Patents by Inventor Kenneth E. Mulh

Kenneth E. Mulh has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8146137
    Abstract: In embodiments of the present invention, improved capabilities are described for a method presenting a client, providing client information and requesting an IP address from a DHCP server, where the DHCP server may formulate a first IP assignment and a first multiple DHCP options. A policy management facility may be associated with the interception of the first IP assignment and the first multiple DHCP options, which may result in the first IP assignment and the first multiple DHCP options not being sent to the client. The method may send client information to the policy management facility. The policy management facility may formulate a second multiple DHCP options and may send it to the DHCP server. The DHCP server may change first IP assignment and first multiple DHCP option to a second IP assignment and the second multiple DHCP options. The second IP assignment and the second multiple DHCP options may then be forwarded to the client.
    Type: Grant
    Filed: May 31, 2011
    Date of Patent: March 27, 2012
    Assignee: Sophos PLC
    Inventors: Bradley A. C. Manring, Kenneth E. Mulh
  • Publication number: 20110231534
    Abstract: In embodiments of the present invention, improved capabilities are described for a method presenting a client, providing client information and requesting an IP address from a DHCP server, where the DHCP server may formulate a first IP assignment and a first multiple DHCP options. A policy management facility may be associated with the interception of the first IP assignment and the first multiple DHCP options, which may result in the first IP assignment and the first multiple DHCP options not being sent to the client. The method may send client information to the policy management facility. The policy management facility may formulate a second multiple DHCP options and may send it to the DHCP server. The DHCP server may change first IP assignment and first multiple DHCP option to a second IP assignment and the second multiple DHCP options. The second IP assignment and the second multiple DHCP options may then be forwarded to the client.
    Type: Application
    Filed: May 31, 2011
    Publication date: September 22, 2011
    Inventors: Bradley A.C. Manring, Kenneth E. Mulh
  • Patent number: 7966650
    Abstract: In embodiments of the present invention, improved capabilities are described for a method presenting a client, providing client information and requesting an IP address from a DHCP server, where the DHCP server may formulate a first IP assignment and a first multiple DHCP options. A policy management facility may be associated with the interception of the first IP assignment and the first multiple DHCP options, which may result in the first IP assignment and the first multiple DHCP options not being sent to the client. The method may send client information to the policy management facility. The policy management facility may formulate a second multiple DHCP options and may send it to the DHCP server. The DHCP server may change first IP assignment and first multiple DHCP option to a second IP assignment and the second multiple DHCP options. The second IP assignment and the second multiple DHCP options may then be forwarded to the client.
    Type: Grant
    Filed: February 22, 2008
    Date of Patent: June 21, 2011
    Assignee: Sophos PLC
    Inventors: Bradley A. C. Manring, Kenneth E. Mulh
  • Patent number: 7882152
    Abstract: User interface and policy loading aspects of a policy-based, outsourced, network management system. In one aspect, a user selects policies using a graphical user interface (GUI) with a two paned window having a tree view of the policies in one pane. In another aspect, the policies are (1) created in the GUI format (e.g., XML), (2) sent over a network (e.g., the internet) to a service center in the same format, and (3) are loaded, manipulated and stored in the same format. In another aspect, the initial loading of the policies is done using a bulk loader in a logic layer. In another aspect, the logic layer also includes a configuration checker which handles changes or additions to policies in a finished network management system. Any aspects of the new or changed policy that are inconsistent with the finished system are parsed and stripped out. In another aspect, where the details of a new policy or change aren't specified, a base configuration creator creates a policy with minimal attributes.
    Type: Grant
    Filed: September 19, 2006
    Date of Patent: February 1, 2011
    Assignee: Sophos PLC
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell
  • Patent number: 7840599
    Abstract: User interface and policy loading aspects of a policy-based, outsourced, network management system. In one aspect, a user selects policies using a graphical user interface (GUI) with a two paned window having a tree view of the policies in one pane. In another aspect, the policies are (1) created in the GUI format (e.g., XML), (2) sent over a network (e.g., the internet) to a service center in the same format, and (3) are loaded, manipulated and stored in the same format. In another aspect, the initial loading of the policies is done using a bulk loader in a logic layer. In another aspect, the logic layer also includes a configuration checker which handles changes or additions to policies in a finished network management system. Any aspects of the new or changed policy that are inconsistent with the finished system are parsed and stripped out. In another aspect, where the details of a new policy or change aren't specified, a base configuration creator creates a policy with minimal attributes.
    Type: Grant
    Filed: September 19, 2006
    Date of Patent: November 23, 2010
    Assignee: Sophos PLC
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell
  • Publication number: 20090217350
    Abstract: In embodiments of the present invention, improved capabilities are described for a method presenting a client, providing client information and requesting an IP address from a DHCP server, where the DHCP server may formulate a first IP assignment and a first multiple DHCP options. A policy management facility may be associated with the interception of the first IP assignment and the first multiple DHCP options, which may result in the first IP assignment and the first multiple DHCP options not being sent to the client. The method may send client information to the policy management facility. The policy management facility may formulate a second multiple DHCP options and may send it to the DHCP server. The DHCP server may change first IP assignment and first multiple DHCP option to a second IP assignment and the second multiple DHCP options. The second IP assignment and the second multiple DHCP options may then be forwarded to the client.
    Type: Application
    Filed: February 22, 2008
    Publication date: August 27, 2009
    Inventors: Bradley A.C. Manning, Kenneth E. Mulh
  • Publication number: 20090217346
    Abstract: In embodiments of the present invention improved capabilities are described for the computer program product steps of serving a limited network connection to an endpoint computing facility via network device access control lists, where the limited network connection may enable the endpoint to communicate with a limited set of network resources; assessing security compliance information relating to the endpoint to determine a security state; and in response to receiving an indication that the security compliance information is acceptable, serving a managed network connection to the endpoint, where the managed connection may enable the endpoint to communicate with a larger set of network resources than the limited network connection.
    Type: Application
    Filed: March 23, 2009
    Publication date: August 27, 2009
    Inventors: Bradley A.C. Manring, Kenneth E. Mulh
  • Patent number: 7284042
    Abstract: The present invention provides device configuration and policy configuration data to network devices over a public network, e.g., the internet. A secure communication link is first established over the public network to the network device. Next, policy and configuration information is downloaded to the network device using that secure communication link. In one embodiment, the communication link is an IPSec tunnel. In particular, the network policy may include a virtual private network (VPN) policy. The invention addresses the secure downloading of configuration and policy information, which has not been an issue in prior art devices where there was an ability to provide such information internally to a network, without the need to go over the internet.
    Type: Grant
    Filed: August 13, 2002
    Date of Patent: October 16, 2007
    Assignee: Endforce, Inc.
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell
  • Patent number: 7159125
    Abstract: A policy engine in a policy-based, outsourced, network management system. In one embodiment, the management system is multi-layered, modular and stores device configuration data in non-device specific format, which are subsequently translated to device-specific format by lower layers of the management system. The non-device specific format is the same (e.g., XML) as that used to create the policies with the user GUI (e.g., browser) and transport them to the service center over the internet. A database stores a policy directory in a hierarchical format that is separate from a policy store (configuration store) for devices in a flat (non-hierarchical or parallel) format. In one embodiment, a policy engine develops policies in a hierarchical format, but then stores the device schema, or objects, in a low-level, flat database.
    Type: Grant
    Filed: August 13, 2002
    Date of Patent: January 2, 2007
    Assignee: Endforce, Inc.
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell
  • Patent number: 7130854
    Abstract: User interface and policy loading aspects of a policy-based, outsourced, network management system. In one aspect, a user selects policies using a graphical user interface (GUI) with a two paned window having a tree view of the policies in one pane. In another aspect, the policies are (1) created in the GUI format (e.g., XML), (2) sent over a network (e.g., the internet) to a service center in the same format, and (3) are loaded, manipulated and stored in the same format. In another aspect, the initial loading of the policies is done using a bulk loader in a logic layer. In another aspect, the logic layer also includes a configuration checker which handles changes or additions to policies in a finished network management system. Any aspects of the new or changed policy that are inconsistent with the finished system are parsed and stripped out. In another aspect, where the details of a new policy or change aren't specified, a base configuration creator creates a policy with minimal attributes.
    Type: Grant
    Filed: August 13, 2002
    Date of Patent: October 31, 2006
    Assignee: Endforce, Inc.
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell
  • Publication number: 20030154404
    Abstract: A policy engine in a policy-based, outsourced, network management system. In one embodiment, the management system is multi-layered, modular and stores device configuration data in non-device specific format, which are subsequently translated to device-specific format by lower layers of the management system. The non-device specific format is the same (e.g., XML) as that used to create the policies with the user GUI (e.g., browser) and transport them to the service center over the internet. A database stores a policy directory in a hierarchical format that is separate from a policy store (configuration store) for devices in a flat (non-hierarchical or parallel) format. In one embodiment, a policy engine develops policies in a hierarchical format, but then stores the device schema, or objects, in a low-level, flat database.
    Type: Application
    Filed: August 13, 2002
    Publication date: August 14, 2003
    Applicant: Smartpipes, Incorporated
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell
  • Publication number: 20030041139
    Abstract: An event manager for a remote network management system. The event manager provides dynamic response for the purposes of controlling policy updates, generation and deployment. Dynamic events are used to communicate the fact that policy changes/updates/creations have occurred. In prior art systems, a user would simply make a data update, and then the system would retrieve the latest data from the data storage synchronously.
    Type: Application
    Filed: August 13, 2002
    Publication date: February 27, 2003
    Applicant: Smartpipes, Incorporated
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell
  • Publication number: 20030037128
    Abstract: The present invention provides device configuration and policy configuration data to network devices over a public network, e.g., the internet. A secure communication link is first established over the public network to the network device. Next, policy and configuration information is downloaded to the network device using that secure communication link. In one embodiment, the communication link is an IPSec tunnel. In particular, the network policy may include a virtual private network (VPN) policy. The invention addresses the secure downloading of configuration and policy information, which has not been an issue in prior art devices where there was an ability to provide such information internally to a network, without the need to go over the internet.
    Type: Application
    Filed: August 13, 2002
    Publication date: February 20, 2003
    Applicant: Smartpipes, Incorporated
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell
  • Publication number: 20030037129
    Abstract: A modular remote network management system which can configure a customer's network over the internet. A first module receives customer descriptions of desired customer network policy configurations. Another module automatically translates that description into device-level policy configuration data. Finally, a third module transmits the device-level policy configuration data over the internet to the devices of the customer network.
    Type: Application
    Filed: August 13, 2002
    Publication date: February 20, 2003
    Applicant: Smartpipes, Incorporated
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell
  • Publication number: 20030037040
    Abstract: User interface and policy loading aspects of a policy-based, outsourced, network management system. In one aspect, a user selects policies using a graphical user interface (GUI) with a two paned window having a tree view of the policies in one pane. In another aspect, the policies are (1) created in the GUI format (e.g., XML), (2) sent over a network (e.g., the internet) to a service center in the same format, and (3) are loaded, manipulated and stored in the same format. In another aspect, the initial loading of the policies is done using a bulk loader in a logic layer. In another aspect, the logic layer also includes a configuration checker which handles changes or additions to policies in a finished network management system. Any aspects of the new or changed policy that are inconsistent with the finished system are parsed and stripped out. In another aspect, where the details of a new policy or change aren't specified, a base configuration creator creates a policy with minimal attributes.
    Type: Application
    Filed: August 13, 2002
    Publication date: February 20, 2003
    Applicant: Smartpipes, Incorporated
    Inventors: Mark A. Beadles, William S. Emerick, Kevin A. Russo, Kenneth E. Mulh, Raymond J. Bell