×

Method and apparatus for application awareness in a network

  • US 9,444,841 B2
  • Filed: 02/14/2013
  • Issued: 09/13/2016
  • Est. Priority Date: 02/14/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method for enforcing a network policy on an application executing within a first context, the method comprising:

  • collecting statistics about data flow through a network socket of the first context;

    altering the network policy based on the collected statistics;

    intercepting, by an agent executing in the first context, a network socket event request from the application before the network socket event request reaches a transport layer in a network stack of the first context;

    sending, by the agent to a security server executing in a second context, a request for a decision on whether to allow or deny the intercepted network socket event, the request for the decision including an application identifier and a domain of the application;

    receiving, by the agent, the decision from the security server, the decision being an allowance or a denial of the network socket event request, the decision being based at least in part on the application identifier, the domain of the application, and the altered network policy; and

    preventing, by the agent, the network socket request from reaching the transport layer in the first context when the decision is the denial of the network socket event request.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×