; 5,649,095; 5,623,600; 5,613,002; 5,537,540; 5,511,184; 5,111,163; 5,502,815; 5,485,575; 5,473,769; 5,452,442; 5,398,196; 5,359,659; 5,319,776.
Security in computer network communications deals with two general types of malicious content which may be communicated over a network to a computer: viruses and vandals. Viruses may be classified into a number of categories, such as file infectors, file system viruses, macro viruses and system/boot record infectors.
Vandals are distinguished from viruses in that whereas viruses require a user to execute a program in order to cause damage, vandals are auto-executable Internet applications and may cause immediate damage. Currently the following types of vandals are known: Java applets, ActiveX objects, scripts and cookies. Vandals may hide in various types of communicated content, including Email, web content, legitimate sites and file downloads.
It is known to employ proxy servers to detect and prevent receipt of malicious content by a computer. Use of proxy servers for this type of application is described inter alia in the aforesaid U.S. Patents 5,951,698; 5,889,943 & 5,623,600. The use of proxy servers for this purpose has a number of disadvantages including non-real time operation, generation of network bottlenecks, requiring special configuration of each desktop and relative ease of bypass by a user.
SUMMARY OF THE INVENTION
The present invention seeks to provide apparatus and a method for protection of computers against malicious content generally in real time and without requiring the use of a proxy server.
There is thus provided in accordance with a preferred embodiment of the present invention a gateway including an input for receiving communications packets, an output for outputting communications packets generally in real time with respect to receipt thereof, a policy manager determining criteria for collection and inspection of a collection of packets and a packet collection agent receiving packets from the input in accordance with criteria established by the policy manager and including a content inspector inspecting the collection of packets in accordance with criteria established by the policy manager and being operative to prevent supply of at least one packet of a collection of packets to the output when the collection of packets includes undesirable content in accordance with the criteria established by the policy manager.
There is also provided in accordance with a preferred embodiment of the present invention a method for protecting a computer from malicious content comprising the steps of: <ul id="ul0001" list-style="none" compact="compact"><li>determining criteria for collection and inspection of a collection of packets;</li><li>receiving packets from among the collection of packets in accordance with the criteria;</li><li>inspecting the packets in accordance with the criteria;</li><li>preventing output of at least one packet but not all packets of a collection of packets when the collection of packets includes undesirable content in accordance with the criteria; and</li><li>outputting packets other than the at least one packet generally in real time with respect to receipt thereof;</li></ul>
In accordance with a preferred embodiment of the present invention, the at least one packet is the last packet of a file.
BRIEF DESCRIPTION OF THE DRAWINGS
The present invention will be understood and appreciated more fully from the following detailed description, taken in conjunction with the drawings in which: <ul id="ul0002" list-style="none" compact="compact"><li>Fig. 1A is a simplified block diagram illustration of implementation of the invention in a firewall-type configuration for checking incoming Internet but not intranet traffic;</li><li>Fig. 1B is a simplified block diagram illustration of implementation of the invention for checking all incoming communications;</li><li>Fig. 2 is a simplified block diagram illustration of the use of multiple content inspectors by a single packet collection agent; and</li><li>Fig. 3 is a simplified flow chart illustrating operation of a packet collection agent in accordance with a preferred embodiment of the present invention.</li></ul>
DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS
The present invention seeks to provide protection of a computer against malicious content without requiring the use of a proxy server.
Reference is now made to Fig. 1A, which is a simplified block diagram illustration of implementation of the invention in a firewall-type configuration for checking incoming Internet but not intranet traffic. As seen in Fig. 1A, there is provided a typical computer 10 in which resides conventional TCP/IP routing software 12. Computer 10 is typically connected to a network 13.
In accordance with a preferred embodiment of the present invention a packet collection agent (PCA) 14 is interposed between a network interface card (NIC) 16 which receives Internet traffic and the TCP/IP routing software 12. In this embodiment, a separate NIC 18 handles intranet traffic and does not have a PCA interfaced between it and the TCP/IP routing software 12.
In accordance with a preferred embodiment of the present invention, the PCA 14 interfaces with policy manager software 20, which determines collection criteria, i.e. which types of packets of which types of files are collected, and inspection criteria, i.e. which types of content in a file are not allowed to pass to or from network 13.
Based on the criteria established by the policy manager software 20, the PCA 14 operates content inspector software 22, which inspects the packets of a file which fits the criteria for collection and inspection. The content inspector software 22 operates based on criteria established by the policy manager software 20 and reports its inspection findings to the PCA 14. Alternatively, policy manager software 20 may be obviated. In such a case, the PCA 14 and the content inspector software are each programmed with suitable criteria.
In accordance with a preferred embodiment of the invention, the PCA 14 does not delay transmittal of most packets, even of files that require inspection. Rather, while transmitting all but typically the last packet in a file, it operates content inspector software 22 to inspect the contents of the file. If the contents are found to be acceptable, typically the last packet is released. If the contents of a file are not found to be acceptable by the criteria typically established by the policy manager software 20, at least one packet, typically the last packet, is not released, preventing activation of the unacceptable content by the computer.
Reference is now made to Fig. 1B, which illustrates implementation of the invention for checking all incoming communications along a network 28. In this illustrated embodiment, as seen in Fig. 1B, there is provided a typical computer 30 on which resides TCP/IP software 32. In accordance with a preferred embodiment of the present invention, a packet collection agent (PCA) 34 is interposed between a network interface card (NIC) 36, which receives Internet and intranet traffic, and the TCP/IP software 32.
In accordance with a preferred embodiment of the present invention, as in the embodiment of Fig. 1A, the PCA 34 interfaces with policy manager software 40, which determines collection criteria, i.e. which types of packets of which types of files are collected, and inspection criteria, i.e. which types of content in a file are not allowed to pass to the computer.
Based on the criteria typically established by the policy manager software 40, the PCA 34 operates content inspector software 42, which inspects the packets of a file which fits the criteria for collection and inspection. The content inspector software 42 operates typically based on criteria established by the policy manager software 40 and reports its inspection findings to the PCA 34.
In accordance with a preferred embodiment of the invention, the PCA 34 does not delay transmittal of most packets, even of files that require inspection. Rather while transmitting all but typically the last packet in a file, it operates content inspector software 42 to inspect the contents of the file. If the contents are found to be acceptable, typically the last packet is released. If the contents of a file are not found to be acceptable by the criteria typically established by the policy manager software 40, at least one packet, typically the last packet, is not released, preventing activation of the unacceptable content by the computer.
Reference is now made to Fig. 2, which is a simplified block diagram illustration of the use of multiple content inspectors by a single packet collection agent. As illustrated in Fig. 2, a single PCA 50 may interface with a single policy manager 52, which may, in certain embodiments be obviated, and with a plurality of content inspectors 54 simultaneously. This type of arrangement may be particularly useful for handling high traffic volumes.
Reference is now made to Fig. 3, which is a simplified flow chart illustrating operation of a PCA in accordance with a preferred embodiment of the present invention.
As seen in Fig. 3, upon receipt of a packet, if the packet is received in the context of an existing file and is not the last packet, the packet is simultaneously stored and released to its destination, generally in real time.
If the packet is the last packet in a file, the PCA typically obtains the inspection criteria from the policy manager and sends all of the packets in the file to a content inspector for inspection in accordance with the inspection policy typically established by the policy manager. If the file passes inspection, the last packet is released as well. If not, the last packet is not released.
If the packet is the first packet of a new file and thus is a control packet as opposed to a data packet, the PCA employs the collection criteria typically established by the policy manager to determine whether the file requires inspection. If not, the packet and all subsequent packets of that file are immediately released as they arrive. If the file is a type of file that is not permitted, no packets are released. If, however, the file is a type of file that requires inspection, the packet is immediately released and the subsequent packets are inspected.
It will be appreciated by persons skilled in the art that the present invention is not limited by what has been particularly shown and described hereinabove. Rather the scope of the present invention includes both combinations and subcombinations of various features described hereinabove and in the drawings as well as modifications and variations thereof which would occur to a person of ordinary skill in the art upon reading the foregoing description and which are not in the prior art.
Where technical features mentioned in any claim are followed by reference signs, those reference signs have been included for the sole purpose of increasing the intelligibility of the claims and accordingly, such reference signs do not have any limiting effect on the scope of each element identified by way of example by such reference signs.
Contents5
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2016163162A | Cited by | Japan | Search report |
| US9038174B2 | Cited by | United States of America | Applicant |
| US7991723B1 | Cited by | United States of America | Applicant |
| US8533824B2 | Cited by | United States of America | Applicant |
| US7545767B2 | Cited by | United States of America | Applicant |
| US7716313B2 | Cited by | United States of America | Applicant |
| US10360388B2 | Cited by | United States of America | Applicant |
| EP1728349A4 | Cited by | European Patent Office (EPO) | Search report |
| EP2140279A1 | Cited by | European Patent Office (EPO) | Search report |
| US8813221B1 | Cited by | United States of America | Applicant |
| US7684363B2 | Cited by | United States of America | Applicant |
| EP1528743A3 | Cited by | European Patent Office (EPO) | Search report |
| US10015138B2 | Cited by | United States of America | Applicant |
| EP1782197A2 | Cited by | European Patent Office (EPO) | Search report |
| US11218495B2 | Cited by | United States of America | Applicant |
| US10348748B2 | Cited by | United States of America | Applicant |
| EP1318646A1 | Cited by | European Patent Office (EPO) | Search report |
| US9582756B2 | Cited by | United States of America | Applicant |
| EP1782197A4 | Cited by | European Patent Office (EPO) | Search report |
| US9100427B2 | Cited by | United States of America | Applicant |
| US9832222B2 | Cited by | United States of America | Applicant |
| US9330264B1 | Cited by | United States of America | Applicant |
| WO2005055545A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2011058261A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10419456B2 | Cited by | United States of America | Applicant |
| US8321939B1 | Cited by | United States of America | Applicant |
| US9553883B2 | Cited by | United States of America | Applicant |
| US7761915B2 | Cited by | United States of America | Applicant |
| US10742606B2 | Cited by | United States of America | Applicant |
| WO2005055545A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10021122B2 | Cited by | United States of America | Applicant |
| EP1804457A1 | Cited by | European Patent Office (EPO) | Search report |
| US8392603B2 | Cited by | United States of America | Applicant |
| US10462164B2 | Cited by | United States of America | Applicant |
| EP1528743A2 | Cited by | European Patent Office (EPO) | Search report |
| US9729564B2 | Cited by | United States of America | Applicant |
| US9516045B2 | Cited by | United States of America | Applicant |
| US8578489B1 | Cited by | United States of America | Applicant |
| US9769149B1 | Cited by | United States of America | Applicant |
| WO2008019906A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7140041B2 | Cited by | United States of America | Applicant |
| EP2140279A4 | Cited by | European Patent Office (EPO) | Search report |
| US9729513B2 | Cited by | United States of America | Applicant |
| US8584238B1 | Cited by | United States of America | Applicant |
| US8626689B1 | Cited by | United States of America | Applicant |
| US9577983B2 | Cited by | United States of America | Applicant |
| US9462012B2 | Cited by | United States of America | Applicant |
| US8185954B2 | Cited by | United States of America | Applicant |
| US10462163B2 | Cited by | United States of America | Applicant |
| US8869283B2 | Cited by | United States of America | Applicant |
| EP1728349A2 | Cited by | European Patent Office (EPO) | Search report |
| US10686808B2 | Cited by | United States of America | Applicant |
| US9065848B2 | Cited by | United States of America | Applicant |
| US7835361B1 | Cited by | United States of America | Applicant |
| US10021121B2 | Cited by | United States of America | Applicant |
| US11475315B2 | Cited by | United States of America | Applicant |
| US11799881B2 | Cited by | United States of America | Applicant |
| US7310815B2 | Cited by | United States of America | Applicant |
| US8272057B1 | Cited by | United States of America | Applicant |
| US8863286B1 | Cited by | United States of America | Applicant |
| WO0000879A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| US6088803A | Cites | United States of America | Search report |
| WO9739399A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
8 members in 3 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 498093 | United States of America | – | |
| 49809300 | United States of America | A | |
| 49809300 | United States of America | A | |
| 498093 | – | – | – |
| US20000498093 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| EP1122932A2This record | European Patent Office (EPO) | A2 | |
| EP1122932A3 | European Patent Office (EPO) | A3 | |
| EP1122932B1 | European Patent Office (EPO) | B1 | |
| AT336131T | Austria | T | |
| ATE336131T1 | Austria | T1 | |
| DE60122033D1 | Germany | D1 | |
| DE60122033T2 | Germany | T2 | |
| DE60122033T4 | Germany | T4 |
58 legal events, as 6 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Notification of lapseLapsedST | ST | FR | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Change of name or company nameCD | CD | FR | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of representativeR082 | R082 | DE | |
| Change of representativeR082 | R082 | DE | |
| Change of representativeR082 | R082 | DE | |
| Change of representativeR082 | R082 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Fr: translation filedET | ET | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Designation fees paidAKX | AKX | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1122932
- Publication, DOCDB
- 1122932
- Publication, EPODOC
- EP1122932
- Application
- 1102150
- Application, DOCDB
- 01102150
- Application, EPODOC
- EP20010102150
Titles3
- German
- Schutz von Computernetzen gegen böswillig versandte Inhalte
- English
- Protection of computer networks against malicious content
- French
- Protection de réseaux d'ordinateurs contre des contenus malintentionnés
Classification
- CPC, 3
- H04L63/20
- H04L63/08
- H04L63/14
- IPC, 1
- H04L29 06
Designated states26
- Contracting states, 20
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Türkiye
- Extension states, 6
- Albania
- Lithuania
- Latvia
- North Macedonia
- Romania
- Slovenia