The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 06, 2017

Filed:

Jul. 23, 2009
Applicants:

Ofer Raz, Ramat Gan, IL;

Amnon Perlmutter, Givataim, IL;

Erez Berkner, Tel Aviv, IL;

Inventors:

Ofer Raz, Ramat Gan, IL;

Amnon Perlmutter, Givataim, IL;

Erez Berkner, Tel Aviv, IL;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 17/00 (2006.01); G06F 21/60 (2013.01); H04L 29/06 (2006.01); G06F 15/16 (2006.01); G06F 11/00 (2006.01);
U.S. Cl.
CPC ...
G06F 17/00 (2013.01); G06F 11/00 (2013.01); G06F 15/16 (2013.01); G06F 21/606 (2013.01); H04L 63/12 (2013.01);
Abstract

The present invention discloses methods for effective network-security inspection in virtualized environments, the methods including the steps of: providing a data packet, embodied in machine-readable signals, being sent from a sending virtual machine to a receiving virtual machine via a virtual switch; intercepting the data packet by a sending security agent associated with the sending virtual machine; injecting the data packet into an inspecting security agent associated with a security virtual machine via a direct transmission channel which bypasses the virtual switch; forwarding the data packet to the security virtual machine by employing a packet-forwarding mechanism; determining, by the security virtual machine, whether the data packet is allowed for transmission; upon determining the data packet is allowed, injecting the data packet back into the sending security agent via the direct transmission channel; and forwarding the data packet to the receiving virtual machine via the virtual switch.


Find Patent Forward Citations

Loading…