Systems and methods for updating content detection devices and systems

US9231968B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9231968-B2
Application numberUS-201314072184-A
CountryUS
Kind codeB2
Filing dateNov 5, 2013
Priority dateMar 12, 2004
Publication dateJan 5, 2016
Grant dateJan 5, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems, methods, and software for processing received network traffic content in view of content detection data and configuration data to either block, permit, or to further evaluate network traffic content when entering a network.

First claim

Opening claim text (preview).

What is claimed is: 1. A network gateway device comprising: at least one processor; at least one memory device; at least one network interface device; content detection and configuration data stored on the at least one memory device; and an instruction set, stored in the at least one memory device and executable by the at least one processor to: receive network traffic via the at least one network interface device; process the received network traffic in view of the content detection and configuration data stored in the at least one memory device to enforce policies defined at least in part by the content detection and configuration data and including at least one policy that defines a suspicious category of network traffic, the policy enforcement performed to determine whether to allow the received network traffic to pass, the policy enforcement including user identification, content identification, and at least one of source verification and destination verification, wherein when network traffic is determined to violate the at least one policy defining suspicious network traffic, forwarding the network traffic to an analysis process that will perform analysis on network traffic to determine whether the network traffic contains a threat desired to be detected and, when the network traffic is determined to contain a threat desired to be detected, the analysis process generates additional content detection data to detect the threat in subsequently received network traffic; receive, via the network interface device, the additional content detection data indirectly from the analysis process via an update station; store the additional content detection data on the at least one memory device; process subsequently received network traffic in view of the additional content detection data; block network traffic determined to violate at least one policy; and allow network traffic to pass that does not violate a policy. 2. The network gateway device of claim 1 , wherein the analysis process, to which the network traffic content is forwarded, executes on a computing device distinct from the network gateway device. 3. The network gateway device of claim 2 , wherein the analysis process facilitates an analysis that includes receiving administrator input. 4. A method comprising: receiving network traffic via at least one network interface device; processing the received network traffic, by executing instructions on at least one processor of a data network device, in view of content detection and configuration data stored on at least one memory device to enforce policies defined at least in part by the content detection and configuration data and including at least one policy that defines a suspicious category of network traffic, the policy enforcement performed to determine whether to allow the received network traffic to pass on a data network, the policy enforcement including user identification, content identification, and at least one of source verification and destination verification; when network traffic is determined to violate the at least one policy defining suspicious network traffic, forwarding the network traffic to an analysis process that will perform analysis on network traffic to determine whether the network traffic contains a threat desired to be detected and, when the network traffic is determined to contain a threat desired to be detected, the analysis process generates additional content detection data to detect the threat in subsequently received network traffic; receiving, via the at least one network interface device, the additional content detection data indirectly from the analysis process via an update station; storing the additional content detection data on the at least one memory device; processing subsequently received network traffic in view of the additional content detection data; blocking network traffic determined to violate at least one policy; and allowing network traffic to pass on the data network that does not violate a policy. 5. The method of claim 4 , wherein the analysis process, to which the network traffic content is forwarded, executes on a computing device distinct from the data network device. 6. The method of claim 5 , wherein the analysis process facilitates an analysis that includes receiving administrator input. 7. A non-transitory computer-readable medium with instructions stored thereon which when executed by at least one processor of a data network device, causes the data network device to: receive network traffic via at least one network interface device; process the received network traffic in view of content detection and configuration data stored on at least one memory device to enforce policies defined at least in part by the content detection and configuration data and including at least one policy that defines a suspicious category of network traffic, the policy enforcement performed to determine whether to allow the received network traffic to pass on a data network, the policy enforcement including user identification, content identification, and at least one of source verification and destination verification; when network traffic is determined to violate the at least one policy defining suspicious network traffic, forward the network traffic to an analysis process that will perform analysis on network traffic to determine whether the network traffic contains a threat desired to be detected and, when the network traffic is determined to contain a threat desired to be detected, the analysis process generates additional content detection data to detect the threat in subsequently received network traffic; receive, via the at least one network interface device, the additional content detection data indirectly from the analysis process via an update station; store the additional content detection data on the at least one memory device; process subsequently received network traffic in view of the additional content detection data; block network traffic determined to violate at least one policy; and allowing network traffic to pass on the data network that does not violate a policy. 8. The non-transitory computer-readable medium of claim 7 , wherein the analysis process, to which the network traffic content is forwarded, executes on a computing device distinct from the data network device. 9. The non-transitory computer-readable medium of claim 8 , wherein the analysis process facilitates an analysis that includes receiving administrator input.

Assignees

Inventors

Classifications

  • using dedicated hardware · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9231968B2 cover?
Systems, methods, and software for processing received network traffic content in view of content detection data and configuration data to either block, permit, or to further evaluate network traffic content when entering a network.
Who is the assignee on this patent?
Fortinet Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 05 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).