Invention Grant
- Patent Title: Methods for effective network-security inspection in virtualized environments
-
Application No.: US12507830Application Date: 2009-07-23
-
Publication No.: US09672189B2Publication Date: 2017-06-06
- Inventor: Ofer Raz , Amnon Perlmutter , Erez Berkner
- Applicant: Ofer Raz , Amnon Perlmutter , Erez Berkner
- Applicant Address: IL Tel Aviv
- Assignee: CHECK POINT SOFTWARE TECHNOLOGIES, LTD.
- Current Assignee: CHECK POINT SOFTWARE TECHNOLOGIES, LTD.
- Current Assignee Address: IL Tel Aviv
- Agent Mark M. Friedman
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F17/00 ; G06F21/60 ; H04L29/06 ; G06F15/16 ; G06F11/00

Abstract:
The present invention discloses methods for effective network-security inspection in virtualized environments, the methods including the steps of: providing a data packet, embodied in machine-readable signals, being sent from a sending virtual machine to a receiving virtual machine via a virtual switch; intercepting the data packet by a sending security agent associated with the sending virtual machine; injecting the data packet into an inspecting security agent associated with a security virtual machine via a direct transmission channel which bypasses the virtual switch; forwarding the data packet to the security virtual machine by employing a packet-forwarding mechanism; determining, by the security virtual machine, whether the data packet is allowed for transmission; upon determining the data packet is allowed, injecting the data packet back into the sending security agent via the direct transmission channel; and forwarding the data packet to the receiving virtual machine via the virtual switch.
Public/Granted literature
- US20100269171A1 METHODS FOR EFFECTIVE NETWORK-SECURITY INSPECTION IN VIRTUALIZED ENVIRONMENTS Public/Granted day:2010-10-21
Information query