Patents Assigned to VARMOUR NETWORKS, INC.
-
Patent number: 10333827Abstract: A network system includes a first network access device having an input/output (IO) module of a firewall to capture a packet of a network session originated from a first node associated with the first network access device, a first security device having a firewall processing module to determine based on the captured packet whether the first node is a destination node that is receiving VM migration from a second node that is associated with a second network access device. The first security device is to update a first flow table within the first network access device. The network system further includes a second security device to receive a message from the first security device concerning the VM migration to update a second flow table of the second network access device, such that further network traffic of the network session is routed to the first node without interrupting the network session.Type: GrantFiled: April 10, 2013Date of Patent: June 25, 2019Assignee: VARMOUR NETWORKS, INC.Inventors: Meng Xu, Yi Sun, Hsisheng Wang, Choung-Yaw Shieh
-
Patent number: 9742732Abstract: A method and apparatus is disclosed herein for TCP SYN flood protection. In one embodiment, a TCP SYN flood protection arrangement comprises a first device operable to process packet input and output functions, including performing sender verification with respect to a connection initiation from a sender for a first TCP connection between the sender and a destination server and a second device, separate from the first device, to perform one or more security processing operations on packets of the first TCP connection from the sender after the first device verifies the sender is legitimate.Type: GrantFiled: March 11, 2013Date of Patent: August 22, 2017Assignee: VARMOUR NETWORKS, INC.Inventors: Yi Sun, Meng Xu, Lee Cheung, Choung-Yaw Michael Shieh
-
Patent number: 9621568Abstract: A method and apparatus for distributed threat detection in a computer network is described. The method may include receiving, by a threat detection system of a first computer network, a request for a service from a threat sensor of a second computer network, the service requested of the threat sensor within the second computer network from a network element of the second computer network. The method may also include emulating the service identified in the request to generate a response to the request, and sending the response to the threat sensor for forwarding to the network element within the second computer network. Furthermore, the method may include analyzing one or more communications between the threat detection system and the network element during emulation of the service requested by the network element to determine whether the network element is a threat to the second network.Type: GrantFiled: September 8, 2014Date of Patent: April 11, 2017Assignee: VARMOUR NETWORKS, INC.Inventor: Choung-Yaw Michael Shieh
-
Patent number: 9529995Abstract: A method and apparatus is disclosed herein for performing auto discovery of virtual machines. In one embodiment, the method includes monitoring, using an interface of the device, one or more packets being sent from one or more virtual machines, the one or more packets being sent determining, using a processor of the device, if one of the monitored packets includes a discovery packet from one virtual machine of the one or more virtual machines, wherein the discovery packet includes an address of a destination location; sending, using the interface of the device, a reply packet to the one virtual machine using an address in the discovery packet identified in the monitored packets, the reply packet including an Internet Protocol (IP) address of the device.Type: GrantFiled: November 8, 2011Date of Patent: December 27, 2016Assignee: VARMOUR NETWORKS, INC.Inventor: Choung-Yaw Michael Shieh
-
Patent number: 9419941Abstract: A method and apparatus is disclosed herein for distributed zone-based security. In one embodiment, the method comprises: determining an ingress security zone associated with an ingress of a first network device based on a first key and a media access control (MAC) address of a source of a packet; determining an egress security zone of a second network device based on a MAC address of a destination for the packet and a second key; performing a policy lookup based on the ingress security zone and the egress security zone to identify a policy to apply to the packet; and applying the policy to the packet.Type: GrantFiled: March 22, 2013Date of Patent: August 16, 2016Assignee: VARMOUR NETWORKS, INC.Inventors: Yi Sun, Meng Xu, Lee Cheung, Hsisheng Wang, Chuong-Yaw Michael Shieh
-
Patent number: 9294302Abstract: A method and apparatus is disclosed herein for IP packet tunneling in a network. In one embodiment, the method comprises receiving, at a first network device, a first IP packet of a IP connection; creating a second IP packet by replacing information in a field in the first IP packet with a session ID identifying the IP connection; and forwarding, by the first network device, the second IP packet to the second network device in the distributed network environment.Type: GrantFiled: March 20, 2013Date of Patent: March 22, 2016Assignee: VARMOUR NETWORKS, INC.Inventors: Yi Sun, Meng Xu, Choung-Yaw Michael Shieh
-
Patent number: 9258275Abstract: A method and apparatus for dynamic security insertion into virtualized networks is described. The method may include receiving, at a network device from a second network device, a data packet and application data extracted from the data packet. The method may also include generating a routing decision for a network connection associated with the data packet based, at least in part, on the application data. Furthermore, the method may include transmitting the routing decision for the data packet to the second device for the second device to route the data based on the routing decision.Type: GrantFiled: April 11, 2013Date of Patent: February 9, 2016Assignee: VARMOUR NETWORKS, INC.Inventors: Yi Sun, Meng Xu, Jia-Jyi Roger Lian, Choung-Yaw Michael Shieh
-
Patent number: 9191327Abstract: A network gateway device includes an ingress interface, an egress interface, and a load balancing module coupled to the ingress and egress interfaces. The load balancing module configured to receive a packet from the ingress interface, determine a set of a plurality of processes corresponding a connections session associated with the packet based on a policy. For each of the identified processes, the load balancing module is to identify a service processing module executed by a virtual machine that is capable of handling the identified process, and to send the packet to the identified service processing module to perform the identified process on the packet. The packet is then transmitted to the egress interface of the gateway device to be forwarded to a destination.Type: GrantFiled: January 31, 2012Date of Patent: November 17, 2015Assignee: VARMOUR NETWORKS, INC.Inventor: Choung-Yaw Michael Shieh
-
Publication number: 20130091264Abstract: A method and apparatus is disclosed herein for migrating session information between security gateways are disclosed. In one embodiment, receiving, at a first security gateway, session information associated with a session corresponding to a network connection, the session information having been transferred from a second security gateway, the first and second security gateway being separate physical devices; and thereafter performing security processing for the session at the first security gateway.Type: ApplicationFiled: October 4, 2012Publication date: April 11, 2013Applicant: VARMOUR NETWORKS, INC.Inventor: vArmour Networks, Inc.