The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 22, 2022

Filed:

May. 03, 2019
Applicant:

Nicira, Inc., Palo Alto, CA (US);

Inventors:

Vasantha Kumar, Tamil Nadu, IN;

Prasad Sharad Dabak, Pune, IN;

Azeem Feroz, San Jose, CA (US);

Amit Vasant Patil, Pune, IN;

Assignee:

NICIRA, INC., Palo Alto, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 9/455 (2018.01); G06F 21/53 (2013.01); G06F 21/62 (2013.01);
U.S. Cl.
CPC ...
G06F 9/45558 (2013.01); G06F 21/53 (2013.01); G06F 21/629 (2013.01); H04L 63/0227 (2013.01); H04L 63/102 (2013.01); H04L 63/20 (2013.01); G06F 2009/45587 (2013.01); G06F 2009/45595 (2013.01); G06F 2221/2105 (2013.01); G06F 2221/2117 (2013.01); G06F 2221/2141 (2013.01); H04L 63/104 (2013.01);
Abstract

Some embodiments provide a novel method for authorizing network requests for a machine in a network. In some embodiments, the method is performed by security agents that execute on virtual machines operating on a host machine. In some embodiments, the method captures a network request (e.g., network control packets, socket connection request, etc.) from a primary application executing on the machine. The method identifies an extended context for the network request and determines whether the network request is authorized based on the extended context. The method then processes the network request according to the determination. The extended context of some embodiments includes identifications for primary and secondary applications associated with the network request. Alternatively, or conjunctively, some embodiments include identifications for primary and secondary users associated with the network request.


Find Patent Forward Citations

Loading…