Abstract: Systems and methods for managing forwarded infectious messages are provided. Managing electronic message comprises receiving a message, forwarding the message, determining that the forwarded message is infectious after the message has been forwarded and preventing the infectious forwarded message from spreading.
Abstract: A hardware or software firewall may be installed within a private network. The firewall may intercept a first set of login credentials entered into a login interface of a social media platform. The firewall then checks that the first set of login credentials are correct against a first set of reference login credentials stored in a firewall memory, and sends a second set of login credentials to the login interface of the social media platform. This allows business employees to access a corporate social media profile from a private network but not outside the private network. The firewall can also limit social media interactions using the firewall by limiting the other profiles that a user's profile can interact with (e.g., using a whitelist, blacklist, or reputation score), by limiting communication types (e.g., using a whitelist or blacklist), by imposing firewall policies, or some combination thereof.
Abstract: A system and method are disclosed for classifying a message. The method includes receiving the message, identifying in the message a distinguishing property; generating a signature using the distinguishing property; and comparing the signature to a database of signatures generated by previously classified messages.
Type:
Grant
Filed:
December 20, 2016
Date of Patent:
August 7, 2018
Assignee:
SonicWALL Inc.
Inventors:
Brian K. Wilson, David A. Koblas, Arno A. Penzias
Abstract: A method and apparatus for centralized policy programming and distributive policy enforcement is described. A method comprises centrally maintaining a plurality of policy definitions for one or more subscribers, generating policy configurations using the plurality of policy definitions, each of the policy configurations being specific to one of the plurality of policy definitions, and disseminating the policy configurations to the appropriate ones of the subscribers' networks.
Abstract: A system and method are disclosed for improving a statistical message classifier. A message may be tested with a machine classifier, wherein the machine classifier is capable of making a classification on the message. In the event the message is classifiable by the machine classifier, the statistical message classifier is updated according to the reliable classification made by the machine classifier. The message may also be tested with a first classifier. In the event that the message is not classifiable by the first classifier, it is tested with a second classifier, wherein the second classifier is capable of making a second classification. In the event that the message is classifiable by the second classifier, the statistical message classifier is updated according to the second classification.
Type:
Grant
Filed:
June 3, 2016
Date of Patent:
August 7, 2018
Assignee:
SonicWALL Inc.
Inventors:
Jonathan J. Oliver, Scott Roy, Scott D. Eikenberry, Bryan Kim, David A. Koblas, Brian K. Wilson
Abstract: Methods and systems are provided for detecting dead tunnels associated with a VPN. An indicator of a tunnel capability, for example, a DPD vendor ID, is received from a peer through a VPN connection. The tunnel capability is associated with one or more phase II tunnels associated with the VPN. Traffic generated by the peer is detected, and if traffic is detected at a tunnel, the tunnel is presumed to be alive. When no traffic is detected in a tunnel, a DPD packet exchange with the tunnel is initiated. A determination is made, based on the packet exchange, whether the tunnel is alive.
Type:
Grant
Filed:
June 26, 2017
Date of Patent:
August 7, 2018
Assignee:
SonicWALL Inc.
Inventors:
Zhong Chen, Aravind Thangavelu, Dong Xiang, Yanjun Yang
Abstract: A method and an apparatus request web pages and content rating information thereof have been disclosed. In one embodiment, the method includes receiving a request from a user for a web page, retrieving content rating of the web page in response to the request, and fetching the web page substantially simultaneously with the retrieving of the content rating in response to the request. Other embodiments have been claimed and described.
Type:
Grant
Filed:
July 14, 2016
Date of Patent:
July 24, 2018
Assignee:
SonicWALL Inc.
Inventors:
John E. Gmuender, Alex M. Dubrovsky, Nikolay V. Popov, Alexander Shor, Roman Yanovsky, Shunhui Zhu, Boris Yanovsky
Abstract: Systems and methods for processing a message are provided. A message may be processed to generate a message summary by removing or replacing certain words, phrases, sentences, punctuation, and the like. Message signatures based upon the message summary may be generated and stored in a signature database, which may be used to identify and/or classify spam messages. Subsequently received messages may be classified by signature and processed based on classification.
Type:
Grant
Filed:
March 18, 2016
Date of Patent:
July 17, 2018
Assignee:
SonicWALL Inc.
Inventors:
Jonathan J. Oliver, David A. Koblas, Brian K. Wilson
Abstract: Techniques for notification of reassembly-free file scanning are described herein. According to one embodiment, a first request for accessing a document provided by a remote node is received from a client. In response to the first request, it is determined whether a second request previously for accessing the document of the remote node indicates that the requested document from the remote node contains offensive data. If the requested document contains offensive data, a message is returned to the client, without accessing the requested document of the remote node, indicating that the requested document is not delivered to the client.
Type:
Grant
Filed:
October 4, 2016
Date of Patent:
July 10, 2018
Assignee:
SonicWALL Inc.
Inventors:
Aleksandr Dubrovsky, Igor Korsunsky, Roman Yanovsky, Boris Yanovsky
Abstract: A method and an apparatus to perform multiple packet payload analysis have been disclosed. In one embodiment, the method includes receiving a plurality of data packets, each of the plurality of data packets containing a portion of a data pattern, determining whether each of the plurality of data packets is out of order, and making and storing a local copy of the corresponding data packet if the corresponding data packet is out of order. Other embodiments have been claimed and described.
Type:
Grant
Filed:
January 24, 2017
Date of Patent:
July 10, 2018
Assignee:
SonicWALL Inc.
Inventors:
Aleksandr Dubrovsky, Roman Yanovsky, Scott Aaron More, Boris Yanovsky
Abstract: Systems and methods for management of persistent cookies in a corporate web portal are described. A plurality of zones may be defined and stored in memory. Each zone may be associated with a zone property indicative of whether cookies are allowed. A resource request may be received from a user device over a network where access to the requested resource may require a cookie. The user device may be classified into a zone from the plurality of zones based on the attributes of the user device. The cookie may be automatically installed on the user device based on a zone property for the zone and for those resources that have been configured to require installation of a cookie installed without requiring further user interaction following the request.
Type:
Grant
Filed:
January 8, 2016
Date of Patent:
July 10, 2018
Assignee:
SonicWALL Inc.
Inventors:
Christopher D. Peterson, Jeetendra Kulkarni
Abstract: Systems and methods are directed towards network data leakage prevention (DLP). More specifically, the systems and methods are directed towards using TCP (Transmission Control Protocol) data packets in conjunction with the DLP monitor. The network DLP utilizes TCP data packets to carry source user identity. With the source user identity, the DLP monitor can determine if sensitive data can be transmitted based on the provided user information and corresponding DLP policies for each user. Furthermore, the DLP monitor can determine if sensitive data can also be transmitted for particular users in situations where multiple users share the same IP address.
Abstract: A method and apparatus for identifying data patterns of a file are described herein. In one embodiment, an exemplary process includes, but is not limited to, receiving a data packet of a data stream containing a file segment of a file originated from an external host and destined to a protected host of a local area network (LAN), the file being transmitted via multiple file segments contained in multiple data packets of the data stream, and performing a data pattern analysis on the received data packet to determine whether the received data packet contains a predetermined data pattern, without waiting for a remainder of the data stream to arrive. Other methods and apparatuses are also described.
Type:
Grant
Filed:
February 17, 2017
Date of Patent:
July 3, 2018
Assignee:
SonicWALL Inc.
Inventors:
Aleksandr Dubrovsky, John Everett Gmuender, Boris Yanovsky, Roman Yanovsky, Shunhui Zhu
Abstract: Techniques for determining which resource access requests are handled locally at a remote computer, and which resource access requests are routed or “redirected” through a virtual private network. One or more routing or “redirection” rules are downloaded from a redirection rule server to a remote computer. When the node of the virtual private network running on the remote computer receives a resource access request, it compares the identified resource with the rules. Based upon how the identified resource matches one or more rules, the node will determine whether the resource access request is redirected through the virtual private network or handled locally (e.g., retrieved locally from another network). A single set of redirection rules can be distributed to and employed by a variety of different virtual private network communication techniques.
Type:
Grant
Filed:
June 13, 2016
Date of Patent:
June 19, 2018
Assignee:
SONICWALL INC.
Inventors:
Chris Hopen, Bryan Sauve, Paul Hoover, Bill Perry
Abstract: The present invention provides the initiation of a transport layer security (TLS) session between a client device and a server using a firewall without interruption. The present invention holds a TLS hello message received from the client device until after the server has been validated. A firewall consistent with the present invention does not interrupt a transport layer control (TCP) connection that was established between the client device and the firewall before the TLS hello message was received by the firewall.
Type:
Grant
Filed:
January 27, 2015
Date of Patent:
June 12, 2018
Assignee:
SonicWALL Inc.
Inventors:
Raj Raman, Alex Dubrovsky, Akbal Singh Karlcut
Abstract: The present disclosure relates to an apparatus, a method, and a non-transitory computer readable storage medium for filtering routing assignment (RA) messages in a computer network. Methods, non-transitory computer readable storage medium, and apparatus consistent with the present disclosure may receive an RA message, extract information included in an RA message when identifying whether that particular RA messages should be forwarded or blocked. Information used to identify when to forward or block particular RA messages may be related to information that identifies a user of a computer or that identifies a computer that sends RA messages over a computer network.
Abstract: Disclosed in the authentication and authorization of a client device to access a plurality of resources, requiring a user of a client device to enter only one set of login information. Authentication and authorization of a client device to access a plurality of resources after an initial set of login information is received by a networked computing environment. After the initial set of login information is received, a series of steps are performed that may be entirely transparent to the user of the client device.
Type:
Grant
Filed:
October 11, 2016
Date of Patent:
May 15, 2018
Assignee:
SONICWALL INC.
Inventors:
Xiao Yu Huang, Zhong Chen, Yi Fei Hu, Riji Cai
Abstract: A transparent batch file transfer is provided from a client to a server via a batch pool system. The batch pool system may be implemented by a proxy file server which is used to receive the file transfer from the client device and free the client device as soon as possible. The file transfer to an intended remote server is carried out by a batch transfer system at the proxy file server. The user of the client machine may then use their device to perform other tasks while the file transfer is completed by the proxy file server batch transfer system. The file transfer is coordinated by a background transfer module that is integrated with file system protocols. Hence, there is no new system or software for a user of the client to learn or operate.
Abstract: Systems and methods are directed towards generating a verified unique watermark. More specifically, the systems and methods are directed towards generating a watermark that is as long as possible without any repetition. Such watermarks are possible by selecting characteristics of the watermark and methods for producing the watermarks (e.g., dandy rollers). By producing longer unique watermarks, users would be capable of generating longer rolls of paper whereby more sheets can be produced that each possesses a unique watermark. With the unique watermark, users can identify what information is printed on each sheet as well as authenticate the contents of each individual sheet.
Abstract: An extension is provided to the SEND protocol without requiring a CGA or third party trust anchor. A shared key is provided to both a sender and receiver of a neighbor discovery (ND) message. A digital signature option is contained in the ND message. A digital signature field is determined by the algorithm field in the option. When the ND message is received, the receiver may verify the digital signature field using the pre-shared key according to the algorithm field. If the ND message passes verification, the receiver may process the message.
Type:
Grant
Filed:
August 23, 2017
Date of Patent:
March 6, 2018
Assignee:
SONICWALL INC.
Inventors:
Yun Feng Liu, Zhong Chen, Eric Xiang, Yanjun Yang