Invention Grant
- Patent Title: Virtual patching in a label-based segmented network environment
-
Application No.: US16553137Application Date: 2019-08-27
-
Publication No.: US11516242B2Publication Date: 2022-11-29
- Inventor: Rupesh Kumar Mishra , Pritesh Kothari
- Applicant: Illumio, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Illumio, Inc.
- Current Assignee: Illumio, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Fenwick & West LLP
- Main IPC: G06F17/00
- IPC: G06F17/00 ; H04L9/40 ; H04L47/20 ; G06F8/65 ; H04L67/561 ; H04L67/563

Abstract:
A segmentation server configures and distributes rules for enforcing a segmentation policy that includes one or more virtual patches. The rules including the virtual patches are enforced by distributed enforcement modules that may execute on host devices or on network devices upstream from the host devices. An enforcement module enforces the rules using traffic filters that filter traffic based on network layer data. To implement a virtual patch, the traffic filters are configured to redirect traffic to or from an application being patched to a transparent application proxy. The transparent application proxy implements an application layer filter that filters traffic based on application layer data to block specific types of traffic associated with a vulnerability addressed by the virtual patch.
Public/Granted literature
- US20210067538A1 Virtual Patching In A Label-Based Segmented Network Environment Public/Granted day:2021-03-04
Information query